Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Generic Win32/Explorer.exe/DrWatson32 errors


  • Please log in to reply

#1
Frustrated355

Frustrated355

    New Member

  • Member
  • Pip
  • 5 posts
Ok, so about a week ago I started getting problems with my internet connection. Naturally, I tried to fix it using the repair function, and unfortunately it always stalled at "Clearing Netbt." I looked into this error, trying nearly everything I could find to remedy it, but nothing worked. My last resort was a Winsock Fix. So, I ran the Winsock Fix, restarted, and it worked. I could repair my connection and everything seemed fine. So, I loaded up my computer game and started to play, only to find myself tabbing every few minutes to look at a new error.

Ever since then, everytime I start up Windows, I keep getting a series of errors. Win32 Generic processes/Explorer.exe/DrWatson has encountered an error and needs to close/WindowsLive Msn; they all encounter errors. It doesnt happen immediately, and almost seems at random. I can open Firefox, and surf the net for a little while before it starts shutting down, or I can open a videogame for up to 10 minutes before it starts. It seems like once I have a few windows or programs open, it starts to error.

Ive done a few system restores, ive ran AVG, and removed some viruses/cookies/malware. I uninstalled AVG, then installed Avira, doing a full system scan and removing a worm and some other junk. Ive cleaned out internet caches and other temporary files.

I ran a MBAM last night, removing some undesirables. Here's the log:

--------------------------------------------------------------------------

Malwarebytes' Anti-Malware 1.40
Database version: 2719
Windows 5.1.2600 Service Pack 2

30/08/2009 21:30:37
mbam-log-2009-08-30 (21-30-37).txt

Scan type: Full Scan (C:\|)
Objects scanned: 132080
Time elapsed: 52 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 4
Registry Data Items Infected: 2
Folders Infected: 2
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OLE\Windows Update (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\intime (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\reup (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WaitToKillServiceT (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\RECYCLER\S-1-5-21-0243336035-3055115375-381863305-1553 (Worm.Autorun) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243636035-3055115376-381863306-1556 (TrojanProxy.Slenugga) -> Quarantined and deleted successfully.

Files Infected:
C:\RECYCLER\S-1-5-21-0243336035-3055115375-381863305-1553\Desktop.ini (Worm.Autorun) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243636035-3055115376-381863306-1556\Desktop.ini (TrojanProxy.Slenugga) -> Quarantined and deleted successfully.

--------------------------------------------------------------------------

I loaded up my computer this morning, thinking everything was now fixed, but I still have the same issue. So, I ran MBAM again, to find no suspicious files.
After I get the initial errors, I can go to task manager and close two drwatson32.exe's, in which case my desktop is functional, but slow, and abnormal. Im not sure if that's relevant. Anyway, I ran a RootRepeal scan, and here's my log:

--------------------------------------------------------------------------

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/31 11:26
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB1CCE000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79B1000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAF5A4000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\Documents and Settings\Michael\Local Settings\Temp\etilqs_1obJ02RKhH14Ao5Ohaf9
Status: Invisible to the Windows API!

==EOF==


--------------------------------------------------------------------------

Lastly my OTL:


--------------------------------------------------------------------------

OTL logfile created on: 31/08/2009 11:38:11 - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Michael\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.25 Gb Total Physical Memory | 0.78 Gb Available Physical Memory | 62.75% Memory free
2.98 Gb Paging File | 2.68 Gb Available in Paging File | 89.98% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 57.26 Gb Total Space | 28.95 Gb Free Space | 50.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 512.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MIKE-8A9UQGCQZX
Current User Name: Michael
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2006/02/21 20:39:16 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2009/07/09 12:22:18 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2006/02/21 20:39:16 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2004/08/04 00:56:58 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe
PRC - [2009/07/13 14:03:10 | 00,292,128 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/02/06 18:51:28 | 03,885,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2004/08/04 00:56:54 | 01,667,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2009/07/13 14:02:50 | 00,542,496 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2004/08/04 00:56:50 | 01,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/08/04 00:56:52 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/08/05 12:53:17 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/08/31 11:36:52 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Michael\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/07/09 12:22:18 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2005/09/23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2006/02/21 20:39:16 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2005/09/23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2004/08/04 00:56:46 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009/07/13 14:02:50 | 00,542,496 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2007/11/06 21:22:26 | 00,092,792 | ---- | M] (CACE Technologies) -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd [On_Demand | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/30 11:48:15 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/30 11:48:15 | 00,000,000 | ---D | M]

