I have noted that similar problems have been had before, by other people, so I am hopeful!
Details are: Using Firefox to browse, I use Google as standard search engine and noticed a few days ago that some of the hits when clicked were bringing up spurious search pages. Not all the time, it seems to be just a pain the neck than dangerous, on the 2nd or 3rd click it goes to the correct site, but it concerns me that whatever it is could be "watching me", banking pwds etc.?
History of action taken so far (to no avail, alas) - AVG detected and seemed to cure an infection from a "b.exe" virus a few days before I noticed this, but when I run a scan now it finds various things (see log below), which it cannot remove or heal.
Tried my usual stalwarts SpybotSD and MBAM, but neither will get more than a few seconds on the screen before being shutdown - even when I download fresh install/set-up files and rename them before running them or run them in Safe Mode. Also maybe worth noting, once these have failed, they become unusable (error message: Windows cannot access the specified device, path or file. You may not have the approriate permissions to access the item).
Tried a System Restore (taking it back a few weeks) this failed.
So, I have been reading the Geeks to Go Malware and Spyware Cleaning Guide. So far I have TFC'd, set a System Restore, run ERUNT successfully, but then failed on MBAM and to run a successful Virus Scan using AVG. I am running Windows update as I type this, and have completed a Rootappeal and OTL Scan. All logs are posted below (I hope there's not too much - seems massive!).
Also observed spmeone else was asked to run a Win32kDiag scan, so did that too, report posted as well.
That's about all I can tell you, do you think you can help? Is this thing likely to be dangerous or just a nuisance and how the devil did it get on my machine, do you think - have I been careless?
Yours hopefully
The following were found by AVG , but could not remove or heal them.....
"\\?\globalroot\Device\__max++>\3AA98726.x86.dll";"Spyware Generic.CE";"Potentially dangerous object"
"\\?\globalroot\Device\__max++>\3AA98726.x86.dll";"Spyware Generic.CE";"Potentially dangerous object"
"\\?\globalroot\Device\__max++>\3AA98726.x86.dll";"Spyware Generic.CE";"Potentially dangerous object"
"\\?\globalroot\Device\__max++>\3AA98726.x86.dll";"Spyware Generic.CE";"Potentially dangerous object"
"\\?\globalroot\Device\__max++>\3AA98726.x86.dll";"Spyware Generic.CE";"Potentially dangerous object"
"D:\PROGRA~1\AVG\AVG8\avgemc.exe (1412)";"Spyware Generic.CE";"Potentially dangerous object"
"D:\PROGRA~1\Yahoo!\browser\ycommon.exe (2544)";"Spyware Generic.CE";"Potentially dangerous object"
"\\?\globalroot\Device\__max++>\3AA98726.x86.dll";"Spyware Generic.CE";"Potentially dangerous object"
"D:\PROGRA~1\AVG\AVG8\avgnsx.exe (1520)";"Spyware Generic.CE";"Potentially dangerous object"
"D:\WINDOWS\explorer.exe (1432)";"Spyware Generic.CE";"Potentially dangerous object"
"D:\WINDOWS\system32\spoolsv.exe (1724)";"Spyware Generic.CE";"Potentially dangerous object"
"D:\WINDOWS\system32\svchost.exe (1072)";"Spyware Generic.CE";"Potentially dangerous object"
Win32kDiag Report
Running from: D:\Documents and Settings\Will\desktop\win32kdiag.exeLog file at : D:\Documents and Settings\Will\Desktop\Win32kDiag.txtRemoving all found mount points.Attempting to reset file permissions.WARNING: Could not get backup privileges!Searching 'D:\WINDOWS'...Found mount point : D:\WINDOWS\addins\addinsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\addins\addinsFound mount point : D:\WINDOWS\Config\ConfigMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\Config\ConfigFound mount point : D:\WINDOWS\Connection Wizard\Connection WizardMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\Connection Wizard\Connection WizardFound mount point : D:\WINDOWS\Debug\UserMode\UserModeMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\Debug\UserMode\UserModeFound mount point : D:\WINDOWS\ftpcache\ftpcacheMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\ftpcache\ftpcacheFound mount point : D:\WINDOWS\ime\chsime\applets\appletsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\ime\chsime\applets\appletsFound mount point : D:\WINDOWS\ime\CHTIME\Applets\AppletsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\ime\CHTIME\Applets\AppletsFound mount point : D:\WINDOWS\ime\imejp\applets\appletsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\ime\imejp\applets\appletsFound mount point : D:\WINDOWS\ime\imejp98\imejp98Mount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\ime\imejp98\imejp98Found mount point : D:\WINDOWS\ime\imjp8_1\applets\appletsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\ime\imjp8_1\applets\appletsFound mount point : D:\WINDOWS\ime\imkr6_1\applets\appletsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\ime\imkr6_1\applets\appletsFound mount point : D:\WINDOWS\ime\imkr6_1\dicts\dictsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\ime\imkr6_1\dicts\dictsFound mount point : D:\WINDOWS\ime\shared\res\resMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\ime\shared\res\resFound mount point : D:\WINDOWS\java\trustlib\trustlibMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\java\trustlib\trustlibFound mount point : D:\WINDOWS\msapps\msinfo\msinfoMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\msapps\msinfo\msinfoFound mount point : D:\WINDOWS\mui\muiMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\mui\muiFound mount point : D:\WINDOWS\pchealth\helpctr\BATCH\BATCHMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\pchealth\helpctr\BATCH\BATCHCannot access: D:\WINDOWS\pchealth\helpctr\binaries\HelpSvc.exeAttempting to restore permissions of : D:\WINDOWS\pchealth\helpctr\binaries\HelpSvc.exeFound mount point : D:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPointMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPointFound mount point : D:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFilesMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFilesFound mount point : D:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUsFound mount point : D:\WINDOWS\pchealth\helpctr\System\DFS\DFSMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\pchealth\helpctr\System\DFS\DFSFound mount point : D:\WINDOWS\pchealth\helpctr\System\News\NewsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\pchealth\helpctr\System\News\NewsFound mount point : D:\WINDOWS\pchealth\helpctr\System_OEM\System_OEMMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\pchealth\helpctr\System_OEM\System_OEMFound mount point : D:\WINDOWS\pchealth\helpctr\Temp\TempMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\pchealth\helpctr\Temp\TempFound mount point : D:\WINDOWS\Profiles\All Users\Adobe\Webbuy\WebbuyMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\Profiles\All Users\Adobe\Webbuy\WebbuyFound mount point : D:\WINDOWS\Registration\CRMLog\CRMLogMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\Registration\CRMLog\CRMLogFound mount point : D:\WINDOWS\SoftwareDistribution\AuthCabs\AuthCabsMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\SoftwareDistribution\AuthCabs\AuthCabsFound mount point : D:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\backup\backupMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\backup\backupFound mount point : D:\WINDOWS\SoftwareDistribution\Download\44fb4874aea086fc46affdc6f401b232\44fb4874aea086fc46affdc6f401b232Mount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\SoftwareDistribution\Download\44fb4874aea086fc46affdc6f401b232\44fb4874aea086fc46affdc6f401b232Found mount point : D:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\10\10Mount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\10\10Found mount point : D:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\msft\msftMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\msft\msftFound mount point : D:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\60\msft\msftMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\60\msft\msftFound mount point : D:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\70\70Mount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\70\70Found mount point : D:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\DefaultMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\DefaultFound mount point : D:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\RegisteredMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\RegisteredFound mount point : D:\WINDOWS\Sun\Java\Deployment\DeploymentMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\Sun\Java\Deployment\DeploymentCannot access: D:\WINDOWS\system32\eventlog.dllAttempting to restore permissions of : D:\WINDOWS\system32\eventlog.dll[1] 2008-04-14 01:11:53 56320 D:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll (Microsoft Corporation)[1] 2004-08-04 13:00:00 55808 D:\WINDOWS\system32\dllcache\eventlog.dll (Microsoft Corporation)[1] 2004-08-04 13:00:00 61952 D:\WINDOWS\system32\eventlog.dll ()[2] 2004-08-04 13:00:00 55808 D:\WINDOWS\system32\logevent.dll (Microsoft Corporation)Found mount point : D:\WINDOWS\Temp\TempMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\Temp\TempFound mount point : D:\WINDOWS\WinSxS\InstallTemp\InstallTempMount point destination : \Device\__max++>\^Removing mount point : D:\WINDOWS\WinSxS\InstallTemp\InstallTempFinished!
RootRepeal Report
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/06 23:44
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: ACPI.sys
Image Path: ACPI.sys
Address: 0xF84E7000 Size: 187776 File Visible: - Signed: -
Status: -
Name: ACPI_HAL
Image Path: \Driver\ACPI_HAL
Address: 0x804D7000 Size: 2180480 File Visible: - Signed: -
Status: -
Name: afd.sys
Image Path: D:\WINDOWS\System32\drivers\afd.sys
Address: 0xF6532000 Size: 138368 File Visible: - Signed: -
Status: -
Name: agp440.sys
Image Path: agp440.sys
Address: 0xF8596000 Size: 42368 File Visible: - Signed: -
Status: -
Name: atapi.sys
Image Path: atapi.sys
Address: 0xF849F000 Size: 95360 File Visible: - Signed: -
Status: -
Name: audstub.sys
Image Path: D:\WINDOWS\system32\DRIVERS\audstub.sys
Address: 0xF8BDE000 Size: 3072 File Visible: - Signed: -
Status: -
Name: avgldx86.sys
Image Path: D:\WINDOWS\System32\Drivers\avgldx86.sys
Address: 0xF6426000 Size: 328576 File Visible: - Signed: -
Status: -
Name: avgmfx86.sys
Image Path: D:\WINDOWS\System32\Drivers\avgmfx86.sys
Address: 0xF88BE000 Size: 21120 File Visible: - Signed: -
Status: -
Name: avgtdix.sys
Image Path: D:\WINDOWS\System32\Drivers\avgtdix.sys
Address: 0xF657C000 Size: 101888 File Visible: - Signed: -
Status: -
Name: BCMSM.sys
Image Path: D:\WINDOWS\system32\DRIVERS\BCMSM.sys
Address: 0xF79F6000 Size: 1101696 File Visible: - Signed: -
Status: -
Name: Beep.SYS
Image Path: D:\WINDOWS\System32\Drivers\Beep.SYS
Address: 0xF8A6E000 Size: 4224 File Visible: - Signed: -
Status: -
Name: BOOTVID.dll
Image Path: D:\WINDOWS\system32\BOOTVID.dll
Address: 0xF8946000 Size: 12288 File Visible: - Signed: -
Status: -
Name: Cdfs.SYS
Image Path: D:\WINDOWS\System32\Drivers\Cdfs.SYS
Address: 0xF8656000 Size: 63744 File Visible: - Signed: -
Status: -
Name: cdrom.sys
Image Path: D:\WINDOWS\system32\DRIVERS\cdrom.sys
Address: 0xF7DAE000 Size: 49536 File Visible: - Signed: -
Status: -
Name: CLASSPNP.SYS
Image Path: D:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Address: 0xF8576000 Size: 53248 File Visible: - Signed: -
Status: -
Name: ctoss2k.sys
Image Path: D:\WINDOWS\system32\DRIVERS\ctoss2k.sys
Address: 0xF783E000 Size: 178400 File Visible: - Signed: -
Status: -
Name: ctsfm2k.sys
Image Path: D:\WINDOWS\system32\DRIVERS\ctsfm2k.sys
Address: 0xF781E000 Size: 129920 File Visible: - Signed: -
Status: -
Name: disk.sys
Image Path: disk.sys
Address: 0xF8566000 Size: 36352 File Visible: - Signed: -
Status: -
Name: DNINDIS5.SYS
Image Path: C:\PROGRA~1\Belkin\BELKIN~1.11G\DNINDIS5.SYS
Address: 0xF2A3C000 Size: 15744 File Visible: - Signed: -
Status: -
Name: drmk.sys
Image Path: D:\WINDOWS\system32\drivers\drmk.sys
Address: 0xF8796000 Size: 61440 File Visible: - Signed: -
Status: -
Name: dump_atapi.sys
Image Path: D:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF640E000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: D:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8A7E000 Size: 8192 File Visible: No Signed: -
Status: -
Name: Dxapi.sys
Image Path: D:\WINDOWS\System32\drivers\Dxapi.sys
Address: 0xF6664000 Size: 12288 File Visible: - Signed: -
Status: -
Name: dxg.sys
Image Path: D:\WINDOWS\System32\drivers\dxg.sys
Address: 0xBF000000 Size: 73728 File Visible: - Signed: -
Status: -
Name: dxgthk.sys
Image Path: D:\WINDOWS\System32\drivers\dxgthk.sys
Address: 0xF8BCC000 Size: 4096 File Visible: - Signed: -
Status: -
Name: fdc.sys
Image Path: D:\WINDOWS\system32\DRIVERS\fdc.sys
Address: 0xF884E000 Size: 27392 File Visible: - Signed: -
Status: -
Name: Fips.SYS
Image Path: D:\WINDOWS\System32\Drivers\Fips.SYS
Address: 0xF8626000 Size: 34944 File Visible: - Signed: -
Status: -
Name: fltMgr.sys
Image Path: fltMgr.sys
Address: 0xF847F000 Size: 128896 File Visible: - Signed: -
Status: -
Name: Fs_Rec.SYS
Image Path: D:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Address: 0xF8A5A000 Size: 7936 File Visible: - Signed: -
Status: -
Name: ftdisk.sys
Image Path: ftdisk.sys
Address: 0xF84B7000 Size: 125056 File Visible: - Signed: -
Status: -
Name: hal.dll
Image Path: D:\WINDOWS\system32\hal.dll
Address: 0x806EC000 Size: 131968 File Visible: - Signed: -
Status: -
Name: HTTP.sys
Image Path: D:\WINDOWS\System32\Drivers\HTTP.sys
Address: 0xF2A74000 Size: 262784 File Visible: - Signed: -
Status: -
Name: i8042prt.sys
Image Path: D:\WINDOWS\system32\DRIVERS\i8042prt.sys
Address: 0xF87A6000 Size: 52736 File Visible: - Signed: -
Status: -
Name: imapi.sys
Image Path: D:\WINDOWS\system32\DRIVERS\imapi.sys
Address: 0xF7D8E000 Size: 41856 File Visible: - Signed: -
Status: -
Name: intelide.sys
Image Path: intelide.sys
Address: 0xF8A3A000 Size: 5504 File Visible: - Signed: -
Status: -
Name: intelppm.sys
Image Path: D:\WINDOWS\system32\DRIVERS\intelppm.sys
Address: 0xF8786000 Size: 36096 File Visible: - Signed: -
Status: -
Name: ipnat.sys
Image Path: D:\WINDOWS\system32\DRIVERS\ipnat.sys
Address: 0xF6477000 Size: 134912 File Visible: - Signed: -
Status: -
Name: ipsec.sys
Image Path: D:\WINDOWS\system32\DRIVERS\ipsec.sys
Address: 0xF65ED000 Size: 74752 File Visible: - Signed: -
Status: -
Name: isapnp.sys
Image Path: isapnp.sys
Address: 0xF8536000 Size: 35840 File Visible: - Signed: -
Status: -
Name: kbdclass.sys
Image Path: D:\WINDOWS\system32\DRIVERS\kbdclass.sys
Address: 0xF8856000 Size: 24576 File Visible: - Signed: -
Status: -
Name: KDCOM.DLL
Image Path: D:\WINDOWS\system32\KDCOM.DLL
Address: 0xF8A36000 Size: 8192 File Visible: - Signed: -
Status: -
Name: ks.sys
Image Path: D:\WINDOWS\system32\DRIVERS\ks.sys
Address: 0xF79D3000 Size: 143360 File Visible: - Signed: -
Status: -
Name: KSecDD.sys
Image Path: KSecDD.sys
Address: 0xF8456000 Size: 92544 File Visible: - Signed: -
Status: -
Name: L8042Kbd.sys
Image Path: D:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
Address: 0xF89E2000 Size: 11872 File Visible: - Signed: -
Status: -
Name: L8042mou.Sys
Image Path: D:\WINDOWS\system32\DRIVERS\L8042mou.Sys
Address: 0xF85B6000 Size: 50304 File Visible: - Signed: -
Status: -
Name: LMouKE.Sys
Image Path: D:\WINDOWS\system32\DRIVERS\LMouKE.Sys
Address: 0xF7DCE000 Size: 64480 File Visible: - Signed: -
Status: -
Name: mdc8021x.sys
Image Path: D:\WINDOWS\system32\DRIVERS\mdc8021x.sys
Address: 0xF5316000 Size: 14176 File Visible: - Signed: -
Status: -
Name: mnmdd.SYS
Image Path: D:\WINDOWS\System32\Drivers\mnmdd.SYS
Address: 0xF8A70000 Size: 4224 File Visible: - Signed: -
Status: -
Name: Modem.SYS
Image Path: D:\WINDOWS\System32\Drivers\Modem.SYS
Address: 0xF8846000 Size: 30080 File Visible: - Signed: -
Status: -
Name: MODEMCSA.sys
Image Path: D:\WINDOWS\system32\drivers\MODEMCSA.sys
Address: 0xF8A26000 Size: 16128 File Visible: - Signed: -
Status: -
Name: mouclass.sys
Image Path: D:\WINDOWS\system32\DRIVERS\mouclass.sys
Address: 0xF885E000 Size: 23040 File Visible: - Signed: -
Status: -
Name: MountMgr.sys
Image Path: MountMgr.sys
Address: 0xF8546000 Size: 42240 File Visible: - Signed: -
Status: -
Name: MRESP50.SYS
Image Path: D:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
Address: 0xF882E000 Size: 20096 File Visible: - Signed: -
Status: -
Name: mrxdav.sys
Image Path: D:\WINDOWS\system32\DRIVERS\mrxdav.sys
Address: 0xF3057000 Size: 179584 File Visible: - Signed: -
Status: -
Name: mrxsmb.sys
Image Path: D:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Address: 0xF6498000 Size: 453632 File Visible: - Signed: -
Status: -
Name: Msfs.SYS
Image Path: D:\WINDOWS\System32\Drivers\Msfs.SYS
Address: 0xF88A6000 Size: 19072 File Visible: - Signed: -
Status: -
Name: msgpc.sys
Image Path: D:\WINDOWS\system32\DRIVERS\msgpc.sys
Address: 0xF7D4E000 Size: 35072 File Visible: - Signed: -
Status: -
Name: mssmbios.sys
Image Path: D:\WINDOWS\system32\DRIVERS\mssmbios.sys
Address: 0xF89FA000 Size: 15488 File Visible: - Signed: -
Status: -
Name: Mup.sys
Image Path: Mup.sys
Address: 0xF8381000 Size: 107904 File Visible: - Signed: -
Status: -
Name: NDIS.sys
Image Path: NDIS.sys
Address: 0xF839C000 Size: 182912 File Visible: - Signed: -
Status: -
Name: ndistapi.sys
Image Path: D:\WINDOWS\system32\DRIVERS\ndistapi.sys
Address: 0xF89F2000 Size: 9600 File Visible: - Signed: -
Status: -
Name: ndisuio.sys
Image Path: D:\WINDOWS\system32\DRIVERS\ndisuio.sys
Address: 0xF4778000 Size: 12928 File Visible: - Signed: -
Status: -
Name: ndiswan.sys
Image Path: D:\WINDOWS\system32\DRIVERS\ndiswan.sys
Address: 0xF77F3000 Size: 91776 File Visible: - Signed: -
Status: -
Name: NDProxy.SYS
Image Path: D:\WINDOWS\System32\Drivers\NDProxy.SYS
Address: 0xF85C6000 Size: 38016 File Visible: - Signed: -
Status: -
Name: netbios.sys
Image Path: D:\WINDOWS\system32\DRIVERS\netbios.sys
Address: 0xF8616000 Size: 34560 File Visible: - Signed: -
Status: -
Name: netbt.sys
Image Path: D:\WINDOWS\system32\DRIVERS\netbt.sys
Address: 0xF6554000 Size: 162816 File Visible: - Signed: -
Status: -
Name: Npfs.SYS
Image Path: D:\WINDOWS\System32\Drivers\Npfs.SYS
Address: 0xF88AE000 Size: 30848 File Visible: - Signed: -
Status: -
Name: Ntfs.sys
Image Path: Ntfs.sys
Address: 0xF83C9000 Size: 574464 File Visible: - Signed: -
Status: -
Name: ntoskrnl.exe
Image Path: D:\WINDOWS\system32\ntoskrnl.exe
Address: 0x804D7000 Size: 2180480 File Visible: - Signed: -
Status: -
Name: Null.SYS
Image Path: D:\WINDOWS\System32\Drivers\Null.SYS
Address: 0xF8C83000 Size: 2944 File Visible: - Signed: -
Status: -
Name: nv4_disp.dll
Image Path: D:\WINDOWS\System32\nv4_disp.dll
Address: 0xBF012000 Size: 4276224 File Visible: - Signed: -
Status: -
Name: nv4_mini.sys
Image Path: D:\WINDOWS\system32\DRIVERS\nv4_mini.sys
Address: 0xF7B6E000 Size: 1897408 File Visible: - Signed: -
Status: -
Name: P16X.sys
Image Path: D:\WINDOWS\system32\drivers\P16X.sys
Address: 0xF788E000 Size: 1330048 File Visible: - Signed: -
Status: -
Name: parport.sys
Image Path: D:\WINDOWS\system32\DRIVERS\parport.sys
Address: 0xF780A000 Size: 80128 File Visible: - Signed: -
Status: -
Name: PartMgr.sys
Image Path: PartMgr.sys
Address: 0xF87BE000 Size: 18688 File Visible: - Signed: -
Status: -
Name: ParVdm.SYS
Image Path: D:\WINDOWS\System32\Drivers\ParVdm.SYS
Address: 0xF8A5E000 Size: 6784 File Visible: - Signed: -
Status: -
Name: pci.sys
Image Path: pci.sys
Address: 0xF84D6000 Size: 68224 File Visible: - Signed: -
Status: -
Name: PCIIDEX.SYS
Image Path: D:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Address: 0xF87B6000 Size: 28672 File Visible: - Signed: -
Status: -
Name: PnpManager
Image Path: \Driver\PnpManager
Address: 0x804D7000 Size: 2180480 File Visible: - Signed: -
Status: -
Name: portcls.sys
Image Path: D:\WINDOWS\system32\drivers\portcls.sys
Address: 0xF786A000 Size: 147456 File Visible: - Signed: -
Status: -
Name: psched.sys
Image Path: D:\WINDOWS\system32\DRIVERS\psched.sys
Address: 0xF77E2000 Size: 69120 File Visible: - Signed: -
Status: -
Name: ptilink.sys
Image Path: D:\WINDOWS\system32\DRIVERS\ptilink.sys
Address: 0xF886E000 Size: 17792 File Visible: - Signed: -
Status: -
Name: PxHelp20.sys
Image Path: PxHelp20.sys
Address: 0xF8586000 Size: 35712 File Visible: - Signed: -
Status: -
Name: rasacd.sys
Image Path: D:\WINDOWS\system32\DRIVERS\rasacd.sys
Address: 0xF8234000 Size: 8832 File Visible: - Signed: -
Status: -
Name: rasl2tp.sys
Image Path: D:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Address: 0xF7D7E000 Size: 51328 File Visible: - Signed: -
Status: -
Name: raspppoe.sys
Image Path: D:\WINDOWS\system32\DRIVERS\raspppoe.sys
Address: 0xF7D6E000 Size: 41472 File Visible: - Signed: -
Status: -
Name: raspptp.sys
Image Path: D:\WINDOWS\system32\DRIVERS\raspptp.sys
Address: 0xF7D5E000 Size: 48384 File Visible: - Signed: -
Status: -
Name: raspti.sys
Image Path: D:\WINDOWS\system32\DRIVERS\raspti.sys
Address: 0xF8876000 Size: 16512 File Visible: - Signed: -
Status: -
Name: RAW
Image Path: \FileSystem\RAW
Address: 0x804D7000 Size: 2180480 File Visible: - Signed: -
Status: -
Name: rdbss.sys
Image Path: D:\WINDOWS\system32\DRIVERS\rdbss.sys
Address: 0xF6507000 Size: 174592 File Visible: - Signed: -
Status: -
Name: RDPCDD.sys
Image Path: D:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Address: 0xF8A72000 Size: 4224 File Visible: - Signed: -
Status: -
Name: redbook.sys
Image Path: D:\WINDOWS\system32\DRIVERS\redbook.sys
Address: 0xF7D9E000 Size: 57472 File Visible: - Signed: -
Status: -
Name: rootrepeal.sys
Image Path: D:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF278C000 Size: 49152 File Visible: No Signed: -
Status: -
Name: RT2500.sys
Image Path: D:\WINDOWS\system32\DRIVERS\RT2500.sys
Address: 0xF7B03000 Size: 211072 File Visible: - Signed: -
Status: -
Name: serenum.sys
Image Path: D:\WINDOWS\system32\DRIVERS\serenum.sys
Address: 0xF89E6000 Size: 15488 File Visible: - Signed: -
Status: -
Name: serial.sys
Image Path: D:\WINDOWS\system32\DRIVERS\serial.sys
Address: 0xF7DBE000 Size: 64896 File Visible: - Signed: -
Status: -
Name: sr.sys
Image Path: sr.sys
Address: 0xF846D000 Size: 73472 File Visible: - Signed: -
Status: -
Name: srv.sys
Image Path: D:\WINDOWS\system32\DRIVERS\srv.sys
Address: 0xF2F15000 Size: 333184 File Visible: - Signed: -
Status: -
Name: swenum.sys
Image Path: D:\WINDOWS\system32\DRIVERS\swenum.sys
Address: 0xF8A50000 Size: 4352 File Visible: - Signed: -
Status: -
Name: sysaudio.sys
Image Path: D:\WINDOWS\system32\drivers\sysaudio.sys
Address: 0xF334E000 Size: 60800 File Visible: - Signed: -
Status: -
Name: tcpip.sys
Image Path: D:\WINDOWS\system32\DRIVERS\tcpip.sys
Address: 0xF6595000 Size: 360320 File Visible: - Signed: -
Status: -
Name: TDI.SYS
Image Path: D:\WINDOWS\system32\DRIVERS\TDI.SYS
Address: 0xF8866000 Size: 20480 File Visible: - Signed: -
Status: -
Name: termdd.sys
Image Path: D:\WINDOWS\system32\DRIVERS\termdd.sys
Address: 0xF7D3E000 Size: 40704 File Visible: - Signed: -
Status: -
Name: update.sys
Image Path: D:\WINDOWS\system32\DRIVERS\update.sys
Address: 0xF7789000 Size: 364160 File Visible: - Signed: -
Status: -
Name: usbaudio.sys
Image Path: D:\WINDOWS\system32\drivers\usbaudio.sys
Address: 0xF8606000 Size: 59264 File Visible: - Signed: -
Status: -
Name: usbccgp.sys
Image Path: D:\WINDOWS\system32\DRIVERS\usbccgp.sys
Address: 0xF888E000 Size: 31616 File Visible: - Signed: -
Status: -
Name: USBD.SYS
Image Path: D:\WINDOWS\system32\DRIVERS\USBD.SYS
Address: 0xF8A56000 Size: 8192 File Visible: - Signed: -
Status: -
Name: usbehci.sys
Image Path: D:\WINDOWS\system32\DRIVERS\usbehci.sys
Address: 0xF883E000 Size: 26624 File Visible: - Signed: -
Status: -
Name: usbhub.sys
Image Path: D:\WINDOWS\system32\DRIVERS\usbhub.sys
Address: 0xF85D6000 Size: 57600 File Visible: - Signed: -
Status: -
Name: USBPORT.SYS
Image Path: D:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Address: 0xF7B37000 Size: 143360 File Visible: - Signed: -
Status: -
Name: usbuhci.sys
Image Path: D:\WINDOWS\system32\DRIVERS\usbuhci.sys
Address: 0xF8836000 Size: 20480 File Visible: - Signed: -
Status: -
Name: vga.sys
Image Path: D:\WINDOWS\System32\drivers\vga.sys
Address: 0xF889E000 Size: 20992 File Visible: - Signed: -
Status: -
Name: VIDEOPRT.SYS
Image Path: D:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Address: 0xF7B5A000 Size: 81920 File Visible: - Signed: -
Status: -
Name: VolSnap.sys
Image Path: VolSnap.sys
Address: 0xF8556000 Size: 52352 File Visible: - Signed: -
Status: -
Name: wanarp.sys
Image Path: D:\WINDOWS\system32\DRIVERS\wanarp.sys
Address: 0xF8636000 Size: 34560 File Visible: - Signed: -
Status: -
Name: watchdog.sys
Image Path: D:\WINDOWS\System32\watchdog.sys
Address: 0xF88CE000 Size: 20480 File Visible: - Signed: -
Status: -
Name: wdmaud.sys
Image Path: D:\WINDOWS\system32\drivers\wdmaud.sys
Address: 0xF31C9000 Size: 82944 File Visible: - Signed: -
Status: -
Name: Win32k
Image Path: \Driver\Win32k
Address: 0xBF800000 Size: 1847296 File Visible: - Signed: -
Status: -
Name: win32k.sys
Image Path: D:\WINDOWS\System32\win32k.sys
Address: 0xBF800000 Size: 1847296 File Visible: - Signed: -
Status: -
Name: win32k.sys:1
Image Path: D:\WINDOWS\win32k.sys:1
Address: 0xF88F6000 Size: 20480 File Visible: No Signed: -
Status: -
Name: win32k.sys:2
Image Path: D:\WINDOWS\win32k.sys:2
Address: 0xF63C6000 Size: 61440 File Visible: No Signed: -
Status: -
Name: WMILIB.SYS
Image Path: D:\WINDOWS\system32\DRIVERS\WMILIB.SYS
Address: 0xF8A38000 Size: 8192 File Visible: - Signed: -
Status: -
Name: WMIxWDM
Image Path: \Driver\WMIxWDM
Address: 0x804D7000 Size: 2180480 File Visible: - Signed: -
Status: -
OTL
OTL logfile created on: 06/10/2009 23:57:29 - Run 1
OTL by OldTimer - Version 3.0.18.4 Folder = D:\Documents and Settings\Will\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
510.98 Mb Total Physical Memory | 195.20 Mb Available Physical Memory | 38.20% Memory free
1.22 Gb Paging File | 0.89 Gb Available in Paging File | 73.18% Paging File free
Paging file location(s): D:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 232.82 Gb Total Space | 223.11 Gb Free Space | 95.83% Space Free | Partition Type: NTFS
Drive D: | 152.66 Gb Total Space | 91.87 Gb Free Space | 60.18% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MAINWILL
Current User Name: Will
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2007/06/13 11:23:07 | 01,033,216 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Explorer.EXE
PRC - [2008/08/29 00:53:18 | 00,303,104 | ---- | M] (Motive Communications, Inc.) -- D:\Program Files\Common Files\Motive\McciCMService.exe
PRC - [2003/12/09 13:03:08 | 00,057,344 | ---- | M] (Yahoo!, Inc.) -- D:\Program Files\Yahoo!\browser\ybrwicon.exe
PRC - [2003/08/29 05:59:24 | 00,122,880 | ---- | M] (Broadcom Corporation) -- D:\WINDOWS\BCMSMMSG.exe
PRC - [2009/09/14 17:56:46 | 01,584,640 | ---- | M] (Alcatel-Lucent) -- D:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
PRC - [2003/05/08 12:00:58 | 00,049,152 | ---- | M] (ScanSoft, Inc.) -- D:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
PRC - [2004/09/08 11:20:22 | 00,327,765 | ---- | M] (Belkin) -- D:\Program Files\Belkin\Belkin 802.11g Wireless PCI Card Configuration Utility\utility.exe
PRC - [2004/07/15 11:56:56 | 00,581,632 | ---- | M] (Logitech Inc.) -- D:\Program Files\Logitech\SetPoint\KEM.exe
PRC - [2006/03/03 15:18:10 | 00,200,704 | ---- | M] (Yahoo!, Inc.) -- D:\Program Files\Yahoo!\browser\ycommon.exe
PRC - [2003/10/15 18:32:00 | 00,192,512 | R--- | M] (Microsoft Corp.) -- D:\Program Files\Winter Fun Pack 2004 for Windows XP\WinterWallToy\WinterWalltoy.exe
PRC - [2009/01/14 13:00:00 | 00,525,664 | R--- | M] (WinZip Computing, S.L.) -- D:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2007/11/22 11:49:08 | 00,385,024 | ---- | M] (Sony Corporation) -- D:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
PRC - [2005/08/31 18:11:08 | 00,090,112 | ---- | M] () -- D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
PRC - [2004/06/08 12:31:38 | 00,029,696 | ---- | M] (Logitech Inc.) -- D:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
PRC - [2009/10/06 22:55:50 | 02,023,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/08/22 10:21:23 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/08/22 10:21:38 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/08/22 10:21:33 | 00,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/08/22 10:21:26 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/08/22 10:21:37 | 00,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2009/10/06 23:53:42 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Will\Desktop\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - File not found -- -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/08/22 10:21:26 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Running])
SRV - [2009/08/22 10:21:23 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - File not found -- -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/08/05 21:02:05 | 00,133,104 | ---- | M] (Google Inc.) -- D:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate [Auto | Stopped])
SRV - [2004/08/04 13:00:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - File not found -- -- (JavaQuickStarterService [Auto | Stopped])
SRV - [2008/08/29 00:53:18 | 00,303,104 | ---- | M] (Motive Communications, Inc.) -- D:\Program Files\Common Files\Motive\McciCMService.exe -- (McciCMService [Auto | Running])
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2003/05/19 17:07:38 | 00,086,016 | ---- | M] (Yahoo! Inc.) -- D:\WINDOWS\system32\YPcservice.exe -- (YPCService [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi...arch.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe...-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - D:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: avg@igeared:2.507.024.001
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14
FF - prefs.js..network.proxy.no_proxies_on: "127.0.0.1"
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: D:\Program Files\AVG\AVG8\Firefox [2009/10/06 22:50:02 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: D:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared [2009/08/23 23:11:27 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: D:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/10/06 22:57:26 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2009/09/10 12:43:00 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2009/10/06 22:46:43 | 00,000,000 | ---D | M]
[2008/11/15 02:44:06 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\mozilla\Extensions
[2008/11/15 02:44:06 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/11/15 02:44:06 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\mozilla\Firefox\Profiles\874ky92u.default\extensions
[2009/10/06 22:28:57 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions
[2009/09/10 12:43:00 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/10/06 22:57:25 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/09/10 12:42:49 | 00,023,032 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/10 12:42:50 | 00,134,648 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/06/27 17:03:12 | 01,446,440 | ---- | M] (Microsoft Corporation) -- D:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/09/10 12:42:53 | 00,065,528 | ---- | M] (mozilla.org) -- D:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/06/16 20:44:48 | 00,001,538 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2009/06/16 20:44:48 | 00,002,193 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/12 09:33:38 | 00,001,465 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\avg_igeared.xml
[2009/06/16 20:44:48 | 00,000,947 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2009/06/16 20:44:48 | 00,001,534 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/06/16 20:44:48 | 00,000,759 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2009/06/16 20:44:48 | 00,001,706 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/06/16 20:44:48 | 00,001,178 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/06/16 20:44:48 | 00,000,831 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: (302468 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10428 more lines...
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (UberButton Class) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo!)
O2 - BHO: (YahooTaggedBM Class) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - D:\Program Files\Yahoo!\Common\YIeTagBm.dll (Yahoo! Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - D:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll File not found
O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - D:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - D:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - D:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] D:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BCMSMMSG] D:\WINDOWS\BCMSMMSG.exe (Broadcom Corporation)
O4 - HKLM..\Run: [btbb_McciTrayApp] D:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [OpwareSE2] D:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [YBrowser] D:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo!, Inc.)
O4 - HKCU..\Run: [eyeBeam SIP Client] File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKCU..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Belkin 802.11g Wireless PCI Card Configuration Utility.lnk = D:\Program Files\Belkin\Belkin 802.11g Wireless PCI Card Configuration Utility\utility.exe (Belkin)
O4 - Startup: D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech SetPoint.lnk = D:\Program Files\Logitech\SetPoint\KEM.exe (Logitech Inc.)
O4 - Startup: D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Winter Fun Wallpaper Changer.lnk = D:\WINDOWS\Installer\{038A524F-58DB-438A-8391-8F7F0CA14B9E}\Icon038A524F.exe ()
O4 - Startup: D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O4 - Startup: D:\Documents and Settings\Will\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = D:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo!)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O12 - Plugin for: .spop - D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: motive.com ([pbttbc.bt] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} D:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://D:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - application/octet-stream - File not found
O18 - Protocol\Filter: - application/x-complus - File not found
O18 - Protocol\Filter: - application/x-msdownload - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll File not found
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - D:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - D:\Program Files\SUPERAntiSpyware\SASSEH.DLL File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/30 01:49:32 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{5f3400db-fe42-11dc-9421-001150141f44}\Shell\AutoRun\command - "" = G:\setupSNK.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - D:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: Wmi - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ==========
[2009/10/05 22:58:13 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
[2009/10/06 23:39:20 | 00,000,000 | ---D | C] -- D:\Documents and Settings\Will\Application Data\Malwarebytes
[2009/10/05 23:12:50 | 00,000,000 | ---D | C] -- D:\Documents and Settings\Will\Application Data\SUPERAntiSpyware.com
[2009/10/06 23:39:10 | 00,000,000 | ---D | C] -- D:\Program Files\Anti-Malware
[2009/10/06 19:31:57 | 00,000,000 | ---D | C] -- D:\Program Files\ERUNT
[2009/10/06 02:21:50 | 00,000,000 | ---D | C] -- D:\Program Files\Panda Security
[2009/10/05 23:12:50 | 00,000,000 | ---D | C] -- D:\Program Files\SUPERAntiSpyware
[2009/10/06 23:53:40 | 00,520,704 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Will\Desktop\OTL.exe
[2009/10/06 23:40:41 | 00,472,064 | ---- | C] ( ) -- D:\Documents and Settings\Will\Desktop\RootRepeal.exe
[2009/10/06 23:35:39 | 04,045,536 | ---- | C] (Malwarebytes Corporation ) -- D:\Documents and Settings\Will\Desktop\Mattock1.exe
[2009/10/06 22:46:43 | 00,000,000 | ---D | C] -- D:\Config.Msi
[2009/10/06 19:32:58 | 00,000,000 | ---D | C] -- D:\WINDOWS\ERDNT
[2009/10/06 19:25:25 | 00,000,000 | ---D | C] -- D:\WINDOWS\assembly
[2009/10/06 19:24:06 | 00,000,000 | ---D | C] -- D:\WINDOWS\Microsoft.NET
[2009/10/05 22:58:15 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/05 22:58:13 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
========== Files - Modified Within 14 Days ==========
[2009/10/07 00:00:00 | 00,000,274 | -H-- | M] () -- D:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[2009/10/07 00:00:00 | 00,000,238 | -H-- | M] () -- D:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/10/06 23:55:28 | 04,915,254 | -H-- | M] () -- D:\WINDOWS\System32\toyhide.bmp
[2009/10/06 23:53:42 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Will\Desktop\OTL.exe
[2009/10/06 23:41:02 | 00,000,000 | ---- | M] () -- D:\Documents and Settings\Will\Desktop\settings.dat
[2009/10/06 23:40:42 | 00,472,064 | ---- | M] ( ) -- D:\Documents and Settings\Will\Desktop\RootRepeal.exe
[2009/10/06 23:39:15 | 00,000,626 | ---- | M] () -- D:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/06 23:36:03 | 04,045,536 | ---- | M] (Malwarebytes Corporation ) -- D:\Documents and Settings\Will\Desktop\Mattock1.exe
[2009/10/06 23:12:17 | 00,047,616 | ---- | M] () -- D:\Documents and Settings\Will\Desktop\Win32kDiag.exe
[2009/10/06 23:07:01 | 00,000,882 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/10/06 22:58:07 | 00,009,280 | ---- | M] () -- D:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/10/06 22:58:06 | 42,401,219 | ---- | M] () -- D:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/10/06 22:53:19 | 00,002,405 | ---- | M] () -- D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Winter Fun Wallpaper Changer.lnk
[2009/10/06 22:52:15 | 00,000,878 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/10/06 22:52:12 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2009/10/06 22:51:58 | 00,000,000 | ---- | M] () -- D:\WINDOWS\win32k.sys
[2009/10/06 22:51:57 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2009/10/06 22:51:56 | 53,587,1488 | -HS- | M] () -- D:\hiberfil.sys
[2009/10/06 22:33:10 | 00,013,646 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2009/10/06 22:15:55 | 04,240,656 | -H-- | M] () -- D:\Documents and Settings\Will\Local Settings\Application Data\IconCache.db
[2009/10/06 19:28:37 | 00,392,604 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2009/10/06 19:28:37 | 00,058,712 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2009/10/06 17:56:08 | 00,000,231 | ---- | M] () -- D:\WINDOWS\system.ini
[2009/10/06 00:43:30 | 00,492,629 | ---- | M] () -- D:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/10/06 00:19:35 | 00,025,476 | ---- | M] () -- D:\AVG Resident Shield List 5-10-09.csv
[2009/09/30 20:27:14 | 00,356,120 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI
[2009/09/30 18:38:20 | 00,001,087 | ---- | M] () -- D:\Documents and Settings\All Users.WINDOWS\Desktop\BT Broadband Desktop Help.lnk
[2009/09/27 12:55:59 | 00,002,265 | ---- | M] () -- D:\Documents and Settings\All Users.WINDOWS\Desktop\Skype.lnk
========== Files - No Company Name ==========
[2009/10/06 23:41:02 | 00,000,000 | ---- | C] () -- D:\Documents and Settings\Will\Desktop\settings.dat
[2009/10/06 23:12:15 | 00,047,616 | ---- | C] () -- D:\Documents and Settings\Will\Desktop\Win32kDiag.exe
[2009/10/06 22:18:32 | 53,587,1488 | -HS- | C] () -- D:\hiberfil.sys
[2009/10/06 00:19:35 | 00,025,476 | ---- | C] () -- D:\AVG Resident Shield List 5-10-09.csv
[2009/10/05 22:58:19 | 00,000,626 | ---- | C] () -- D:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/01 00:32:28 | 00,000,238 | -H-- | C] () -- D:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/10/01 00:32:03 | 00,000,274 | -H-- | C] () -- D:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[2009/10/01 00:31:57 | 00,000,000 | ---- | C] () -- D:\WINDOWS\win32k.sys
[2009/09/30 18:38:20 | 00,001,087 | ---- | C] () -- D:\Documents and Settings\All Users.WINDOWS\Desktop\BT Broadband Desktop Help.lnk
[2008/10/20 22:37:33 | 04,240,656 | -H-- | C] () -- D:\Documents and Settings\Will\Local Settings\Application Data\IconCache.db
[2008/05/14 23:46:33 | 00,015,080 | ---- | C] () -- D:\Documents and Settings\Will\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/03/30 11:17:08 | 00,040,960 | ---- | C] () -- D:\Documents and Settings\Will\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/03/27 00:25:12 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\Will\Application Data\desktop.ini
[2008/03/27 00:08:20 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\All Users.WINDOWS\Application Data\desktop.ini
========== LOP Check ==========
[2009/10/06 21:35:47 | 00,000,000 | RH-D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data
[2009/09/08 16:02:11 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
[2008/10/31 20:34:12 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Motive
[2008/04/06 22:07:39 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\SSScanAppDataDir
[2008/04/06 22:07:39 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\SSScanWizard
[2008/11/19 22:36:50 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\WhiteCap (Holiday Edition)
[2009/02/21 17:16:59 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
[2009/10/06 23:39:20 | 00,000,000 | RH-D | M] -- D:\Documents and Settings\Will\Application Data
[2008/03/27 20:32:23 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\ArcSoft
[2009/05/24 11:10:38 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\AVGTOOLBAR
[2008/06/15 23:30:31 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\dvdcss
[2008/04/06 22:05:26 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\InterTrust
[2008/10/31 20:34:16 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\Motive
[2009/10/05 21:32:30 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\OpenOffice.org2
[2008/04/06 22:07:40 | 00,000,000 | ---D | M] -- D:\Documents and Settings\Will\Application Data\ScanSoft
[2004/08/04 13:00:00 | 00,000,065 | RH-- | M] () -- D:\WINDOWS\Tasks\desktop.ini
[2009/10/06 22:52:15 | 00,000,878 | ---- | M] () -- D:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/10/06 23:07:01 | 00,000,882 | ---- | M] () -- D:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009/10/06 22:52:12 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\Tasks\SA.DAT
[2009/10/07 00:00:00 | 00,000,238 | -H-- | M] () -- D:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/10/07 00:00:00 | 00,000,274 | -H-- | M] () -- D:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2007/10/30 20:16:20 | 30,422,984 | ---- | M] () -- D:\avg75free_503a1171.exe
[2007/11/18 10:49:39 | 09,679,815 | ---- | M] () -- D:\vlc-0.8.6c-win32.exe
< %systemroot%\system32\eventlog.dll >
[2004/08/04 13:00:00 | 00,061,952 | ---- | M] () -- D:\WINDOWS\system32\eventlog.dll
< %systemroot%\system32\scecli.dll >
[2004/08/04 13:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\scecli.dll
< %systemroot%\netlogon.dll >
< %systemroot%\system32\cngaudit.dll >
< %systemroot%\system32\sceclt.dll >
< %systemroot%\ntelogon.dll >
< %systemroot%\system32\logevent.dll >
[2004/08/04 13:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\logevent.dll
< End of report >
EXTRAS
OTL Extras logfile created on: 06/10/2009 23:57:29 - Run 1
OTL by OldTimer - Version 3.0.18.4 Folder = D:\Documents and Settings\Will\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
510.98 Mb Total Physical Memory | 195.20 Mb Available Physical Memory | 38.20% Memory free
1.22 Gb Paging File | 0.89 Gb Available in Paging File | 73.18% Paging File free
Paging file location(s): D:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 232.82 Gb Total Space | 223.11 Gb Free Space | 95.83% Space Free | Partition Type: NTFS
Drive D: | 152.66 Gb Total Space | 91.87 Gb Free Space | 60.18% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MAINWILL
Current User Name: Will
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- D:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- D:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "D:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "D:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "D:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "D:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "D:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "D:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "D:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Program Files\Grisoft\AVG7\avginet.exe" = D:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe -- File not found
"D:\Program Files\Grisoft\AVG7\avgamsvr.exe" = D:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe -- File not found
"D:\Program Files\Grisoft\AVG7\avgcc.exe" = D:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe -- File not found
"D:\Program Files\Yahoo!\Messenger\ypager.exe" = D:\Program Files\Yahoo!\Messenger\ypager.exe:*:Enabled:Yahoo! Messenger -- ()
"D:\Program Files\Yahoo!\Messenger\YServer.exe" = D:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- (Yahoo! Inc.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"D:\Program Files\BT Broadband Desktop Help\bin\BTHelpBrowser.exe" = D:\Program Files\BT Broadband Desktop Help\bin\BTHelpBrowser.exe:*:Enabled:BT Broadband Desktop Help Browser -- File not found
"D:\Program Files\Internet Explorer\iexplore.exe" = D:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer -- (Microsoft Corporation)
"D:\Program Files\AVG\AVG8\avgupd.exe" = D:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"D:\Program Files\AVG\AVG8\avgemc.exe" = D:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"D:\Program Files\Mozilla Firefox\firefox.exe" = D:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"D:\Program Files\Skype\Phone\Skype.exe" = D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"D:\Program Files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe" = D:\Program Files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe:*:Enabled:BT Broadband Desktop Help -- (Alcatel-Lucent)
"D:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" = D:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe:*:Enabled:BT Broadband Desktop Help Notifier -- (Alcatel-Lucent)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{038A524F-58DB-438A-8391-8F7F0CA14B9E}" = MicrosoftŪ Winter Fun Pack 2004 for WindowsŪ XP
"{088A077A-8028-408C-AE7B-4512AE2A65A0}" = Canon CanoScan Toolbox 4.7
"{230CCBE9-14B0-4008-97AF-30C10F99E42C}" = ArcSoft PhotoStudio 5.5
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java 6 Update 15
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{2F29D6D2-824E-4FEF-8AED-7013F39F642A}" = OpenOffice.org 2.3
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{362BFFCD-8274-11D8-97C8-000129760CBE}" = MediaLife
"{52C8FAA0-68CA-4AF9-8A7A-92CF3174CC77}" = Windows Media Player 9 Series Winter Fun Pack
"{59C2635E-336A-4CDF-8936-994F989E67D1}" = Belkin 802.11g Wireless PCI Card
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7523F68F-3DA4-452A-A17F-4AF55A8A25BB}" = ChristmasTheme
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{CABB50D8-AC2C-4C59-BF8A-71F073B88B3B}" = Manual CanoScan 5200F
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype 4.1
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"AC3Filter" = AC3Filter (remove only)
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG8Uninstall" = AVG Free 8.5
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"BT Broadband Desktop Help" = BT Broadband Desktop Help
"BT Home Hub" = BT Home Hub
"BT Wireless Connection Manager" = BT Wireless Connection Manager
"BT Yahoo! Applications" = BT Yahoo! Applications
"ERUNT_is1" = ERUNT 1.1j
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.0.14)" = Mozilla Firefox (3.0.14)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"RealPlayer 6.0" = RealPlayer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Toolbar" = Yahoo! Toolbar
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 06/10/2009 07:07:05 | Computer Name = MAINWILL | Source = Google Update | ID = 20
Description =
Error - 06/10/2009 08:07:05 | Computer Name = MAINWILL | Source = Google Update | ID = 20
Description =
Error - 06/10/2009 09:07:05 | Computer Name = MAINWILL | Source = Google Update | ID = 20
Description =
Error - 06/10/2009 10:07:05 | Computer Name = MAINWILL | Source = Google Update | ID = 20
Description =
Error - 06/10/2009 11:07:05 | Computer Name = MAINWILL | Source = Google Update | ID = 20
Description =
Error - 06/10/2009 12:07:05 | Computer Name = MAINWILL | Source = Google Update | ID = 20
Description =
Error - 06/10/2009 13:07:08 | Computer Name = MAINWILL | Source = Google Update | ID = 20
Description =
Error - 06/10/2009 15:39:45 | Computer Name = MAINWILL | Source = Application Error | ID = 1000
Description = Faulting application teatimer.exe, version 1.6.4.26, faulting module
teatimer.exe, version 1.6.4.26, fault address 0x0006e60e.
Error - 06/10/2009 16:38:45 | Computer Name = MAINWILL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 06/10/2009 16:38:45 | Computer Name = MAINWILL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
[ System Events ]
Error - 06/10/2009 17:17:28 | Computer Name = MAINWILL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 06/10/2009 17:19:49 | Computer Name = MAINWILL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
pavboot SASDIFSV SASKUTIL
Error - 06/10/2009 17:19:53 | Computer Name = MAINWILL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Application Layer Gateway
Service service to connect.
Error - 06/10/2009 17:19:53 | Computer Name = MAINWILL | Source = Service Control Manager | ID = 7000
Description = The Application Layer Gateway Service service failed to start due
to the following error: %%1053
Error - 06/10/2009 17:52:29 | Computer Name = MAINWILL | Source = Service Control Manager | ID = 7000
Description = The Java Quick Starter service failed to start due to the following
error: %%2
Error - 06/10/2009 17:52:31 | Computer Name = MAINWILL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
pavboot SASDIFSV SASKUTIL
Error - 06/10/2009 17:52:37 | Computer Name = MAINWILL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Application Layer Gateway
Service service to connect.
Error - 06/10/2009 17:52:37 | Computer Name = MAINWILL | Source = Service Control Manager | ID = 7000
Description = The Application Layer Gateway Service service failed to start due
to the following error: %%1053
Error - 06/10/2009 17:59:58 | Computer Name = MAINWILL | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the avg8wd service.
Error - 06/10/2009 18:13:56 | Computer Name = MAINWILL | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000000D'
while processing the file 'addins' on the volume 'HarddiskVolume2'. It has stopped
monitoring the volume.
< End of report >
