here we are????
ComboFix 09-09-13.04 - Carol 09/13/2009 19:29.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.645 [GMT -5:00]
Running from: c:\documents and settings\Carol\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\carol\favorites\.url
c:\windows\Installer\7741bf.msp
c:\windows\system32\ATHPRXY(2).DLL
c:\windows\system32\AutoRun.inf
c:\windows\system32\Data
c:\windows\system32\drivers\kbiwkmkvxodpbi.sys
c:\windows\system32\kbiwkmbpwpavsn.dat
c:\windows\system32\kbiwkmjyfykpaf.dll
c:\windows\system32\kbiwkmmppetltc.dll
c:\windows\system32\kbiwkmqavyounk.dll
c:\windows\system32\kbiwkmqrwkrotq.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_kbiwkmenqtjlqg
-------\Legacy_kbiwkmenqtjlqg
((((((((((((((((((((((((( Files Created from 2009-08-14 to 2009-09-14 )))))))))))))))))))))))))))))))
.
2009-09-11 21:10 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-09-08 21:30 . 2009-09-08 21:30 -------- d-----w- c:\program files\Trend Micro
2009-09-08 21:27 . 2009-09-08 21:28 -------- d-----w- c:\program files\ERUNT
2009-09-08 01:29 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll
2009-09-08 01:29 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2009-09-08 01:29 . 2008-04-13 18:39 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-09-08 01:29 . 2008-04-13 18:39 14592 ----a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-09-08 01:07 . 2009-06-25 08:25 54272 ------w- c:\windows\system32\dllcache\wdigest.dll
2009-09-08 01:07 . 2009-06-25 08:25 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2009-09-08 01:07 . 2009-06-24 11:18 92928 ------w- c:\windows\system32\dllcache\ksecdd.sys
2009-09-08 01:07 . 2009-06-25 08:25 301568 ------w- c:\windows\system32\dllcache\kerberos.dll
2009-09-08 00:59 . 2009-09-08 00:59 -------- d-----w- C:\301cedce54151710f1
2009-09-08 00:58 . 2009-09-08 00:58 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-09-08 00:57 . 2009-09-08 00:57 -------- d-----w- c:\windows\system32\XPSViewer
2009-09-08 00:57 . 2009-09-08 00:57 -------- d-----w- c:\program files\MSBuild
2009-09-08 00:57 . 2009-09-08 00:57 -------- d-----w- c:\program files\Reference Assemblies
2009-09-08 00:56 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-09-08 00:56 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-09-08 00:56 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-09-08 00:56 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-09-08 00:56 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-09-08 00:56 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-09-08 00:56 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-09-08 00:56 . 2009-09-08 00:57 -------- d-----w- C:\54c95076448f26fb03d11a9da7
2009-09-08 00:56 . 2009-09-08 01:01 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-28 15:37 . 2009-07-03 17:09 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-08-28 15:37 . 2009-07-03 17:09 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-24 02:02 . 2009-08-24 02:02 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-24 01:59 . 2009-08-24 01:59 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2009-08-24 01:56 . 2009-08-24 01:56 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-23 12:49 . 2009-09-11 21:43 -------- d-----w- c:\windows\ie8updates
2009-08-23 12:47 . 2009-07-01 07:08 101376 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-08-23 12:40 . 2009-08-23 12:47 -------- dc-h--w- c:\windows\ie8
2009-08-16 02:29 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-13 22:22 . 2008-11-11 00:45 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-08 01:19 . 2003-06-14 01:57 56896 ----a-w- c:\documents and settings\Carol\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-08 00:38 . 2008-11-15 12:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-08 00:38 . 2008-11-15 12:44 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-08 00:36 . 2008-07-03 02:09 -------- d-----w- c:\program files\IncrediMail
2009-09-06 12:07 . 2008-11-11 22:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-06 12:07 . 2008-07-03 02:11 -------- d-----w- c:\program files\Lavasoft
2009-09-06 11:52 . 2008-07-03 02:21 -------- d-----w- c:\program files\RegVac
2009-08-05 09:01 . 2003-06-14 23:26 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2002-08-29 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2004-10-30 12:45 286208 ------w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2004-08-24 01:32 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2002-08-29 10:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2002-08-29 10:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2002-08-29 10:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2002-08-29 10:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2002-08-29 10:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2002-08-29 10:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2002-08-29 10:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2002-08-29 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2002-08-29 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2002-07-17 200767]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-14 1957888]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-10-06 5058560]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-06-03 151597]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-16 28672]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"BCMSMMSG"="BCMSMMSG.exe" - c:\windows\BCMSMMSG.exe [2003-08-29 122880]
"nwiz"="nwiz.exe" - c:\windows\SYSTEM32\nwiz.exe [2003-10-06 741376]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
NkvMon.exe.lnk - c:\program files\Nikon\NkView6\NkvMon.exe [2003-6-14 237568]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)
"EPSONStatusAgent2"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpySweeper"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 PQV2i;PQV2i;c:\windows\SYSTEM32\DRIVERS\PQV2i.sys [6/3/2003 3:52 PM 123957]
R1 PQIMount;PQIMount;c:\windows\SYSTEM32\DRIVERS\PQIMount.sys [6/3/2003 3:52 PM 46900]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2008-09-01 c:\windows\Tasks\Disk Defragmenter.job
- c:\documents and settings\All Users\Start Menu\Programs\Accessories\System Tools\Disk Defragmenter.lnk [2002-09-03 09:48]
2009-07-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-01 15:53]
2008-09-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-01 15:53]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.earthlink.net
uDefault_Search_URL = hxxp://www.earthlink.net/partner/more/msie/button/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=localhost:8081
uInternet Settings,ProxyOverride = <local>
IE: &Add animation to IncrediMail Style Box - c:\progra~1\INCRED~1\bin\resources\WebMenuImg.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: EarthLink Google Search - c:\program files\EarthLink\Toolbar\SearchUI.dll/search.html
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Carol\Application Data\Mozilla\Firefox\Profiles\xeerdlvf.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-13 19:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1724484436-4072049485-3156628389-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:00000003
[HKEY_USERS\S-1-5-21-1724484436-4072049485-3156628389-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:00000003
[HKEY_USERS\S-1-5-21-1724484436-4072049485-3156628389-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:00000003
[HKEY_USERS\S-1-5-21-1724484436-4072049485-3156628389-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:00000003
[HKEY_USERS\S-1-5-21-1724484436-4072049485-3156628389-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000003
.
Completion time: 2009-09-14 19:49
ComboFix-quarantined-files.txt 2009-09-14 00:49
Pre-Run: 124,270,329,856 bytes free
Post-Run: 124,266,520,576 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
212 --- E O F --- 2009-09-14 00:06
DDS (Ver_09-07-30.01) - NTFSx86
Run by Carol at 20:01:53.17 on Sun 09/13/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.488 [GMT -5:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\GEARSec.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\DSentry.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Carol\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://my.earthlink.net
uDefault_Search_URL = hxxp://www.earthlink.net/partner/more/msie/button/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=localhost:8081
uInternet Settings,ProxyOverride = <local>
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll
BHO: ElnkPubBHO Class: {512acf1b-64d9-4928-b382-a80556f28db4} - c:\program files\earthlink\toolbar\ElnkPub.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
BHO: ElnkProtectionBHO Class: {9579d574-d4d8-4335-9560-fe8641a013bd} - c:\program files\earthlink\toolbar\ProtctIE.dll
BHO: ElnkLegacyUninstBHO Class: {e713904c-df05-4c79-bbad-02db923253be} - c:\program files\earthlink\toolbar\uninsttb.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: EarthLink Toolbar: {d7f30b62-8269-41af-9539-b2697fa7d77e} -
TB: EarthLink Toolbar: {c7768536-96f8-4001-b1a2-90ee21279187} - c:\program files\earthlink\toolbar\Toolbar.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe"
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [BCMSMMSG] BCMSMMSG.exe
mRun: [diagent] "c:\program files\creative\sblive\diagnostics\diagent.exe" startup
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AdaptecDirectCD] "c:\program files\roxio\easy cd creator 5\directcd\DirectCD.exe"
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [nwiz] nwiz.exe /install
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nkvmon~1.lnk - c:\program files\nikon\nkview6\NkvMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
mPolicies-explorer: <NO NAME> =
IE: &Add animation to IncrediMail Style Box - c:\progra~1\incred~1\bin\resources\WebMenuImg.htm
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: EarthLink Google Search - c:\program files\earthlink\toolbar\SearchUI.dll/search.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,76/mcinsctl.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1193540747812
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37869.809375
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\carol\applic~1\mozilla\firefox\profiles\xeerdlvf.default\
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2003-6-3 123957]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2007-3-1 214024]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2003-6-3 46900]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2007-11-14 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2007-3-1 144704]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2007-3-1 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2007-3-1 79880]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2007-3-1 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-3-1 40552]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-3-1 34216]
=============== Created Last 30 ================
2009-09-13 19:19 <DIR> a-dshr-- C:\cmdcons
2009-09-13 19:17 229,888 a------- c:\windows\PEV.exe
2009-09-13 19:17 161,792 a------- c:\windows\SWREG.exe
2009-09-13 19:17 98,816 a------- c:\windows\sed.exe
2009-09-11 16:10 1,089,593 -------- c:\windows\system32\dllcache\ntprint.cat
2009-09-11 16:10 153,088 -------- c:\windows\system32\dllcache\triedit.dll
2009-09-08 16:30 <DIR> --d----- c:\program files\Trend Micro
2009-09-07 20:29 21,504 a------- c:\windows\system32\hidserv.dll
2009-09-07 20:29 21,504 a------- c:\windows\system32\dllcache\hidserv.dll
2009-09-07 20:29 14,592 a------- c:\windows\system32\drivers\kbdhid.sys
2009-09-07 20:29 14,592 a------- c:\windows\system32\dllcache\kbdhid.sys
2009-09-07 20:07 54,272 -------- c:\windows\system32\dllcache\wdigest.dll
2009-09-07 20:07 136,192 -------- c:\windows\system32\dllcache\msv1_0.dll
2009-09-07 20:07 92,928 -------- c:\windows\system32\dllcache\ksecdd.sys
2009-09-07 20:07 301,568 -------- c:\windows\system32\dllcache\kerberos.dll
2009-09-07 19:59 <DIR> --d----- C:\301cedce54151710f1
2009-09-07 19:57 <DIR> --d----- c:\windows\system32\XPSViewer
2009-09-07 19:56 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-09-07 19:56 1,676,288 -------- c:\windows\system32\dllcache\xpssvcs.dll
2009-09-07 19:56 597,504 -------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-09-07 19:56 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-09-07 19:56 575,488 -------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-09-07 19:56 117,760 -------- c:\windows\system32\prntvpt.dll
2009-09-07 19:56 89,088 -------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-09-07 19:56 <DIR> --d----- C:\54c95076448f26fb03d11a9da7
2009-09-07 19:56 <DIR> --d----- c:\windows\SxsCaPendDel
2009-08-28 10:37 246,272 -------- c:\windows\system32\dllcache\ieproxy.dll
2009-08-28 10:37 12,800 -------- c:\windows\system32\dllcache\xpshims.dll
2009-08-23 07:49 <DIR> --d----- c:\windows\ie8updates
2009-08-23 07:47 101,376 -------- c:\windows\system32\dllcache\iecompat.dll
2009-08-23 07:40 <DIR> -cd-h--- c:\windows\ie8
2009-08-15 21:29 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
==================== Find3M ====================
2009-08-05 04:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-05 04:01 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-19 18:48 11,067,392 a------- c:\windows\system32\dllcache\ieframe.dll
2009-07-19 08:18 5,937,152 a------- c:\windows\system32\dllcache\mshtml.dll
2009-07-17 14:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-17 14:01 58,880 -------- c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 10,841,088 -------- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 -------- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 -------- c:\windows\system32\dllcache\wmpdxm.dll
2009-07-03 12:09 915,456 a------- c:\windows\system32\dllcache\wininet.dll
2009-07-03 12:09 915,456 -------- c:\windows\system32\wininet.dll
2009-07-03 12:09 1,208,832 a------- c:\windows\system32\dllcache\urlmon.dll
2009-07-03 12:09 206,848 a------- c:\windows\system32\dllcache\occache.dll
2009-07-03 12:09 594,432 a------- c:\windows\system32\dllcache\msfeeds.dll
2009-07-03 12:09 55,296 a------- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-03 12:09 1,985,536 a------- c:\windows\system32\dllcache\iertutil.dll
2009-07-03 12:09 25,600 a------- c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 12:09 184,320 a------- c:\windows\system32\dllcache\iepeers.dll
2009-07-03 12:09 386,048 a------- c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 06:01 173,056 a------- c:\windows\system32\dllcache\ie4uinit.exe
2009-06-29 11:12 133,120 -------- c:\windows\system32\dllcache\extmgr.dll
2009-06-29 06:07 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2009-06-25 03:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 03:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 03:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 03:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 03:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 03:25 54,272 a------- c:\windows\system32\wdigest.dll
2009-06-25 03:25 730,112 -------- c:\windows\system32\dllcache\lsasrv.dll
2009-06-25 03:25 147,456 -------- c:\windows\system32\dllcache\schannel.dll
2009-06-25 03:25 56,832 -------- c:\windows\system32\dllcache\secur32.dll
2009-06-22 01:44 726,528 a------- c:\windows\system32\dllcache\jscript.dll
2009-06-16 09:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 09:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-16 09:36 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
2009-06-16 09:36 81,920 -------- c:\windows\system32\dllcache\fontsub.dll
2005-03-22 18:28 58,944 a------- c:\docume~1\carol\applic~1\GDIPFONTCACHEV1.DAT
============= FINISH: 20:02:50.32 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-07-30.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 6/13/2003 8:55:46 PM
System Uptime: 9/13/2009 7:56:45 PM (1 hours ago)
Motherboard: Dell Computer Corp. | | 0M0321
Processor: Intel(R) Pentium(R) 4 CPU 2.53GHz | Microprocessor | 2524/533mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 149 GiB total, 115.757 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is FIXED (NTFS) - 28 GiB total, 14.218 GiB free.
G: is FIXED (NTFS) - 112 GiB total, 60.882 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP240: 8/23/2009 9:19:27 PM - Software Distribution Service 3.0
RP241: 8/23/2009 9:19:29 PM - Software Distribution Service 3.0
RP242: 8/23/2009 9:19:31 PM - Software Distribution Service 3.0
RP243: 8/23/2009 9:19:31 PM - Software Distribution Service 3.0
RP244: 8/23/2009 9:19:32 PM - Software Distribution Service 3.0
RP245: 8/23/2009 9:19:33 PM - Software Distribution Service 3.0
RP246: 8/23/2009 9:19:34 PM - Software Distribution Service 3.0
RP247: 8/23/2009 9:19:34 PM - Software Distribution Service 3.0
RP248: 8/23/2009 9:19:35 PM - Software Distribution Service 3.0
RP249: 8/23/2009 9:19:35 PM - Software Distribution Service 3.0
RP250: 8/23/2009 9:19:36 PM - Software Distribution Service 3.0
RP251: 8/23/2009 9:19:36 PM - Software Distribution Service 3.0
RP252: 8/23/2009 9:19:36 PM - Software Distribution Service 3.0
RP253: 8/23/2009 9:19:38 PM - Software Distribution Service 3.0
RP254: 8/23/2009 9:19:38 PM - Software Distribution Service 3.0
RP255: 8/23/2009 9:19:39 PM - Software Distribution Service 3.0
RP256: 8/23/2009 9:19:39 PM - Software Distribution Service 3.0
RP257: 8/23/2009 9:19:39 PM - Software Distribution Service 3.0
RP258: 8/23/2009 9:19:40 PM - Software Distribution Service 3.0
RP259: 8/23/2009 9:19:41 PM - Software Distribution Service 3.0
RP260: 8/23/2009 9:19:42 PM - Software Distribution Service 3.0
RP261: 8/23/2009 9:19:42 PM - Software Distribution Service 3.0
RP262: 8/23/2009 9:19:43 PM - System Checkpoint
RP263: 8/23/2009 9:19:43 PM - Software Distribution Service 3.0
RP264: 8/23/2009 9:19:43 PM - Software Distribution Service 3.0
RP265: 8/23/2009 9:19:43 PM - Software Distribution Service 3.0
RP266: 8/23/2009 9:19:43 PM - Software Distribution Service 3.0
RP267: 8/23/2009 9:19:43 PM - Software Distribution Service 3.0
RP268: 8/23/2009 9:19:43 PM - Software Distribution Service 3.0
RP269: 8/23/2009 9:19:44 PM - Software Distribution Service 3.0
RP270: 8/23/2009 9:19:44 PM - Software Distribution Service 3.0
RP271: 8/23/2009 9:19:44 PM - Software Distribution Service 3.0
RP272: 8/23/2009 9:19:44 PM - Software Distribution Service 3.0
RP273: 8/23/2009 9:19:44 PM - Software Distribution Service 3.0
RP274: 8/23/2009 9:19:44 PM - Software Distribution Service 3.0
RP275: 8/23/2009 9:19:45 PM - Software Distribution Service 3.0
RP276: 8/23/2009 9:19:45 PM - Software Distribution Service 3.0
RP277: 8/23/2009 9:19:45 PM - System Checkpoint
RP278: 8/23/2009 9:19:46 PM - Software Distribution Service 3.0
RP279: 8/23/2009 9:19:46 PM - Software Distribution Service 3.0
RP280: 8/23/2009 9:19:46 PM - Software Distribution Service 3.0
RP281: 8/23/2009 9:19:46 PM - Software Distribution Service 3.0
RP282: 8/23/2009 9:19:46 PM - Software Distribution Service 3.0
RP283: 8/23/2009 9:19:46 PM - Software Distribution Service 3.0
RP284: 8/23/2009 9:19:46 PM - Software Distribution Service 3.0
RP285: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP286: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP287: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP288: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP289: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP290: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP291: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP292: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP293: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP294: 8/23/2009 9:19:47 PM - Software Distribution Service 3.0
RP295: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP296: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP297: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP298: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP299: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP300: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP301: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP302: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP303: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP304: 8/23/2009 9:19:48 PM - Software Distribution Service 3.0
RP305: 8/23/2009 9:19:49 PM - Software Distribution Service 3.0
RP306: 8/23/2009 9:19:49 PM - Software Distribution Service 3.0
RP307: 8/23/2009 9:19:49 PM - Software Distribution Service 3.0
RP308: 8/23/2009 9:19:49 PM - Software Distribution Service 3.0
RP309: 8/23/2009 9:19:49 PM - Software Distribution Service 3.0
RP310: 8/23/2009 9:19:49 PM - Software Distribution Service 3.0
RP311: 8/23/2009 9:19:49 PM - Software Distribution Service 3.0
RP312: 8/23/2009 9:19:50 PM - Software Distribution Service 3.0
RP313: 8/23/2009 9:19:50 PM - Software Distribution Service 3.0
RP314: 8/23/2009 9:19:50 PM - Software Distribution Service 3.0
RP315: 8/23/2009 9:19:50 PM - Software Distribution Service 3.0
RP316: 8/23/2009 9:19:50 PM - Software Distribution Service 3.0
RP317: 8/23/2009 9:19:50 PM - Software Distribution Service 3.0
RP318: 8/23/2009 9:19:51 PM - Software Distribution Service 3.0
RP319: 8/23/2009 9:19:51 PM - Software Distribution Service 3.0
RP320: 8/23/2009 9:19:51 PM - Software Distribution Service 3.0
RP321: 8/23/2009 9:19:51 PM - System Checkpoint
RP322: 8/23/2009 9:19:51 PM - Software Distribution Service 3.0
RP323: 8/23/2009 9:19:51 PM - Software Distribution Service 3.0
RP324: 8/23/2009 9:19:52 PM - Software Distribution Service 3.0
RP325: 8/23/2009 9:19:53 PM - Software Distribution Service 3.0
RP326: 8/23/2009 9:19:54 PM - Software Distribution Service 3.0
RP327: 8/23/2009 9:19:56 PM - Software Distribution Service 3.0
RP328: 8/23/2009 9:19:56 PM - Software Distribution Service 3.0
RP329: 8/23/2009 9:19:57 PM - Software Distribution Service 3.0
RP330: 8/23/2009 9:19:57 PM - Software Distribution Service 3.0
RP331: 8/23/2009 9:19:58 PM - Software Distribution Service 3.0
RP332: 8/23/2009 9:19:59 PM - Software Distribution Service 3.0
RP333: 8/23/2009 9:19:59 PM - Software Distribution Service 3.0
RP334: 8/23/2009 9:19:59 PM - Software Distribution Service 3.0
RP335: 8/23/2009 9:20:00 PM - Software Distribution Service 3.0
RP336: 8/23/2009 9:20:02 PM - Software Distribution Service 3.0
RP337: 8/23/2009 9:20:03 PM - Software Distribution Service 3.0
RP338: 8/23/2009 9:20:04 PM - Software Distribution Service 3.0
RP339: 8/23/2009 9:20:04 PM - Software Distribution Service 3.0
RP340: 8/23/2009 9:20:04 PM - Software Distribution Service 3.0
RP341: 8/23/2009 9:20:04 PM - Software Distribution Service 3.0
RP342: 8/23/2009 9:20:04 PM - Software Distribution Service 3.0
RP343: 8/23/2009 9:20:04 PM - Software Distribution Service 3.0
RP344: 8/23/2009 9:20:04 PM - Software Distribution Service 3.0
RP345: 8/23/2009 9:20:05 PM - Software Distribution Service 3.0
RP346: 8/23/2009 9:20:06 PM - Software Distribution Service 3.0
RP347: 8/23/2009 9:20:07 PM - Software Distribution Service 3.0
RP348: 8/23/2009 9:49:35 PM - Software Distribution Service 3.0
RP349: 8/29/2009 6:32:36 PM - System Checkpoint
RP350: 9/7/2009 8:03:31 PM - Printer Driver Microsoft XPS Document Writer Installed
RP351: 9/13/2009 5:24:58 PM - Software Distribution Service 3.0
==== Installed Programs ======================
32 Bit HP CIO Components Installer
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.0
AIO_Scan
ArcSoft PhotoImpression
ArcSoft Software Suite
B57Inst
BCM V.92 56K Modem
Broadcom Driver Installer
BufferChm
C4200
C4200_doccd
c4200_Help
Creative MediaSource 5
Creative Removable Disk Manager
Creative System Information
Creative ZEN V Series (R2)
Critical Update for Windows Media Player 11 (KB959772)
Custom Info
DAO
Data Lifeguard Tools
Dell Picture Studio - Dell Image Expert
Dell Solution Center
DellSupport
DeviceManagementQFolder
DocProcQFolder
DVDSentry
EarthLink Accelerator
EarthLink Common
EarthLink Common Authentication
EarthLink FastLane
EarthLink IM
EarthLink MailBox
EarthLink MDAC
EarthLink Redistributed
EarthLink Setup
EarthLink Software
EarthLink Spyware Blocker
EarthLink TaskPanel
EarthLink Toolbar
EarthLink Update Manager
EarthLink Webspace
Easy CD Creator 5 Basic
ELNBonus
ERUNT 1.1j
Film Factory
GSP Sudoku
Help and Support Customization
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HP Photosmart All-In-One Software 9.0
HPSSupply
Intel(R) PRO Ethernet Adapter and Software
Intel(R) PROSet II
McAfee SecurityCenter
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.0 Hotfix (KB928367)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2003
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft Picture It! Photo 7.0
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Word 2002
Microsoft Works 2003 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
Microsoft XML Parser
Modem Helper
Mozilla Firefox (3.5.2)
MSSoap
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MUSICMATCH Jukebox
Nero Suite
Nikon View 6
NVIDIA Display Driver
NVIDIA Windows 2000/XP Display Drivers
Paint Shop Pro 7
PowerDVD
PowerQuest Drive Image 7.0
PS_AIO_ProductContext
PS_AIO_Software
PS_AIO_Software_min
Qualxserve Service Agreement
QuickTime
RealOne Player
RegVac - Trial Version
Savings Bond Wizard
Scan
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Shockwave
Sound Blaster Live!
Spybot - Search & Destroy
Toolbox
UnloadSupport
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
WebFldrs XP
WebReg
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
Works Suite OS Pack
ZENcast Organizer
==== Event Viewer Messages From Past Week ========
9/8/2009 6:13:42 AM, error: System Error [1003] - Error code 100000d1, parameter1 e1916000, parameter2 00000002, parameter3 00000000, parameter4 f5b0a225.
9/7/2009 8:53:38 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume5'. It has stopped monitoring the volume.
9/7/2009 8:39:10 PM, error: System Error [1003] - Error code 100000d1, parameter1 e191b000, parameter2 00000002, parameter3 00000000, parameter4 f5b0a225.
9/7/2009 8:19:29 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070663: Office XP Service Pack 3.
9/7/2009 8:06:40 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt
9/7/2009 8:03:07 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Automatic Updates service to connect.
9/7/2009 8:03:07 PM, error: Service Control Manager [7000] - The Automatic Updates service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/6/2009 7:28:29 AM, error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
9/6/2009 11:41:06 AM, error: System Error [1003] - Error code 100000d1, parameter1 e191d000, parameter2 00000002, parameter3 00000000, parameter4 f5b0a225.
9/13/2009 7:27:55 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
9/13/2009 7:21:09 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
9/11/2009 4:21:46 PM, error: System Error [1003] - Error code 100000d1, parameter1 e1936000, parameter2 00000002, parameter3 00000000, parameter4 f5b0a225.
9/11/2009 4:12:10 PM, error: Service Control Manager [7016] - The GEARSecurity service has reported an invalid current state 0.
==== End Of File ===========================