[2009/07/16 19:56:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\mozilla\Extensions
[2009/07/16 19:56:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/16 19:56:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\mozilla\Firefox\Profiles\opne8mao.default\extensions
[2009/07/16 22:45:17 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/08/05 12:53:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/08/05 12:53:12 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/05 12:53:12 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/08/05 12:53:23 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/08/30 11:48:15 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/08/30 11:48:15 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/08/30 11:48:15 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/08/30 11:48:15 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/08/30 11:48:15 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/08/30 11:48:15 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/08/30 11:48:15 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/08/05 12:53:30 | 00,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2009/08/05 12:53:30 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/05 12:53:30 | 00,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2009/08/05 12:53:30 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/05 12:53:30 | 00,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2009/08/05 12:53:30 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/05 12:53:30 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/05 12:53:30 | 00,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: (736 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Cmaudio] File not found
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zon...kr.cab56986.cab (Checkers Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zon...er.cab56986.cab (Minesweeper Flags Class)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\WBSrv: DllName - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll (Stardock Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/27 08:59:48 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/04/18 16:23:00 | 00,000,041 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{7f4e2c43-62f6-11de-af82-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{7f4e2c43-62f6-11de-af82-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7f4e2c43-62f6-11de-af82-806d6172696f}\Shell\AutoRun\command - "" = E:\SETUP.EXE -- [2001/04/30 18:33:00 | 00,032,768 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (aswBoot.exe) - File not found
O34 - HKLM BootExecute: (/A:"*") - File not found
O34 - HKLM BootExecute: (/L:"English") - File not found
O34 - HKLM BootExecute: (/KBD:2) - File not found

NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)

========== Files/Folders - Created Within 14 Days ==========

[2009/08/31 11:36:39 | 00,514,048 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Michael\Desktop\OTL.exe
[2009/08/31 11:26:43 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\settings.dat
[2009/08/31 11:25:12 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\Michael\Desktop\RootRepeal.exe
[2009/08/31 10:27:12 | 00,014,835 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\Microsoft Update.htm
[2009/08/31 10:26:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Desktop\Microsoft Update_files
[2009/08/31 10:20:27 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2009/08/30 20:37:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/08/30 20:36:43 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\NTREGOPT.lnk
[2009/08/30 20:36:42 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\ERUNT.lnk
[2009/08/30 20:36:42 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/08/30 20:35:56 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Michael\Desktop\erunt_setup.exe
[2009/08/30 20:32:41 | 00,272,384 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Michael\Desktop\TFC.exe
[2009/08/30 19:43:01 | 00,005,398 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\zzzzz.rtf
[2009/08/30 19:05:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Malwarebytes
[2009/08/30 19:05:00 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/30 19:04:58 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/30 19:04:56 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/30 19:04:56 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/30 19:04:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/08/30 19:02:36 | 03,942,048 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Michael\Desktop\mbam-setup.exe
[2009/08/30 18:52:38 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/08/30 18:50:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Desktop\Client v1.8
[2009/08/30 15:18:47 | 00,055,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2009/08/30 15:09:20 | 33,961,728 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\avira_antivir_personal_en.exe
[2009/08/30 12:34:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Help
[2009/08/30 12:34:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Help
[2009/08/30 11:51:05 | 00,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/08/30 11:49:04 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/08/30 11:47:57 | 00,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/08/30 11:26:02 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/08/30 11:25:12 | 00,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2009/08/30 11:25:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2009/08/30 10:01:09 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/08/29 15:12:30 | 00,000,079 | ---- | C] () -- C:\WINDOWS\System32\asr_nzuia
[2009/08/29 14:57:33 | 00,000,000 | ---D | C] -- C:\$AVG8.VAULT$
[2009/08/29 14:55:11 | 00,011,952 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx(2).dll
[2009/08/29 14:54:44 | 40,281,795 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg(2)\incavi.avm
[2009/08/29 14:54:42 | 00,073,369 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg(2)\microavi.avg
[2009/08/29 14:54:39 | 00,463,779 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg(2)\miniavi.avg
[2009/08/29 14:54:37 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg(2)\avi7.avg
[2009/08/29 14:54:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg(2)
[2009/08/29 14:54:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/08/29 14:44:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\AVG8
[2009/08/29 14:44:21 | 00,848,712 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Michael\Desktop\avg_free_stb_all_8_32_cnet.exe
[2009/08/29 13:03:48 | 01,445,888 | ---- | C] (Option^Explicit Software Solutions) -- C:\Documents and Settings\Michael\Desktop\WinsockxpFix.exe
[2009/08/29 13:00:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/29 13:00:02 | 08,060,048 | ---- | C] (PC Tools ) -- C:\Documents and Settings\Michael\Desktop\rminstall.exe
[2009/08/29 08:28:18 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2009/08/29 08:28:18 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2009/08/29 08:28:18 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2009/08/29 08:22:57 | 00,001,564 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\Diablo II - Lord of Destruction.lnk
[2009/08/29 08:15:25 | 00,035,330 | ---- | C] () -- C:\WINDOWS\DIIUnin.dat
[2009/08/29 08:15:25 | 00,001,564 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Diablo II.lnk
[2009/08/29 08:15:22 | 00,094,208 | ---- | C] (Blizzard Entertainment) -- C:\WINDOWS\DIIUnin.exe
[2009/08/29 08:15:22 | 00,002,829 | ---- | C] () -- C:\WINDOWS\DIIUnin.pif
[2009/08/29 08:07:49 | 00,000,000 | ---D | C] -- C:\Program Files\Diablo II
[2009/08/26 00:19:00 | 00,013,640 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\LetteRRRR.docx
[2009/08/25 12:07:54 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/08/25 11:57:15 | 00,000,000 | ---D | C] -- C:\Program Files\Abexo
[2009/08/25 11:32:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Apple Computer
[2009/08/25 11:31:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/08/25 11:30:43 | 00,734,517 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\afrcfree.exe
[2009/08/25 11:29:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/08/25 11:29:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Apple
[2009/08/25 11:28:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2009/08/25 11:28:16 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2009/08/25 11:27:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Apple Computer
[2009/08/25 03:52:33 | 00,000,303 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\TEST.html

