Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account

iexplorer 100% cpu

  • Please log in to reply



    New Member

  • Member
  • Pip
  • 1 posts
OTL logfile created on: 2011-04-22 12:46:01 - Run 1
OTL by OldTimer - Version Folder = C:\Documents and Settings\EriAnns\Skrivbord
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

767,00 Mb Total Physical Memory | 406,00 Mb Available Physical Memory | 53,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program
Drive C: | 74,52 Gb Total Space | 58,92 Gb Free Space | 79,06% Space Free | Partition Type: NTFS
Drive D: | 189,92 Gb Total Space | 128,62 Gb Free Space | 67,73% Space Free | Partition Type: NTFS

Computer Name: ERIANN | User Name: EriAnns | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011-04-22 12:45:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\EriAnns\Skrivbord\OTL.exe
PRC - [2011-02-23 17:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program\Alwil Software\Avast5\AvastUI.exe
PRC - [2011-02-23 17:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program\Alwil Software\Avast5\AvastSvc.exe
PRC - [2008-04-14 18:05:06 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

========== Modules (SafeList) ==========

MOD - [2011-04-22 12:45:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\EriAnns\Skrivbord\OTL.exe
MOD - [2011-02-23 17:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program\Alwil Software\Avast5\snxhk.dll
MOD - [2010-08-23 18:12:54 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll

========== Win32 Services (SafeList) ==========

SRV - [2011-02-23 17:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)

