hi gary, i already tried blacklight with tetonbob under the hijackthis forum and he said nothing about the results so i tried rootkitrevealer, it found 12 i went to save on to the desktop and rootkit revealer error popped up and needed to close and straight after drwatson came up and with error and also needed to close, the rootkitrevealer screen however was still up but with only four of the problems left visible. after this i did the windows free online scan and it found nothing though thankfully finished. but then when i shut it both my internet explorer pages were not responding and the same error message came up saying they needed to be closed. i then ran event viewer hwich had entries under security and application, log to follow of the last couple of or so, maybe it will help.
other problems, when i turn on the computer and it goes to the desktop, all the icons flash once as if a program has just started and done something, when online the arrow often changes to an hourgalss and i'm not able to do anything but wait till it returns to normal, but still slower. i dont have drwatson installed, why is it on my computer?
and finally i havent run cccleaner as i dont have the xp cd, should i get hold of it before i try and clean the registry and there's not much on my computer that i cant replace, just some word documents which i can put on my memory stick. also tetonbob mentioned something like "dumprep" and linked me to this thread. whats that?
Application Section
12/12/2006 23:11:12 Application Hang Error (101) 1002 N/A RECLUSE Hanging application iexplore.exe, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
12/12/2006 22:18:25 Application Error Error (100) 1000 N/A RECLUSE Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.
12/12/2006 22:18:11 Application Error Error (100) 1000 N/A RECLUSE Faulting application ULJV.exe, version 1.71.0.0, faulting module comctl32.dll, version 6.0.2900.2180, fault address 0x00004933.
12/12/2006 21:42:09 SecurityCenter Information None 1800 N/A RECLUSE The Windows Security Center Service has started.
12/12/2006 21:42:08 EAPOL Information None 2002 N/A RECLUSE EAPOL service was stopped successfully
12/12/2006 21:42:08 EAPOL Information None 2003 N/A RECLUSE EAPOL service is running
12/12/2006 21:42:07 AVGEMS Information None 1 N/A RECLUSE Service started
12/12/2006 21:42:06 RegSrvc Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( RegSrvc ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/12/2006 21:42:06 OwnershipProtocol Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( OwnershipProtocol ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/12/2006 21:42:05 Avg7UpdSvc Information None 1 N/A RECLUSE Service started
12/12/2006 21:41:58 EvtEng Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( EvtEng ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/12/2006 00:15:45 SecurityCenter Information None 1800 N/A RECLUSE The Windows Security Center Service has started.
12/12/2006 00:15:45 AVGEMS Information None 1 N/A RECLUSE Service started
12/12/2006 00:15:41 RegSrvc Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( RegSrvc ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/12/2006 00:15:41 OwnershipProtocol Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( OwnershipProtocol ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/12/2006 00:15:41 Avg7UpdSvc Information None 1 N/A RECLUSE Service started
12/12/2006 00:15:37 EAPOL Information None 2002 N/A RECLUSE EAPOL service was stopped successfully
12/12/2006 00:15:37 EAPOL Information None 2003 N/A RECLUSE EAPOL service is running
12/12/2006 00:15:27 EvtEng Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( EvtEng ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 17:20:58 EAPOL Information None 2002 N/A RECLUSE EAPOL service was stopped successfully
11/12/2006 17:20:58 EAPOL Information None 2003 N/A RECLUSE EAPOL service is running
11/12/2006 17:20:57 SecurityCenter Information None 1800 N/A RECLUSE The Windows Security Center Service has started.
11/12/2006 17:20:56 AVGEMS Information None 1 N/A RECLUSE Service started
11/12/2006 17:20:56 RegSrvc Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( RegSrvc ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 17:20:56 OwnershipProtocol Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( OwnershipProtocol ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 17:20:55 Avg7UpdSvc Information None 1 N/A RECLUSE Service started
11/12/2006 17:20:48 EvtEng Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( EvtEng ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 17:14:07 EAPOL Information None 2002 N/A RECLUSE EAPOL service was stopped successfully
11/12/2006 17:14:07 EAPOL Information None 2003 N/A RECLUSE EAPOL service is running
11/12/2006 17:14:06 SecurityCenter Information None 1800 N/A RECLUSE The Windows Security Center Service has started.
11/12/2006 17:14:05 AVGEMS Information None 1 N/A RECLUSE Service started
11/12/2006 17:14:05 RegSrvc Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( RegSrvc ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 17:14:05 OwnershipProtocol Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( OwnershipProtocol ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 17:14:04 Avg7UpdSvc Information None 1 N/A RECLUSE Service started
11/12/2006 17:13:57 EvtEng Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( EvtEng ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 17:04:54 SecurityCenter Information None 1800 N/A RECLUSE The Windows Security Center Service has started.
11/12/2006 17:04:51 AVGEMS Information None 1 N/A RECLUSE Service started
11/12/2006 17:04:50 RegSrvc Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( RegSrvc ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 17:04:50 OwnershipProtocol Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( OwnershipProtocol ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 17:04:49 Avg7UpdSvc Information None 1 N/A RECLUSE Service started
11/12/2006 17:04:46 EAPOL Information None 2002 N/A RECLUSE EAPOL service was stopped successfully
11/12/2006 17:04:46 EAPOL Information None 2003 N/A RECLUSE EAPOL service is running
11/12/2006 17:04:36 EvtEng Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( EvtEng ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 16:41:27 EAPOL Information None 2002 N/A RECLUSE EAPOL service was stopped successfully
11/12/2006 16:41:27 EAPOL Information None 2003 N/A RECLUSE EAPOL service is running
11/12/2006 16:41:20 SecurityCenter Information None 1800 N/A RECLUSE The Windows Security Center Service has started.
11/12/2006 16:41:19 AVGEMS Information None 1 N/A RECLUSE Service started
11/12/2006 16:41:19 RegSrvc Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( RegSrvc ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 16:41:19 OwnershipProtocol Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( OwnershipProtocol ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 16:41:18 Avg7UpdSvc Information None 1 N/A RECLUSE Service started
11/12/2006 16:41:10 EvtEng Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( EvtEng ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 14:42:25 EAPOL Information None 2002 N/A RECLUSE EAPOL service was stopped successfully
11/12/2006 14:42:25 EAPOL Information None 2003 N/A RECLUSE EAPOL service is running
11/12/2006 14:42:23 SecurityCenter Information None 1800 N/A RECLUSE The Windows Security Center Service has started.
11/12/2006 14:42:22 AVGEMS Information None 1 N/A RECLUSE Service started
11/12/2006 14:42:21 RegSrvc Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( RegSrvc ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 14:42:21 OwnershipProtocol Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( OwnershipProtocol ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 14:42:20 Avg7UpdSvc Information None 1 N/A RECLUSE Service started
11/12/2006 14:42:12 EvtEng Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( EvtEng ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 05:29:28 SecurityCenter Information None 1800 N/A RECLUSE The Windows Security Center Service has started.
11/12/2006 05:29:28 EAPOL Information None 2002 N/A RECLUSE EAPOL service was stopped successfully
11/12/2006 05:29:28 EAPOL Information None 2003 N/A RECLUSE EAPOL service is running
11/12/2006 05:29:27 AVGEMS Information None 1 N/A RECLUSE Service started
11/12/2006 05:29:26 RegSrvc Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( RegSrvc ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 05:29:26 OwnershipProtocol Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( OwnershipProtocol ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
11/12/2006 05:29:25 Avg7UpdSvc Information None 1 N/A RECLUSE Service started
11/12/2006 05:29:17 EvtEng Information None 0 N/A RECLUSE The description for Event ID ( 0 ) in Source ( EvtEng ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
Security Section
12/12/2006 23:16:13 Service Control Manager Information None 7036 N/A RECLUSE The Windows Installer service entered the stopped state.
12/12/2006 23:06:06 Service Control Manager Information None 7035 NT AUTHORITY\SYSTEM RECLUSE The Windows Installer service was successfully sent a start control.
12/12/2006 23:06:06 Service Control Manager Information None 7036 N/A RECLUSE The Windows Installer service entered the running state.
12/12/2006 22:56:29 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:56:21 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:50:02 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:49:54 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:49:45 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:45:23 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:45:15 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:45:05 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:44:56 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:23:42 Tcpip Warning None 4226 N/A RECLUSE TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
12/12/2006 22:19:57 Service Control Manager Error None 7034 N/A RECLUSE The ULJV service terminated unexpectedly. It has done this 1 time(s).
12/12/2006 22:12:33 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:10:39 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:09:08 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:08:59 Disk Error None 7 N/A RECLUSE The device, \Device\Harddisk0\D, has a bad block.
12/12/2006 22:01:40 Service Control Manager Information None 7035 RECLUSE\Theo P RECLUSE The ULJV service was successfully sent a start control.
12/12/2006 22:01:40 Service Control Manager Information None 7036 N/A RECLUSE The ULJV service entered the running state.
12/12/2006 21:56:20 Tcpip Warning None 4226 N/A RECLUSE TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
12/12/2006 21:46:46 Tcpip Information None 4201 N/A RECLUSE The system detected that network adapter \DEVICE\TCPIP_{96D0FF8E-89E9-4D27-A611-ADFAED013CEA} was connected to the network, and has initiated normal operation over the network adapter.
12/12/2006 21:42:38 Tcpip Warning None 4226 N/A RECLUSE TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
12/12/2006 21:42:22 Service Control Manager Information None 7036 N/A RECLUSE The IMAPI CD-Burning COM Service service entered the stopped state.
12/12/2006 21:42:16 Tcpip Information None 4201 N/A RECLUSE The system detected that network adapter \DEVICE\TCPIP_{96D0FF8E-89E9-4D27-A611-ADFAED013CEA} was connected to the network, and has initiated normal operation over the network adapter.
12/12/2006 21:42:14 Service Control Manager Information None 7036 N/A RECLUSE The IMAPI CD-Burning COM Service service entered the running state.
12/12/2006 21:42:14 Service Control Manager Information None 7036 N/A RECLUSE The SSDP Discovery Service service entered the running state.
12/12/2006 21:42:14 Service Control Manager Information None 7035 NT AUTHORITY\SYSTEM RECLUSE The IMAPI CD-Burning COM Service service was successfully sent a start control.
12/12/2006 21:42:14 Service Control Manager Information None 7035 NT AUTHORITY\SYSTEM RECLUSE The SSDP Discovery Service service was successfully sent a start control.
12/12/2006 21:42:13 Service Control Manager Information None 7035 RECLUSE\Theo P RECLUSE The SIS PORT Driver service was successfully sent a start control.
12/12/2006 21:42:09 Service Control Manager Information None 7036 N/A RECLUSE The Remote Access Connection Manager service entered the running state.
12/12/2006 21:42:09 Service Control Manager Information None 7036 N/A RECLUSE The Application Layer Gateway Service service entered the running state.
12/12/2006 21:42:09 Service Control Manager Information None 7036 N/A RECLUSE The Network Location Awareness (NLA) service entered the running state.
12/12/2006 21:42:09 Service Control Manager Information None 7035 NT AUTHORITY\SYSTEM RECLUSE The Network Location Awareness (NLA) service was successfully sent a start control.
12/12/2006 21:42:09 Service Control Manager Information None 7035 NT AUTHORITY\SYSTEM RECLUSE The Remote Access Connection Manager service was successfully sent a start control.
12/12/2006 21:42:09 Service Control Manager Information None 7036 N/A RECLUSE The Telephony service entered the running state.
12/12/2006 21:42:09 Service Control Manager Information None 7036 N/A RECLUSE The Wireless Zero Configuration service entered the stopped state.
12/12/2006 21:42:09 Service Control Manager Information None 7036 N/A RECLUSE The Fast User Switching Compatibility service entered the running state.
12/12/2006 21:42:09 Service Control Manager Information None 7035 NT AUTHORITY\SYSTEM RECLUSE The Fast User Switching Compatibility service was successfully sent a start control.
12/12/2006 21:42:09 Service Control Manager Information None 7036 N/A RECLUSE The Terminal Services service entered the running state.
12/12/2006 21:42:09 Service Control Manager Information None 7035 RECLUSE\Theo P RECLUSE The Wireless Zero Configuration service was successfully sent a stop control.
12/12/2006 21:41:57 EventLog Information None 6005 N/A RECLUSE The Event log service was started.
12/12/2006 21:41:57 EventLog Information None 6009 N/A RECLUSE Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Uniprocessor Free.
12/12/2006 00:22:07 EventLog Information None 6006 N/A RECLUSE The Event log service was stopped.
12/12/2006 00:20:50 Tcpip Information None 4202 N/A RECLUSE The system detected that network adapter \DEVICE\TCPIP_{96D0FF8E-89E9-4D27-A611-ADFAED013CEA} was disconnected from the network, and the adapter's network configuration has been released. If the network adapter was not disconnected, this may indicate that it has malfunctioned. Please contact your vendor for updated drivers.
12/12/2006 00:16:18 Tcpip Warning None 4226 N/A RECLUSE TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
12/12/2006 00:16:02 Service Control Manager Information None 7036 N/A RECLUSE The IMAPI CD-Burning COM Service service entered the stopped state.
12/12/2006 00:15:57 Tcpip Information None 4201 N/A RECLUSE The system detected that network adapter \DEVICE\TCPIP_{96D0FF8E-89E9-4D27-A611-ADFAED013CEA} was connected to the network, and has initiated normal operation over the network adapter.
12/12/2006 00:15:54 Service Control Manager Information None 7036 N/A RECLUSE The IMAPI CD-Burning COM Service service entered the running state.
12/12/2006 00:15:54 Service Control Manager Information None 7035 NT AUTHORITY\SYSTEM RECLUSE The IMAPI CD-Burning COM Service service was successfully sent a start control.
12/12/2006 00:15:52 Service Control Manager Information None 7036 N/A RECLUSE The SSDP Discovery Service service entered the running state.
12/12/2006 00:15:51 Service Control Manager Information None 7036 N/A RECLUSE The Remote Access Connection Manager service entered the running state.
12/12/2006 00:15:51 Service Control Manager Information None 7035 NT AUTHORITY\SYSTEM RECLUSE The SSDP Discovery Service service was successfully sent a start control.
12/12/2006 00:15:51 Service Control Manager Information None 7035 RECLUSE\Theo P RECLUSE The SIS PORT Driver service was successfully sent a start control.
tcpip has come up alot and i havent used by cdrom burning facility for months??????????