========== Files - Modified Within 14 Days ==========

[2009/08/31 11:36:52 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Michael\Desktop\OTL.exe
[2009/08/31 11:36:06 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/08/31 11:26:43 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\settings.dat
[2009/08/31 11:25:24 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\Michael\Desktop\RootRepeal.exe
[2009/08/31 10:27:12 | 00,014,835 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\Microsoft Update.htm
[2009/08/31 09:27:06 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/08/31 09:23:42 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/08/31 09:23:40 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/08/30 22:22:32 | 03,231,922 | -H-- | M] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\IconCache.db
[2009/08/30 20:36:43 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\NTREGOPT.lnk
[2009/08/30 20:36:43 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\ERUNT.lnk
[2009/08/30 20:36:22 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Michael\Desktop\erunt_setup.exe
[2009/08/30 20:32:41 | 00,272,384 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Michael\Desktop\TFC.exe
[2009/08/30 20:02:27 | 00,005,398 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\zzzzz.rtf
[2009/08/30 19:05:00 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/30 19:04:28 | 03,942,048 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Michael\Desktop\mbam-setup.exe
[2009/08/30 15:11:06 | 33,961,728 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\avira_antivir_personal_en.exe
[2009/08/30 13:20:58 | 01,445,888 | ---- | M] (Option^Explicit Software Solutions) -- C:\Documents and Settings\Michael\Desktop\WinsockxpFix.exe
[2009/08/30 11:47:57 | 00,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/08/30 09:38:52 | 40,281,795 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg(2)\incavi.avm
[2009/08/29 15:12:30 | 00,000,079 | ---- | M] () -- C:\WINDOWS\System32\asr_nzuia
[2009/08/29 14:55:11 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx(2).dll
[2009/08/29 14:54:44 | 00,073,369 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg(2)\microavi.avg
[2009/08/29 14:54:42 | 00,463,779 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg(2)\miniavi.avg
[2009/08/29 14:54:39 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg(2)\avi7.avg
[2009/08/29 14:44:22 | 00,848,712 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Michael\Desktop\avg_free_stb_all_8_32_cnet.exe
[2009/08/29 14:04:37 | 00,134,483 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\Picture 005.jpg
[2009/08/29 14:04:35 | 00,140,514 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\Picture 004.jpg
[2009/08/29 13:59:11 | 00,135,809 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\Picture 003.jpg
[2009/08/29 13:59:09 | 00,137,687 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\Picture 002.jpg
[2009/08/29 13:59:07 | 00,140,267 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\Picture 001.jpg
[2009/08/29 13:10:01 | 00,000,396 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\Local Area Connection.lnk
[2009/08/29 13:00:15 | 08,060,048 | ---- | M] (PC Tools ) -- C:\Documents and Settings\Michael\Desktop\rminstall.exe
[2009/08/29 08:31:44 | 00,035,330 | ---- | M] () -- C:\WINDOWS\DIIUnin.dat
[2009/08/29 08:31:13 | 00,021,840 | ---- | M] () -- C:\WINDOWS\System32\SIntfNT.dll
[2009/08/29 08:31:13 | 00,017,212 | ---- | M] () -- C:\WINDOWS\System32\SIntf32.dll
[2009/08/29 08:31:13 | 00,012,067 | ---- | M] () -- C:\WINDOWS\System32\SIntf16.dll
[2009/08/29 08:22:57 | 00,001,564 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\Diablo II - Lord of Destruction.lnk
[2009/08/29 08:15:25 | 00,001,564 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Diablo II.lnk
[2009/08/29 08:15:23 | 00,002,829 | ---- | M] () -- C:\WINDOWS\DIIUnin.pif
[2009/08/29 08:15:22 | 00,094,208 | ---- | M] (Blizzard Entertainment) -- C:\WINDOWS\DIIUnin.exe
[2009/08/27 18:49:50 | 00,152,344 | ---- | M] () -- C:\WINDOWS\War3Unin.dat
[2009/08/26 00:19:01 | 00,013,640 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\LetteRRRR.docx
[2009/08/25 11:31:02 | 00,734,517 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\afrcfree.exe
[2009/08/25 03:56:45 | 00,000,303 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\TEST.html

========== LOP Check ==========

[2009/08/30 17:41:30 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/08/25 11:32:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/08/01 09:28:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Blizzard
[2009/08/30 17:24:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/08/29 13:03:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/30 19:05:02 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Michael\Application Data
[2009/07/16 18:54:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\ATI
[2009/07/25 03:06:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2009/08/28 23:08:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\uTorrent
[2009/07/01 05:10:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\Ventrilo
[2002/08/29 13:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/08/31 09:23:42 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %systemroot%\system32\eventlog.dll >
[2004/08/04 00:56:44 | 00,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll

< %systemroot%\system32\scecli.dll >
[2004/08/04 00:56:46 | 00,180,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll

< %systemroot%\netlogon.dll >

< %systemroot%\system32\cngaudit.dll >

< %systemroot%\system32\sceclt.dll >

< %systemroot%\ntelogon.dll >

< %systemroot%\system32\logevent.dll >

========== Alternate Data Streams ==========

@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >

OTL Extras logfile created on: 31/08/2009 11:38:11 - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Michael\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.25 Gb Total Physical Memory | 0.78 Gb Available Physical Memory | 62.75% Memory free
2.98 Gb Paging File | 2.68 Gb Available in Paging File | 89.98% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 57.26 Gb Total Space | 28.95 Gb Free Space | 50.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 512.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded


Computer Name: MIKE-8A9UQGCQZX
Current User Name: Michael
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"11501:TCP" = 11501:TCP:*:Enabled:BitComet 11501 TCP
"11501:UDP" = 11501:UDP:*:Enabled:BitComet 11501 UDP
"8395:TCP" = 8395:TCP:*:Enabled:League of Legends Launcher
"8395:UDP" = 8395:UDP:*:Enabled:League of Legends Launcher
"8396:TCP" = 8396:TCP:*:Enabled:League of Legends Launcher
"8396:UDP" = 8396:UDP:*:Enabled:League of Legends Launcher
"8397:TCP" = 8397:TCP:*:Enabled:League of Legends Launcher
"8397:UDP" = 8397:UDP:*:Enabled:League of Legends Launcher
"8398:TCP" = 8398:TCP:*:Enabled:League of Legends Launcher
"8398:UDP" = 8398:UDP:*:Enabled:League of Legends Launcher
"8399:TCP" = 8399:TCP:*:Enabled:League of Legends Launcher
"8399:UDP" = 8399:UDP:*:Enabled:League of Legends Launcher