========== Driver Services (SafeList) ==========

DRV - [2011-02-23 16:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011-02-23 16:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011-02-23 16:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011-02-23 16:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011-02-23 16:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011-02-23 16:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011-02-23 16:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010-07-24 16:40:19 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008-10-09 15:42:42 | 000,017,408 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2008-04-13 20:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2006-02-21 20:46:26 | 001,505,792 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2003-09-22 12:43:06 | 001,330,048 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\P16X.sys -- (P16X) Creative SB Live! Series (WDM)
DRV - [2003-09-22 08:48:06 | 000,130,192 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2003-09-22 08:47:38 | 000,178,672 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2003-03-05 12:19:28 | 000,015,840 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PFMODNT.SYS -- (PfModNT)
DRV - [2002-10-15 15:59:24 | 000,017,153 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
DRV - [2001-08-17 22:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: ([2010-04-22 09:02:03 | 000,000,757 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: localhost
O1 - Hosts: mpa.one.microsoft.com
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live inloggningshjälpen) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [avast5] C:\Program\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Value error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1271919496652 (WUWebControl Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Value error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail....ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Min aktuella startsida) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\EriAnns\Lokala inställningar\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\EriAnns\Lokala inställningar\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-04-21 21:48:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{5f492e7e-0609-11e0-aca5-0007e9aa2dcc}\Shell\AutoRun\command - "" = G:\Launcher.exe
O33 - MountPoints2\{95043c37-4e0b-11df-a9f6-0007e9aa2dcc}\Shell\AutoRun\command - "" = F:\.\Windows\ConnectionManager_MD400.exe
O34 - HKLM BootExecute: (autocheck autochk /p \??\C) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011-04-22 12:45:37 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\EriAnns\Skrivbord\OTL.exe
[2011-04-22 09:41:30 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\EriAnns\Recent
[2011-04-13 17:54:06 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010-04-21 22:03:55 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011-04-22 12:45:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\EriAnns\Skrivbord\OTL.exe
[2011-04-22 12:06:12 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-04-22 12:05:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-04-22 11:43:30 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011-04-21 08:54:15 | 000,101,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011-04-21 08:40:51 | 000,523,672 | ---- | M] () -- C:\WINDOWS\System32\perfh01D.dat
[2011-04-21 08:40:51 | 000,502,772 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-04-21 08:40:51 | 000,111,434 | ---- | M] () -- C:\WINDOWS\System32\perfc01D.dat
[2011-04-21 08:40:51 | 000,088,296 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-04-13 17:59:15 | 000,000,783 | ---- | M] () -- C:\Documents and Settings\EriAnns\Application Data\Microsoft\Internet Explorer\Quick Launch\Starta webbläsaren Internet Explorer.lnk
[2011-04-13 11:23:07 | 000,000,368 | ---- | M] () -- C:\WINDOWS\tasks\AWC Update.job
[2011-04-10 21:47:32 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011-04-13 17:41:21 | 000,000,783 | ---- | C] () -- C:\Documents and Settings\EriAnns\Application Data\Microsoft\Internet Explorer\Quick Launch\Starta webbläsaren Internet Explorer.lnk
[2011-04-13 17:41:20 | 000,000,771 | ---- | C] () -- C:\Documents and Settings\EriAnns\Start-meny\Program\Internet Explorer.lnk
[2010-07-25 23:25:06 | 000,000,085 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2010-07-24 07:12:04 | 000,000,020 | ---- | C] () -- C:\WINDOWS\popcinfot.dat
[2010-04-22 14:39:03 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\EriAnns\Lokala inställningar\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-04-22 11:40:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010-04-22 11:37:46 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2010-04-22 10:27:31 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\EriAnns\Lokala inställningar\Application Data\fusioncache.dat
[2010-04-21 23:38:47 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010-04-21 23:37:39 | 000,101,440 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-04-21 22:04:23 | 000,000,065 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2010-04-21 22:03:55 | 000,047,616 | ---- | C] () -- C:\WINDOWS\System32\P16X.dll
[2010-04-21 22:03:55 | 000,002,696 | ---- | C] () -- C:\WINDOWS\MIXDEF.INI
[2010-04-21 22:03:55 | 000,002,516 | ---- | C] () -- C:\WINDOWS\System32\P16X.ini
[2010-04-21 22:03:55 | 000,000,026 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2010-04-21 21:51:56 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010-04-21 21:45:25 | 000,021,700 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-02-11 06:12:00 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2010-02-11 06:12:00 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2008-05-26 23:10:02 | 000,014,772 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008-05-26 23:10:00 | 000,022,298 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008-05-26 23:09:58 | 000,014,614 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008-05-26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008-05-26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2006-02-13 13:29:26 | 000,121,995 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2004-08-04 01:49:04 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004-08-04 01:33:42 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2004-08-04 01:33:42 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2004-08-04 01:33:42 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2004-08-04 01:33:42 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2004-08-04 01:33:42 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2004-08-02 14:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001-09-28 16:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001-09-28 16:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001-09-28 16:00:00 | 000,523,672 | ---- | C] () -- C:\WINDOWS\System32\perfh01D.dat
[2001-09-28 16:00:00 | 000,502,772 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001-09-28 16:00:00 | 000,274,932 | ---- | C] () -- C:\WINDOWS\System32\perfi01D.dat
[2001-09-28 16:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001-09-28 16:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001-09-28 16:00:00 | 000,111,434 | ---- | C] () -- C:\WINDOWS\System32\perfc01D.dat
[2001-09-28 16:00:00 | 000,088,296 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001-09-28 16:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001-09-28 16:00:00 | 000,033,234 | ---- | C] () -- C:\WINDOWS\System32\perfd01D.dat
[2001-09-28 16:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001-09-28 16:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001-09-28 16:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FCCDF7B1

< End of report >
OTL Extras logfile created on: 2011-04-22 12:46:01 - Run 1
OTL by OldTimer - Version Folder = C:\Documents and Settings\EriAnns\Skrivbord
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

767,00 Mb Total Physical Memory | 406,00 Mb Available Physical Memory | 53,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program
Drive C: | 74,52 Gb Total Space | 58,92 Gb Free Space | 79,06% Space Free | Partition Type: NTFS
Drive D: | 189,92 Gb Total Space | 128,62 Gb Free Space | 67,73% Space Free | Partition Type: NTFS

Computer Name: ERIANN | User Name: EriAnns | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.html [@ = htmlfile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

"Start" = 0

"Start" = 2

========== Firewall Settings ==========


"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - kompatibilitetsläge (HTTP-in)

========== Authorized Applications List ==========


"C:\Program\Spotify\spotify.exe" = C:\Program\Spotify\spotify.exe:*:Enabled:Spotify -- (Spotify Ltd)
"C:\Program\TalismanOnline\game.exe" = C:\Program\TalismanOnline\game.exe:*:Enabled:Talisman Online -- ()
"C:\Program\Alwil Software\Avast5\AvastUI.exe" = C:\Program\Alwil Software\Avast5\AvastUI.exe:*:Enabled:avast! Free Antivirus -- (AVAST Software)
"C:\Program\Adobe\Reader 9.0\Reader\AcroRd32.exe" = C:\Program\Adobe\Reader 9.0\Reader\AcroRd32.exe:*:Disabled:AcroRd32 -- (Adobe Systems Incorporated)
"C:\Program\DC++\DCPlusPlus.exe" = C:\Program\DC++\DCPlusPlus.exe:*:Enabled:DC++ -- ()

========== HKEY_LOCAL_MACHINE Uninstall List ==========

"{03ADC8AB-C130-0C3D-1FF9-2C385DF25689}" = CCC Help Czech
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07021185-008D-ABF9-7716-475AC035F8B3}" = CCC Help Spanish
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0E93710D-31E5-477C-8A4B-5032B484BE74}" = Windows Live inloggningsassistenten
"{0F8D0406-7755-AC37-6529-73AD649DBE32}" = Catalyst Control Center Graphics Previews Common
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22072CC8-7230-96F8-52F4-05EAF3F906B6}" = CCC Help Polish
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2368ADBD-6FDF-4B9F-FE41-E20B4D78E79E}" = CCC Help Chinese Standard
"{25EF0DC4-B072-2E04-4581-A13C91423CE6}" = CCC Help Portuguese
"{26F7855C-443B-00A6-F7B8-A97A5403F617}" = CCC Help Danish
"{296D775C-839A-3618-8D5C-E2B588C5CD12}" = Microsoft .NET Framework 4 Extended SVE Language Pack
"{2CB4A925-48A7-DA65-DCEE-D4DE224B7D84}" = CCC Help English
"{306D75B9-7FFF-FF65-0C76-57F2FE4FE1D6}" = Catalyst Control Center Core Implementation
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32B12FE4-5A51-751A-1FB6-A14E97EBDD5C}" = CCC Help German
"{350C941d-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{351512E5-01BD-E878-6F57-AA3E517D9ECE}" = Skins
"{354A387E-0374-21A3-6832-335674A6D7D1}" = CCC Help French
"{3C00BEE9-26D0-D9E0-A2D1-62F70D412A12}" = CCC Help Turkish
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4346F7AA-3D56-0941-424C-4454E04D37F6}" = CCC Help Italian
"{4CAE2F2C-75CD-A0DE-7520-449BCBBCC833}" = CCC Help Korean
"{57F7F0A5-8F22-8E63-E819-803B5C9CA3A5}" = CCC Help Dutch
"{5EA437D2-7A57-B60E-E8F2-76BFAC0895A5}" = CCC Help Chinese Traditional
"{61AF4E75-050E-0304-3417-8BC16417FEB1}" = CCC Help Greek
"{632005DA-C291-5275-284C-5EE96B05C714}" = Catalyst Control Center HydraVision Full
"{69EA986B-B172-4FAA-B54D-853BD3A2B264}" = Popcap Game Collection
"{6C72BE0C-3E25-CACD-0070-2FD9C02ABA14}" = ccc-core-preinstall
"{77701BFD-3A86-34B0-A9EC-0D7440C6D8AF}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - SVE
"{7D7152AF-581B-316F-8CA4-15342C3EFA4B}" = Microsoft .NET Framework 3.5 Language Pack SP1 - sve
"{880BB617-914E-17E8-D877-A96BAC5794D2}" = Catalyst Control Center Graphics Full New
"{8897CF22-DB6C-8248-895C-12BFA2677F51}" = CCC Help Hungarian
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live!
"{992A2DB1-4ABC-4738-BD71-045C5FFE00D1}" = Microsoft .NET Framework 1.1 Swedish Language Pack
"{9BBE7AA1-AFA8-4D76-8FC2-1FDFD9BD3371}" = Windows Live Mail
"{9D71329D-95A5-4297-8F79-DCDBD156420A}" = Windows Live Essentials
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AA8CF3BD-6717-3B70-83BF-377426410A66}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - SVE
"{AC76BA86-7AD7-1053-7B44-A94000000001}" = Adobe Reader 9.4.2 - Svenska
"{AF710FDE-2815-8C8D-5281-8004C2654AA6}" = CCC Help Russian
"{AFF2D965-C6F2-A210-FBF7-532612AA1D23}" = CCC Help Swedish
"{B21336EE-4AEF-9940-4AC7-EDB89854B8D3}" = CCC Help Thai
"{BBA69346-61A1-BD34-E75A-4D81232DB1FE}" = Catalyst Control Center Localization All
"{BFD5ED08-F066-92D5-BE67-3B9AE5DCFF0C}" = CCC Help Japanese
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4609F15-FB3C-D97E-BAA1-4F10815039C2}" = Catalyst Control Center Graphics Full Existing
"{C60AAF4C-A72C-36E0-8CA4-41FF753D74F6}" = Microsoft .NET Framework 4 Client Profile SVE Language Pack
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D01FAC3D-86B4-3A19-9D10-9156A0EB3EBE}" = CCC Help Finnish
"{D73722C8-3F65-C75B-A631-5D36894DAB92}" = ccc-core-static
"{DDAD33B6-8C00-428D-087B-A7088355B9BE}" = Catalyst Control Center Graphics Light
"{E333F074-FC7F-596D-3D61-44F0EC28E8C0}" = ccc-utility
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F13225E2-6533-4923-A657-083A151E667E}" = Windows Live Messenger
"{FA38F9E4-BED7-E021-B660-8FDFF7EC6E1A}" = CCC Help Norwegian
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"All ATI Software" = ATI - Hjälp för avinstallation av program
"ATI Display Driver" = ATI Display Driver
"avast" = avast! Free Antivirus
"Canon Digital Camera USB WIA Driver" = Canon Digital Camera USB WIA Driver
"CCleaner" = CCleaner
"DC++" = DC++ 0.699
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - sve" = Språkpaket för Microsoft .NET Framework 3.5 SP 1 - sve
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile SVE Language Pack" = Microsoft .NET Framework 4 Client Profile Language Pack - SVE
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended SVE Language Pack" = Microsoft .NET Framework 4 Extended Language Pack - SVE
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"PROSet" = Intel® PRO Ethernet Adapter and Software
"Spotify" = Spotify
"Talisman Online_is1" = Talisman Online Ver.1644
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"VLC media player" = VLC media player 1.0.5
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2011-04-13 11:39:14 | Computer Name = ERIANN | Source = Userenv | ID = 1041
Description = Det går inte att läsa {7B849a69-220F-451E-B3FE-2CB811AF94AE} från
registerposten DllName Detta kommer inte att läsas in. Problemet beror antagligen
på fel i registret.

Error - 2011-04-13 11:39:14 | Computer Name = ERIANN | Source = Userenv | ID = 1041
Description = Det går inte att läsa {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} från
registerposten DllName Detta kommer inte att läsas in. Problemet beror antagligen
på fel i registret.

Error - 2011-04-13 11:45:26 | Computer Name = ERIANN | Source = Userenv | ID = 1041
Description = Det går inte att läsa {7B849a69-220F-451E-B3FE-2CB811AF94AE} från
registerposten DllName Detta kommer inte att läsas in. Problemet beror antagligen
på fel i registret.

Error - 2011-04-13 11:45:26 | Computer Name = ERIANN | Source = Userenv | ID = 1041
Description = Det går inte att läsa {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} från
registerposten DllName Detta kommer inte att läsas in. Problemet beror antagligen
på fel i registret.

Error - 2011-04-13 11:45:26 | Computer Name = ERIANN | Source = Userenv | ID = 1041
Description = Det går inte att läsa {7B849a69-220F-451E-B3FE-2CB811AF94AE} från
registerposten DllName Detta kommer inte att läsas in. Problemet beror antagligen
på fel i registret.

Error - 2011-04-13 11:45:26 | Computer Name = ERIANN | Source = Userenv | ID = 1041
Description = Det går inte att läsa {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} från
registerposten DllName Detta kommer inte att läsas in. Problemet beror antagligen
på fel i registret.

Error - 2011-04-14 06:32:47 | Computer Name = ERIANN | Source = Windows Search Service | ID = 3013
Description = Det går inte att uppdatera posten <C:\DOCUMENTS AND SETTINGS\ERIANNS\RECENT\DESKTOP.INI>
i hash-mappningen. Kontext: program , katalog SystemIndex Information: En enhet som
är ansluten till datorn fungerar inte. (0x8007001f)

Error - 2011-04-14 07:03:40 | Computer Name = ERIANN | Source = Windows Search Service | ID = 3013
Description = Det går inte att uppdatera posten <C:\DOCUMENTS AND SETTINGS\ERIANNS\RECENT\DESKTOP.INI>
i hash-mappningen. Kontext: program , katalog SystemIndex Information: En enhet som
är ansluten till datorn fungerar inte. (0x8007001f)

Error - 2011-04-21 01:49:14 | Computer Name = ERIANN | Source = Application Error | ID = 1000
Description = Felaktigt program chrome.exe, version, felaktig modul gcswf32.dll,
version, felaktig adress 0x0018bdde.

Error - 2011-04-21 02:56:08 | Computer Name = ERIANN | Source = .NET Runtime Optimization Service | ID = 1103
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Tried to start a service that wasn't the latest version of CLR Optimization service.
Will shutdown

[ System Events ]
Error - 2011-04-22 06:13:39 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:13:42 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:13:44 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:13:59 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:14:00 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:14:01 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:14:16 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:14:16 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:14:31 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:14:32 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

< End of report >
  • 0




    Malware Expert

  • Expert
  • 24,709 posts
  • MVP
If you look in your Extras log you will see that the Remote Access Connection Manager is trying to start but can't because it can't find the file.

Error - 2011-04-22 06:13:42 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Error - 2011-04-22 06:13:44 | Computer Name = ERIANN | Source = Service Control Manager | ID = 7001
Description = Tjänsten Remote Access Connection Manager är beroende av tjänsten
Telephony. Den sistnämnda kunde inte starta på grund av följande fel: %%1058

Appears it is in an endless loop which I suspect is causing your CPU usage to max out.

See if you have the file:

rasmans.dll in C:\Windows\System32

This is easy to do in a command Prompt:

Start, Run, cmd, OK (or Start, All Programs, Accessories, Command Prompt) Then type (with an Enter after each line in the code box. Note that I use two spaces to show you where one space goes.)
cd  \
dir  /a  /s  rasmans.dll

The last command will take a while. When it finishes you should be able to see if the file is found in C:\windows\system32

If the file is not there but you see it located in another folder such as C:\windows\system32\dllcache\ you can copy the file:
copy  \windows\system32\dllcache\rasmans.dll  \windows\system32\

Try to start the service:

net  start  rasman

Another possibility is that the service is disabled in the hardware profile under Log On.
Start, Run, services.msc OK to bring up the Services window. Find the Remote Access Connection Manager and right click and select Properties. Click on the Log On tab. Look at the bottom where it says: Hardware Profile and Service. If it says Disabled under Service then click on the entry under Hardware Profile then hit Enable. OK. Try and Start the service now.

If this doesn't start the service then:

1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, but don't restart yet.

Start, Run, eventvwr.msc, OK to bring up the Event Viewer. (In Vista, next select Windows Logs) Right click on System and Clear Log, No (we don't want to save the old log), OK. Repeat for Application. Reboot. The disk check will run and will probably take an hour or more to finish.

Start, Run, sfc /scannow, OK

SPACE after sfc. This will check your critical system files. If it asks for a CD and you don't have one or it doesn't like your CD just tell it to SKIP.

Start, Run, sigverif, OK

Press Start. This will check your drivers. If you just get a few when it finishes tell me what they are. If you get a lot just look for those with newish dates (since about the time the problem started.)

1. Please download the Event Viewer Tool by Vino Rosso
and save it to your Desktop:
2. Double-click VEW.exe
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning

Then use the 'Number of events' as follows:

1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.

Please post the Output log in your next reply then repeat but select Application.

  • 0

Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP