Hello Thomas.
Thank you for your reply. sorry about the stupid question!
Here are the logs.
OTL logfile created on: 20/03/2010 21:43:09 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\PC-User1\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1,023.00 Mb Total Physical Memory | 597.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 95.52 Gb Free Space | 85.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME-PC
Current User Name: PC-User1
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/03/20 21:41:37 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\PC-User1\Desktop\OTL.exe
PRC - [2009/11/24 23:51:40 | 000,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/11/24 23:51:35 | 000,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/11/24 23:51:21 | 000,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/11/24 23:48:48 | 000,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/11/24 23:43:56 | 000,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2008/05/02 11:14:39 | 001,817,600 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
PRC - [2008/05/02 11:14:39 | 000,606,720 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2008/02/10 19:37:40 | 000,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/02/02 19:40:16 | 000,090,112 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2008/02/02 19:40:15 | 000,155,648 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2008/02/02 19:40:14 | 000,423,258 | —- | M] (Acronis) – C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
PRC - [2007/06/13 10:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/10/22 21:28:00 | 000,593,920 | R— | M] () – C:\Program Files\ASUS\AASP\1.00.12\aaCenter.exe
========== Modules (SafeList) ==========
MOD - [2010/03/20 21:41:37 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\PC-User1\Desktop\OTL.exe
MOD - [2006/08/25 15:45:55 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/03/01 11:58:14 | 001,029,456 | —- | M] (Lavasoft) [On_Demand | Stopped] – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2009/11/24 23:51:35 | 000,138,680 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus)
SRV - [2009/11/24 23:51:21 | 000,254,040 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner)
SRV - [2009/11/24 23:48:48 | 000,352,920 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner)
SRV - [2009/11/24 23:43:56 | 000,018,752 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv)
SRV - [2008/05/02 11:14:39 | 000,606,720 | —- | M] (Crawler.com) [Auto | Running] – C:\Program Files\Spyware Terminator\sp_rsser.exe – (sp_rssrv)
SRV - [2008/02/02 19:40:15 | 000,155,648 | —- | M] (Acronis) [Auto | Running] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://en-GB.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official"
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/08/12 21:23:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/06/21 12:54:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/21 12:54:58 | 000,000,000 | —D | M]
[2008/06/07 23:03:43 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\extensions
[2008/02/10 21:51:02 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/01/13 19:25:21 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\extensions\[removed]
[2008/06/07 23:03:43 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/01/12 20:10:47 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2007/11/28 19:31:59 | 000,067,696 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jar50.dll
[2007/11/28 19:31:59 | 000,054,376 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2007/11/28 19:31:59 | 000,034,952 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\myspell.dll
[2007/11/28 19:31:59 | 000,046,720 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2007/11/28 19:31:59 | 000,172,144 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2008/03/24 19:21:00 | 002,889,088 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
[2006/06/15 10:24:15 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2006/06/15 10:24:15 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2006/06/15 10:24:15 | 000,001,077 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2006/09/11 14:39:34 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2008/07/14 10:36:42 | 000,000,686 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Acronis True Image Monitor] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [AsusServiceProvider] C:\Program Files\ASUS\AASP\1.00.12\aaCenter.exe ()
O4 - HKLM..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.12\AsRunHelp.exe ()
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Search with Wanadoo - C:\WINDOWS\System32\WSBar.dll ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/12 17:47:47 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{aa431c24-e7ed-11dc-8122-000e50918fa0}\Shell - "" = AutoRun
O33 - MountPoints2\{aa431c24-e7ed-11dc-8122-000e50918fa0}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{aa431c24-e7ed-11dc-8122-000e50918fa0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{af35984c-fb52-11dc-8181-000e50918fa0}\Shell - "" = AutoRun
O33 - MountPoints2\{af35984c-fb52-11dc-8181-000e50918fa0}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{af35984c-fb52-11dc-8181-000e50918fa0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16610416650092544)
========== Files/Folders - Created Within 14 Days ==========
[2010/03/20 21:41:31 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Documents and Settings\PC-User1\Desktop\OTL.exe
[2010/03/20 11:15:59 | 000,000,000 | RH-D | C] – C:\Documents and Settings\PC-User1\Recent
[2010/03/08 16:45:50 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/02/06 08:57:05 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/02/06 08:52:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/05/25 13:59:49 | 000,017,504 | R— | C] ( ) – C:\WINDOWS\System32\drivers\GT680X.sys
[2008/03/25 21:10:46 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2008/03/25 21:10:46 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2008/01/12 20:54:50 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/01/12 17:50:18 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/01/12 17:47:39 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 14 Days ==========
[2010/03/20 21:41:37 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\PC-User1\Desktop\OTL.exe
[2010/03/20 21:07:05 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/20 20:20:05 | 000,356,120 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/20 20:20:05 | 000,311,934 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/20 20:20:05 | 000,040,196 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/20 20:16:10 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/03/20 20:16:01 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/20 20:15:56 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/20 20:15:46 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/20 11:16:10 | 005,242,880 | —- | M] () – C:\Documents and Settings\PC-User1\ntuser.dat
[2010/03/20 11:16:10 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\PC-User1\ntuser.ini
[2010/03/20 11:16:04 | 005,327,770 | -H– | M] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\IconCache.db
[2010/03/19 10:55:20 | 000,000,603 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2010/03/14 08:40:43 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/03/08 20:55:32 | 000,010,250 | -HS- | M] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\N40fDO82
[2010/03/08 16:36:11 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/03/08 11:57:52 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/03/08 20:53:56 | 000,010,250 | -HS- | C] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\N40fDO82
[2010/03/06 07:30:09 | 000,012,582 | -HS- | C] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\fXsMq7BWv
[2009/06/21 12:54:58 | 000,000,031 | -H– | C] () – C:\WINDOWS\UKCpInfo.sys
[2008/05/25 15:00:49 | 000,000,073 | —- | C] () – C:\WINDOWS\WinInit.Ini
[2008/05/25 13:59:49 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2008/05/25 13:20:50 | 000,000,000 | —- | C] () – C:\WINDOWS\ui.INI
[2008/05/25 13:15:56 | 000,000,603 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2008/05/25 13:12:55 | 000,000,492 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/02/18 21:30:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/02/10 20:09:56 | 000,271,264 | —- | C] () – C:\WINDOWS\System32\VBRUN100.DLL
[2008/02/10 20:09:56 | 000,000,010 | —- | C] () – C:\WINDOWS\BestSol.ini
[2008/02/10 13:17:45 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2008/02/10 11:30:51 | 000,105,472 | —- | C] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/10 11:30:36 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/02/10 10:37:32 | 000,000,309 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2008/02/10 10:01:37 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\WSBar.dll
[2008/02/02 19:40:04 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\setupnt.dll
[2008/01/27 19:55:28 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2008/01/12 20:30:53 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/01/12 19:56:49 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2008/01/12 19:56:49 | 000,005,685 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2008/01/12 19:56:17 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2008/01/12 19:53:02 | 000,016,174 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/01/12 19:53:00 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/01/12 19:52:57 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/03/27 09:45:22 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll
========== LOP Check ==========
[2008/01/13 19:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2010/03/09 16:02:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2008/07/16 07:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/22 10:54:25 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2008/02/10 20:40:31 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\123 Free Solitaire
[2008/02/02 19:44:15 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Acronis
[2010/03/14 13:58:09 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Spyware Terminator
[2010/03/08 11:57:52 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2006/02/28 12:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/13 18:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2004/08/03 22:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\dllcache\agp440.sys
< MD5 for: ATAPI.SYS >
[2006/02/28 12:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/13 18:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2006/02/28 12:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\dllcache\atapi.sys
[2006/02/28 12:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/14 00:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2006/02/28 12:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2006/02/28 12:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/14 00:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2009/02/06 18:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 18:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2006/02/28 12:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\netlogon.dll
[2006/02/28 12:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006/02/28 12:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\scecli.dll
[2006/02/28 12:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2008/04/14 00:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll
< %systemroot%\*. /mp /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 20/03/2010 21:43:09 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\PC-User1\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1,023.00 Mb Total Physical Memory | 597.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 95.52 Gb Free Space | 85.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME-PC
Current User Name: PC-User1
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0EE11800-A1BD-11D3-BFEB-005004AF2D32}" = Risk II
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{31DABA20-10A1-4746-9D9F-57955B8DFF66}" = Free Games Offer, Desktop Shortcut
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = AsusUpdate
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{83C03FBE-4492-4133-BBAB-421CD88ADA32}" = OpenOffice.org 2.3
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA9768AA-FF0B-4C66-A085-31E934F77841}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{BD1DC860-2B0A-11D4-BD2E-00500480A380}" = Combat Mission
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}" = SpeedTouch USB Software
"{D9B4D7EE-481C-4C36-86AB-A8F7417725FF}" = LightScribe 1.6.43.1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F61DD673-0030-4BB2-A382-7E57E97F1033}" = Nero 7 Essentials
"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II
"123 Free Solitaire" = 123 Free Solitaire
"ABBYY FineReader 4.0 Sprint" = ABBYY FineReader 4.0 Sprint
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"CCleaner" = CCleaner (remove only)
"CodeStuff Starter" = CodeStuff Starter
"Combat Mission 2" = Combat Mission 2
"Combat Mission 3 Afrika Korps" = Combat Mission 3 Afrika Korps
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"Lexmark Z600 Series" = Lexmark Z600 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (2.0.0.11)" = Mozilla Firefox (2.0.0.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Patience_is1" = Patience 1.5 beta
"PC Pitstop Driver Alert_is1" = PC Pitstop Driver Alert 1.0
"RealAlt_is1" = Real Alternative 1.7.5
"RealPlayer 6.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.71
"Spyware Terminator_is1" = Spyware Terminator
"TrueImage" = Acronis True Image
"Ulead Photo Express 3.0 SE" = Ulead Photo Express 3.0 SE
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast Ethernet Adapter
"Wanadoo" = Wanadoo Search Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager
========== Last 10 Event Log Errors ==========
[ Antivirus Events ]
Error - 03/08/2009 04:40:03 | Computer Name = HOME-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\DCIM\100C3045\DSCI0228.JPG failed, 0000001E.
[ Application Events ]
Error - 11/03/2010 06:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 13/03/2010 04:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 14/03/2010 10:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 15/03/2010 06:02:06 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 15/03/2010 13:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 17/03/2010 08:40:43 | Computer Name = HOME-PC | Source = Application Hang | ID = 1002
Description = Hanging application soffice.bin, version 2.3.9215.500, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 17/03/2010 12:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 18/03/2010 05:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 20/03/2010 06:35:09 | Computer Name = HOME-PC | Source = Application Hang | ID = 1002
Description = Hanging application soffice.bin, version 2.3.9215.500, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 20/03/2010 17:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
[ Application Events ]
Error - 11/03/2010 06:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 13/03/2010 04:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 14/03/2010 10:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 15/03/2010 06:02:06 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 15/03/2010 13:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 17/03/2010 08:40:43 | Computer Name = HOME-PC | Source = Application Hang | ID = 1002
Description = Hanging application soffice.bin, version 2.3.9215.500, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 17/03/2010 12:02:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 18/03/2010 05:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
Error - 20/03/2010 06:35:09 | Computer Name = HOME-PC | Source = Application Hang | ID = 1002
Description = Hanging application soffice.bin, version 2.3.9215.500, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 20/03/2010 17:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =
[ System Events ]
Error - 08/03/2010 07:03:21 | Computer Name = HOME-PC | Source = Service Control Manager | ID = 7000
Description = The SASDIFSV service failed to start due to the following error: %%183
Error - 09/03/2010 08:04:35 | Computer Name = HOME-PC | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460
Error - 09/03/2010 10:29:05 | Computer Name = HOME-PC | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460
Error - 09/03/2010 10:40:17 | Computer Name = HOME-PC | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460
< End of report >
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-03-21 17:16:56
Windows 5.1.2600 Service Pack 2
Running: u8ot7kfn.exe; Driver: C:\DOCUME~1\PC-User1\LOCALS~1\Temp\kxtdipow.sys
—- System - GMER 1.0.15 —-
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0xAE222606]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xAE22205A]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xAE221D3C]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xAE223652]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xAE221E46]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xAE221F30]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAE12514C]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xAE2228CC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xAE222362]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAE12564E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAE12508C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAE1250F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAE12576E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAE12572E]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xAE221BBA]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xAE222814]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xAE222494]
—- Kernel code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF61C6000, 0x198FE0, 0xE8000020]
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\WINDOWS\system32\services.exe[596] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00390002
IAT C:\WINDOWS\system32\services.exe[596] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00390000
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
—- EOF - GMER 1.0.15 —-
Hope this is Ok. (The GMR scan seemed a bit quick, but what do I know!?)
Regards
Nelclaret