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe -- (Flagship Industries, Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24aab420-4e30-4496-9739-3e216f3de6ae}" = Python 2.6.2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3382A07-BFF1-4A8D-9524-DEF82AE3F58B}" = League of Legends
"{B06D1168-C6D1-11D5-BC91-0800094CFDB8}" = Samsung Digimax 350SE Camera
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Abexo Free Registry Cleaner" = Abexo Free Registry Cleaner
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ATI Display Driver" = ATI Display Driver
"C-Media Audio" = C-Media Audio
"C-Media Audio Driver" = C-Media WDM Audio Driver
"ERUNT_is1" = ERUNT 1.1j
"Eurobattle.net2.0" = Eurobattle.net
"Garena" = Garena
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.5.2)" = Mozilla Firefox (3.5.2)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Ogg Codecs" = Ogg Codecs 0.81.15562
"Security Task Manager" = Security Task Manager 1.7h
"SiSLan" = SiS 900 PCI Fast Ethernet Adapter Driver
"WindowBlinds" = WindowBlinds
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.0.2
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 30/08/2009 14:09:45 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x66043703.

Error - 30/08/2009 14:10:02 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 30/08/2009 14:10:27 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application wlcomm.exe, version 14.0.8064.206, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.

Error - 30/08/2009 15:10:02 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x001f1cb0.

Error - 30/08/2009 15:16:11 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x66043703.

Error - 30/08/2009 15:29:58 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 31/08/2009 04:58:17 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x001f1cb0.

Error - 31/08/2009 04:59:30 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x66043703.

Error - 31/08/2009 04:59:41 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 31/08/2009 04:59:59 | Computer Name = MIKE-8A9UQGCQZX | Source = Application Error | ID = 1000
Description = Faulting application wlcomm.exe, version 14.0.8064.206, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.

[ System Events ]
Error - 30/08/2009 10:12:55 | Computer Name = MIKE-8A9UQGCQZX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MSIServer with
arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}

Error - 30/08/2009 10:12:55 | Computer Name = MIKE-8A9UQGCQZX | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 30/08/2009 10:12:55 | Computer Name = MIKE-8A9UQGCQZX | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 30/08/2009 10:12:55 | Computer Name = MIKE-8A9UQGCQZX | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\DOCUME~1\Michael\LOCALS~1\Temp\RarSFX0\basic\setup.exe.
Reference
error message: The operation completed successfully. .

Error - 30/08/2009 14:47:05 | Computer Name = MIKE-8A9UQGCQZX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 30/08/2009 14:47:51 | Computer Name = MIKE-8A9UQGCQZX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 30/08/2009 15:33:01 | Computer Name = MIKE-8A9UQGCQZX | Source = Service Control Manager | ID = 7034
Description = The Ati HotKey Poller service terminated unexpectedly. It has done
this 1 time(s).

Error - 30/08/2009 15:33:01 | Computer Name = MIKE-8A9UQGCQZX | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 30/08/2009 15:33:01 | Computer Name = MIKE-8A9UQGCQZX | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 30/08/2009 16:32:26 | Computer Name = MIKE-8A9UQGCQZX | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
PCIIde


< End of report >

--------------------------------------------------------------------------

I hope that's everything you need to know. Any help would be greatly appreciated.
  • 0

Advertisements


#2
Frustrated355

Frustrated355

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Ok... so ive fixed the problem, to find I have a new problem. After removing several annoyances, I no longer have errors, but now just slow internet. -_-

I play alot of computer games, and it's incomparable to what it was before. I have delay, I have spikes, and what's the most insulting is, my ping is absolutely fine.

I dont know if this is the relevant section for this kind of rant, but im really frustrated.
  • 0

#3
Frustrated355

Frustrated355

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Nm, errors are back, but now my connection is fine. Pretty amusing. Whatever, just going to wait until someone gets back to me here. At the end of my tether.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP