Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: error message  (Read 8222 times)

0 Members and 1 Guest are viewing this topic.

bucx

    Topic Starter


    Rookie

    error message
    « on: February 18, 2010, 01:20:33 PM »
    I hope I am doing this right.
    I posted a question " I am receiving a error message after reading a link, and have been required to disable Stopzilla popup blocker. message "memory cannot read" . I have dumped Stopzilla.
    I completed virus and spyware instruction. Logs follow.

    (No big problem except this error message every time I read a link)




    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 02/18/2010 at 12:30 PM

    Application Version : 4.26.1006

    Core Rules Database Version : 4600
    Trace Rules Database Version: 2412

    Scan type       : Complete Scan
    Total Scan Time : 00:59:05

    Memory items scanned      : 450
    Memory threats detected   : 0
    Registry items scanned    : 5419
    Registry threats detected : 0
    File items scanned        : 40213
    File threats detected     : 0





    lwarebytes' Anti-Malware 1.38
    Database version: 2403
    Windows 5.1.2600 Service Pack 3

    2/18/2010 1:21:35 PM
    mbam-log-2010-02-18 (13-21-35).txt

    Scan type: Quick Scan
    Objects scanned: 87280
    Time elapsed: 3 minute(s), 50 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)




    ogfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:16:53 PM, on 2/18/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
    C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182175791390
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O16 - DPF: {D6016EE7-A8FF-11D1-B37E-A4759ECD7909} (AxPulse Class) - http://www.pulse3d.com/players/english/PulsePlayerAxWin.cab
    O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://vpn.financialfreedom.com/dana-cached/setup/JuniperSetupSP1.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 7792 bytes



    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: error message
    « Reply #1 on: February 18, 2010, 01:32:25 PM »
    Please run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install
    • Click Start
    • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, you may close the window
    • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    ~Dr Jay

    bucx

      Topic Starter


      Rookie

      Re: error message
      « Reply #2 on: February 18, 2010, 05:44:45 PM »
      Iran a scan on Eset but I cannot get it to copy/paste.

      bucx

        Topic Starter


        Rookie

        Re: error message
        « Reply #3 on: February 19, 2010, 01:50:12 PM »
        I ran the Eset scan again but I'm having trouble capturing the log file.
        Can you instruct me??

        Dr Jay

        • Malware Removal Specialist


        • Specialist
        • Moderator emeritus
        • Thanked: 119
        • Experience: Guru
        • OS: Windows 10
        Re: error message
        « Reply #4 on: February 19, 2010, 03:53:59 PM »
        Try this tool:

        Please download <a href="http://www.helpmyos.com/Cheetah-php-h15.htm?cheetah.zip" target="_blank">Cheetah-Anti-Rogue[/url], and save to your Desktop.
        • Double-click on Cheetah-Anti-Rogue.zip, and extract the file to your Desktop.
        • Double-click on Cheetah-Anti-Rogue.cmd to start.
        • It will finish quickly and launch a log.
        • Post the contents of it in your next reply.
        ~Dr Jay

        bucx

          Topic Starter


          Rookie

          Re: error message
          « Reply #5 on: February 21, 2010, 02:49:27 PM »
          Jay
          >  I downloaded Cheetah-Anti-Rogue in your nessage
          > Got aTXT file listing Cheetah-Anti Rouge.cmd
          > got following log

          Malwarebytes' Anti-Malware 1.38
          Database version: 2403
          Windows 5.1.2600 Service Pack 3

          2/18/2010 1:21:35 PM
          mbam-log-2010-02-18 (13-21-35).txt

          Scan type: Quick Scan
          Objects scanned: 87280
          Time elapsed: 3 minute(s), 50 second(s)

          Memory Processes Infected: 0
          Memory Modules Infected: 0
          Registry Keys Infected: 0
          Registry Values Infected: 0
          Registry Data Items Infected: 0
          Folders Infected: 0
          Files Infected: 0

          Memory Processes Infected:
          (No malicious items detected)

          Memory Modules Infected:
          (No malicious items detected)



          Dr Jay

          • Malware Removal Specialist


          • Specialist
          • Moderator emeritus
          • Thanked: 119
          • Experience: Guru
          • OS: Windows 10
          Re: error message
          « Reply #6 on: February 23, 2010, 10:33:03 PM »
          Download OTL  to your Desktop
          • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
          • Under the Custom Scan box paste this in
          netsvcs
          msconfig
          safebootminimal
          safebootnetwork
          activex
          drivers32
          %SYSTEMDRIVE%\*.exe
          %systemroot%\*. /mp /s
          c:\$recycle.bin\*.* /s
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
          /md5start
          eventlog.dll
          scecli.dll
          netlogon.dll
          cngaudit.dll
          sceclt.dll
          ntelogon.dll
          logevent.dll
          iaStor.sys
          nvstor.sys
          nvstor32.sys
          atapi.sys
          IdeChnDr.sys
          viasraid.sys
          AGP440.sys
          vaxscsi.sys
          nvatabus.sys
          viamraid.sys
          nvata.sys
          nvgts.sys
          iastorv.sys
          ViPrt.sys
          eNetHook.dll
          explorer.exe
          svchost.exe
          userinit.exe
          qmgr.dll
          ws2_32.dll
          proquota.exe
          imm32.dll
          kernel32.dll
          ndis.sys
          autochk.exe
          spoolsv.exe
          xmlprov.dll
          ntmssvc.dll
          mswsock.dll
          Beep.SYS
          ntfs.sys
          termsrv.dll
          sfcfiles.dll
          st3shark.sys
          ahcix86.sys
          srsvc.dll
          nvrd32.sys
          /md5stop
          %systemroot%\system32\*.dll /lockedfiles
          %systemroot%\Tasks\*.job /lockedfiles

          • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
            • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
            • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time
          ~Dr Jay

          bucx

            Topic Starter


            Rookie

            Re: error message
            « Reply #7 on: March 01, 2010, 04:42:59 PM »
            Dragonmaster JAY

            I ran the OTL scan a have the two files. I tried to send them to you as a reply but was over the limit on characters.

             Should I send them in two new posts?

            Dr Jay

            • Malware Removal Specialist


            • Specialist
            • Moderator emeritus
            • Thanked: 119
            • Experience: Guru
            • OS: Windows 10
            Re: error message
            « Reply #8 on: March 01, 2010, 10:34:15 PM »
            Two or three. No biggie. Just so you get it all in, use as many posts as needed but try to limit it to less than 5. :)
            ~Dr Jay

            bucx

              Topic Starter


              Rookie

              Re: error message
              « Reply #9 on: March 02, 2010, 10:56:34 AM »
              logs will follow in new post as "error message follow up for JAY"


              Thanks

              bucx

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: error message
              « Reply #10 on: March 02, 2010, 11:10:46 AM »
              Please keep all of your replies to this issue in the same topic. Thanks. 

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: error message
              « Reply #11 on: March 02, 2010, 11:12:02 AM »
              OTL logfile created on: 3/1/2010 5:04:01 PM - Run 1
              OTL by OldTimer - Version 3.1.32.0     Folder = C:\Documents and Settings\Don\Desktop
              Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
              Internet Explorer (Version = 6.0.2900.5512)
              Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
               
              1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
              2.00 Gb Paging File | 1.00 Gb Available in Paging File | 86.00% Paging File free
              Paging file location(s): C:\pagefile.sys 412 768 [binary data]
               
              %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
              Drive C: | 66.95 Gb Total Space | 49.90 Gb Free Space | 74.53% Space Free | Partition Type: NTFS
              D: Drive not present or media not loaded
              E: Drive not present or media not loaded
              F: Drive not present or media not loaded
              G: Drive not present or media not loaded
              H: Drive not present or media not loaded
              I: Drive not present or media not loaded
               
              Computer Name: DON-7ZNRUN3UQBQ
              Current User Name: Don
              Logged in as Administrator.
               
              Current Boot Mode: Normal
              Scan Mode: Current user
              Company Name Whitelist: On
              Skip Microsoft Files: On
              File Age = 14 Days
              Output = Standard
              Quick Scan
               
              ========== Processes (SafeList) ==========
               
              PRC - [2010/03/01 16:57:40 | 000,551,424 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Don\Desktop\OTL.exe
              PRC - [2010/01/19 05:57:44 | 002,743,104 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
              PRC - [2010/01/19 05:57:41 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
              PRC - [2008/04/23 01:08:13 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
              PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
              PRC - [2008/03/27 22:51:18 | 000,116,032 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
              PRC - [2007/01/29 23:38:07 | 000,348,160 | ---- | M] (Juniper Networks) -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
               
               
              ========== Modules (SafeList) ==========
               
              MOD - [2010/03/01 16:57:40 | 000,551,424 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Don\Desktop\OTL.exe
               
               
              ========== Win32 Services (SafeList) ==========
               
              SRV - [2010/01/19 05:57:41 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
              SRV - [2010/01/19 05:57:41 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
              SRV - [2010/01/19 05:57:41 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
              SRV - [2007/01/29 23:38:07 | 000,348,160 | ---- | M] (Juniper Networks) [Auto | Running] -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe -- (dsNcService)
               
               
              ========== Standard Registry (SafeList) ==========
               
               
              ========== Internet Explorer ==========
               
              IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
              IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
              IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
               
              IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
              IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
              IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
              IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
              IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
               
              ========== FireFox ==========
               
              FF - prefs.js..browser.search.defaultenginen ame: "Google"
              FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
              FF - prefs.js..browser.search.selectedEngine: "Google"
               
              FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2008/05/17 09:52:32 | 000,000,000 | ---D | M]
               
              [2008/05/22 11:49:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\Mozilla\Firefox\Profiles\ixvmyvam.default\extensions
               
              O1 HOSTS File: ([2007/03/23 19:27:11 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
              O1 - Hosts: 127.0.0.1       localhost
              O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
              O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
              O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
              O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
              O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
              O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
              O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O3 - HKLM\..\Toolbar: (no name) - SITEguard - No CLSID value found.
              O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
              O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
              O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
              O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
              O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
              O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Acrobat.exe ()
              O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
              O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
              O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
              O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
              O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
              O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
              O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
              O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
              O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
              O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
              O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
              O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
              O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
              O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
              O15 - HKCU\..Trusted Domains:   ([]msn in My Computer)
              O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab (Reg Error: Key error.)
              O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182175791390 (MUWebControl Class)
              O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab (GMNRev Class)
              O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
              O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Value error.)
              O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
              O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab (MSN Games - Installer)
              O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
              O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
              O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
              O16 - DPF: {D6016EE7-A8FF-11D1-B37E-A4759ECD7909} http://www.pulse3d.com/players/english/PulsePlayerAxWin.cab (AxPulse Class)
              O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://vpn.financialfreedom.com/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
              O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.217.0.5 24.217.201.67 68.113.206.10
              O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
              O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
              O24 - Desktop WallPaper: C:\Documents and Settings\Don\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
              O24 - Desktop BackupWallPaper: C:\Documents and Settings\Don\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
              O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
              O32 - HKLM CDRom: AutoRun - 1
              O32 - AutoRun File - [2007/02/15 14:23:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
              O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
              O35 - comfile [open] -- "%1" %*
              O35 - exefile [open] -- "%1" %*
               
              NetSvcs: 6to4 -  File not found
              NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/02/15 14:23:04 | 000,000,000 | ---D | M]
              NetSvcs: Iprip -  File not found
              NetSvcs: Irmon -  File not found
              NetSvcs: NWCWorkstation -  File not found
              NetSvcs: Nwsapagent -  File not found
              NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
              NetSvcs: WmdmPmSp -  File not found
               
              MsConfig - StartUpReg: Free Registry Fix - hkey= - key= - Reg Error: Value error. File not found
              MsConfig - State: "system.ini" - 0
              MsConfig - State: "win.ini" - 0
              MsConfig - State: "bootini" - 0
              MsConfig - State: "services" - 0
              MsConfig - State: "startup" - 0
               
              SafeBootMin: Base - Driver Group
              SafeBootMin: Boot Bus Extender - Driver Group
              SafeBootMin: Boot file system - Driver Group
              SafeBootMin: File system - Driver Group
              SafeBootMin: Filter - Driver Group
              SafeBootMin: PCI Configuration - Driver Group
              SafeBootMin: PNP Filter - Driver Group
              SafeBootMin: Primary disk - Driver Group
              SafeBootMin: SCSI Class - Driver Group
              SafeBootMin: sermouse.sys - Driver
              SafeBootMin: System Bus Extender - Driver Group
              SafeBootMin: vds - Service
              SafeBootMin: vga.sys - Driver
              SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
              SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
              SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
              SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
              SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
              SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
              SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
              SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
              SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
              SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
              SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
              SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
              SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
              SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
               
              SafeBootNet: Base - Driver Group
              SafeBootNet: Boot Bus Extender - Driver Group
              SafeBootNet: Boot file system - Driver Group
              SafeBootNet: File system - Driver Group
              SafeBootNet: Filter - Driver Group
              SafeBootNet: NDIS Wrapper - Driver Group
              SafeBootNet: NetBIOSGroup - Driver Group
              SafeBootNet: NetDDEGroup - Driver Group
              SafeBootNet: Network - Driver Group
              SafeBootNet: NetworkProvider - Driver Group
              SafeBootNet: PCI Configuration - Driver Group
              SafeBootNet: PNP Filter - Driver Group
              SafeBootNet: PNP_TDI - Driver Group
              SafeBootNet: Primary disk - Driver Group
              SafeBootNet: SCSI Class - Driver Group
              SafeBootNet: sermouse.sys - Driver
              SafeBootNet: Streams Drivers - Driver Group
              SafeBootNet: System Bus Extender - Driver Group
              SafeBootNet: TDI - Driver Group
              SafeBootNet: UploadMgr -  File not found
              SafeBootNet: vga.sys - Driver
              SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
              SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
              SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
              SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
              SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
              SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
              SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
              SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
              SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
              SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
              SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
              SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
              SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
              SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
              SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
              SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
              SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
               
              ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
              ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
              ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
              ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
              ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
              ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
              ActiveX: {30C38EDD-7522-00A4-7262-9557AA7F6346} - Dynamic HTML Data Binding for Java
              ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
              ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
              ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
              ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
              ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
              ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
              ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
              ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX
              ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
              ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
              ActiveX: {4b218e3e-bc98-4770-93d3-2731b9329278} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf
              ActiveX: {4d64f3ba-f112-4efe-a02e-96680859937c} - KB918899
              ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
              ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
              ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Security Update for Windows XP (KB923789)
              ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
              ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
              ActiveX: {5b7bf89d-d196-4c32-a303-a57b8ab7f18d} - KB918439
              ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
              ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
              ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
              ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
              ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
              ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
              ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
              ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe
              ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
              ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
              ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
              ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
              ActiveX: {CAAFB8F9-F8D1-3D27-9AAA-6301A4429440} - .NET Framework
              ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
              ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
              ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
              ActiveX: {dd772a76-bef3-44d7-8b39-502c8504c1f1} - KB925486
              ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
              ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
              ActiveX: {f15ee071-deb7-4cbb-951f-431c98338d8e} - KB911567
              ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
              ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
              ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
              ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
              ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
               
              Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
              Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
              Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
              Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
              Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
              Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
               
              ========== Files/Folders - Created Within 14 Days ==========
               
              [2010/03/01 16:57:40 | 000,551,424 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Don\Desktop\OTL.exe
              [2010/02/22 12:20:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Don\My Documents\answ mach
              [2010/02/18 16:31:57 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
              [2010/02/18 11:10:37 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Don\Recent
              [2010/02/15 17:17:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Don\My Documents\cam pics
              [2008/12/26 22:52:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
              [2008/04/29 13:07:58 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
              [2007/03/25 09:24:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Juniper Networks
              [2007/03/24 16:27:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Juniper Networks
              [2007/02/15 17:17:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
              [2007/02/15 14:27:05 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
              [2007/02/15 14:27:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
              [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
              [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
               
              ========== Files - Modified Within 14 Days ==========
               
              [2010/03/01 16:57:40 | 000,551,424 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Don\Desktop\OTL.exe
              [2010/03/01 12:24:22 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
              [2010/03/01 12:16:40 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
              [2010/03/01 12:16:23 | 000,002,335 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
              [2010/03/01 12:14:35 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
              [2010/03/01 12:14:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
              [2010/02/28 00:51:53 | 009,961,472 | ---- | M] () -- C:\Documents and Settings\Don\NTUSER.DAT
              [2010/02/28 00:51:53 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Don\ntuser.ini
              [2010/02/28 00:51:36 | 005,370,756 | -H-- | M] () -- C:\Documents and Settings\Don\Local Settings\Application Data\IconCache.db
              [2010/02/26 17:15:00 | 000,000,386 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
              [2010/02/18 13:31:01 | 000,001,746 | ---- | M] () -- C:\Documents and Settings\Don\Desktop\HijackThis (2).lnk
              [2010/02/18 09:10:33 | 000,000,744 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
              [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
              [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
               
              ========== Files Created - No Company Name ==========
               
              [2010/02/18 13:41:27 | 000,001,746 | ---- | C] () -- C:\Documents and Settings\Don\Desktop\HijackThis (2).lnk
              [2010/02/18 09:09:53 | 000,000,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
              [2009/07/05 11:55:21 | 000,005,070 | ---- | C] () -- C:\Program Files\justn.txt
              [2009/04/02 11:13:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
              [2008/05/16 13:45:41 | 000,002,550 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
              [2008/01/12 11:55:27 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Don\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
              [2007/03/09 15:06:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\viewlink.ini
              [2007/03/08 11:24:53 | 000,000,990 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
              [2007/03/08 11:24:53 | 000,000,091 | ---- | C] () -- C:\WINDOWS\calera.ini
              [2007/03/08 11:24:43 | 000,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL
              [2007/03/08 11:24:43 | 000,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL
              [2007/03/08 11:24:43 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL
              [2007/03/08 11:24:28 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL
              [2007/02/15 20:06:27 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
              [2007/02/15 18:11:52 | 000,000,848 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
              [2007/02/15 14:58:19 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
              [2007/02/15 14:56:35 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
              [2007/02/15 14:50:07 | 000,000,199 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
              [2007/02/15 14:50:07 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
              [2005/12/10 02:06:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
              [2005/12/10 02:06:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
              [2005/12/10 02:06:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
              [2005/12/10 02:06:00 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
              [2005/12/10 02:06:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
              [2005/12/10 02:06:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
              [2005/12/10 02:06:00 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
              [2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
               
              ========== LOP Check ==========
               
              [2010/01/26 11:00:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
              [2009/01/16 13:11:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
              [2009/03/10 12:44:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Laconic Software
              [2009/01/16 13:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
              [2009/05/28 11:54:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings
              [2010/01/09 11:02:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard
              [2010/02/18 10:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
              [2009/07/28 15:54:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
              [2008/12/10 12:38:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
              [2009/08/12 14:07:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\Error Fix
              [2009/06/27 10:06:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\GetRightToGo
              [2009/07/01 08:17:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\IObit
              [2007/03/23 12:00:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\Juniper Networks
              [2009/03/10 12:21:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\Leadertech
              [2007/02/15 21:40:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\OfficeUpdate12
              [2009/01/16 13:13:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\ParetoLogic
              [2007/09/27 09:14:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\TuneUp Software
              [2009/07/03 15:15:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\uniblue
              [2007/04/16 12:20:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Don\Application Data\Wal-Mart Digital Photo Viewer
              [2010/02/26 17:15:00 | 000,000,386 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job
               
              ========== Purity Check ==========
               
               
               
              ========== Custom Scans ==========
               
               
              < %SYSTEMDRIVE%\*.exe >
               
              < %systemroot%\*. /mp /s >
               
              < c:\$recycle.bin\*.* /s >
               
              < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-02-17 06:50:21
               
               
              < MD5 for: AGP440.SYS  >
              [2007/02/15 16:21:17 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
              [2008/09/23 21:20:38 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
              [2007/02/15 16:21:17 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
              [2008/09/23 21:20:38 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
              [2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
              [2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
              [2004/08/04 00:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
               
              < MD5 for: ATAPI.SYS  >
              [2003/03/31 06:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
              [2007/02/15 16:21:17 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
              [2008/09/23 21:20:38 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
              [2007/02/15 16:21:17 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
              [2008/09/23 21:20:38 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
              [2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
              [2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
              [2004/08/03 23:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
               
              < MD5 for: AUTOCHK.EXE  >
              [2008/04/13 18:12:12 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
              [2008/04/13 18:12:12 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\autochk.exe
              [2004/08/04 01:56:47 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
               
              < MD5 for: BEEP.SYS  >
              [2003/03/31 06:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\dllcache\beep.sys
              [2003/03/31 06:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys
               
              < MD5 for: EVENTLOG.DLL  >
              [2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
              [2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
              [2004/08/04 01:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
               
              < MD5 for: EXPLORER.EXE  >
              [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
              [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
              [2007/06/13 05:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
              [2007/06/13 04:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
              [2004/08/04 01:56:49 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
               
              < MD5 for: IMM32.DLL  >
              [2008/04/13 18:11:54 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=0DA85218E92526972A821587E6A8BF8F -- C:\WINDOWS\ServicePackFiles\i386\imm32.dll
              [2008/04/13 18:11:54 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=0DA85218E92526972A821587E6A8BF8F -- C:\WINDOWS\system32\imm32.dll
              [2004/08/04 01:56:42 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=87CA7CE6469577F059297B9D6556D66D -- C:\WINDOWS\$NtServicePackUninstall$\imm32.dll
               
              < MD5 for: KERNEL32.DLL  >
              [2007/04/16 10:07:27 | 000,986,112 | ---- | M] (Microsoft Corporation) MD5=09F7CB3687F86EDAA4CA081F7AB66C03 -- C:\WINDOWS\$hf_mig$\KB935839\SP2QFE\kernel32.dll
              [2006/07/05 04:57:10 | 000,985,088 | ---- | M] (Microsoft Corporation) MD5=0FDD84928A5DDE2510761B7EC76CCEC9 -- C:\WINDOWS\$hf_mig$\KB917422\SP2QFE\kernel32.dll
              [2004/08/04 01:56:42 | 000,983,552 | ---- | M] (Microsoft Corporation) MD5=888190E31455FAD793312F8D087146EB -- C:\WINDOWS\$NtUninstallKB917422$\kernel32.dll
              [2003/03/31 06:00:00 | 000,930,304 | ---- | M] (Microsoft Corporation) MD5=8F162DC91D67D87C1A481BF602A9DAC8 -- C:\WINDOWS\$NtUninstallKB917422_0$\kernel32.dll
              [2007/04/16 09:52:53 | 000,984,576 | ---- | M] (Microsoft Corporation) MD5=A01F9CA902A88F7CED06884174D6419D -- C:\WINDOWS\$NtServicePackUninstall$\kernel32.dll
              [2009/03/21 08:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\system32\dllcache\kernel32.dll
              [2009/03/21 08:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\system32\kernel32.dll
              [2008/04/13 18:11:56 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=C24B983D211C34DA8FCC1AC38477971D -- C:\WINDOWS\$NtUninstallKB959426$\kernel32.dll
              [2008/04/13 18:11:56 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=C24B983D211C34DA8FCC1AC38477971D -- C:\WINDOWS\ServicePackFiles\i386\kernel32.dll
              [2006/07/05 04:55:01 | 000,984,064 | ---- | M] (Microsoft Corporation) MD5=D8DB5397DE07577C1CB50BA6D23B3AD4 -- C:\WINDOWS\$hf_mig$\KB917422\SP2GDR\kernel32.dll
              [2006/07/05 04:55:01 | 000,984,064 | ---- | M] (Microsoft Corporation) MD5=D8DB5397DE07577C1CB50BA6D23B3AD4 -- C:\WINDOWS\$NtUninstallKB935839$\kernel32.dll
              [2009/03/21 07:59:23 | 000,991,744 | ---- | M] (Microsoft Corporation) MD5=DA11D9D6ECBDF0F93436A4B7C13F7BEC -- C:\WINDOWS\$hf_mig$\KB959426\SP3QFE\kernel32.dll
               
              < MD5 for: MSWSOCK.DLL  >
              [2008/06/20 11:41:10 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=097722F235A1FB698BF9234E01B52637 -- C:\WINDOWS\$NtServicePackUninstall$\mswsock.dll
              [2008/06/20 11:36:11 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=1DFCA7713EA5A70D5D93B436AEA0317A -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\mswsock.dll
              [2004/08/04 01:56:44 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=4E74AF063C3271FBEA20DD940CFD1184 -- C:\WINDOWS\$NtUninstallKB951748$\mswsock.dll
              [2008/06/20 11:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\mswsock.dll
              [2008/06/20 11:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\system32\dllcache\mswsock.dll
              [2008/06/20 11:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\system32\mswsock.dll
              [2008/04/13 18:12:01 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=B4138E99236F0F57D4CF49BAE98A0746 -- C:\WINDOWS\ServicePackFiles\i386\mswsock.dll
              [2008/06/20 11:43:05 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=FCEE5FCB99F7C724593365C706D28388 -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\mswsock.dll
               
              < MD5 for: NDIS.SYS  >
              [2008/04/13 13:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
              [2008/04/13 13:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
              [2004/08/04 00:14:28 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
               
              < MD5 for: NETLOGON.DLL  >
              [2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
              [2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
              [2004/08/04 01:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
               
              < MD5 for: NTFS.SYS  >
              [2007/02/09 05:23:36 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=05AB81909514BFD69CBB1F2C147CF6B9 -- C:\WINDOWS\$hf_mig$\KB930916\SP2QFE\ntfs.sys
              [2007/02/09 05:10:35 | 000,574,464 | ---- | M] (Microsoft Corporation) MD5=19A811EF5F1ED5C926A028CE107FF1AF -- C:\WINDOWS\$NtServicePackUninstall$\ntfs.sys
              [2008/04/13 13:15:53 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ServicePackFiles\i386\ntfs.sys
              [2008/04/13 13:15:53 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys
              [2004/08/04 00:15:09 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\WINDOWS\$NtUninstallKB930916$\ntfs.sys
               
              < MD5 for: NTMSSVC.DLL  >
              [2008/04/13 18:12:02 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\ServicePackFiles\i386\ntmssvc.dll
              [2008/04/13 18:12:02 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\system32\ntmssvc.dll
              [2004/08/04 01:56:44 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=B62F29C00AC55A761B2E45877D85EA0F -- C:\WINDOWS\$NtServicePackUninstall$\ntmssvc.dll
               
              < MD5 for: PROQUOTA.EXE  >
              [2004/08/04 01:56:55 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=4D9D45A4370E0C2AD00C362B7118E2A4 -- C:\WINDOWS\$NtServicePackUninstall$\proquota.exe
              [2008/04/13 18:12:32 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\ServicePackFiles\i386\proquota.exe
              [2008/04/13 18:12:32 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\system32\proquota.exe
               
              < MD5 for: QMGR.DLL  >
              [2004/08/04 01:56:44 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\$NtServicePackUninstall$\qmgr.dll
              [2008/04/13 18:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\ServicePackFiles\i386\qmgr.dll
              [2008/04/13 18:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\bits\qmgr.dll
              [2008/04/13 18:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\qmgr.dll
              [2003/03/31 06:00:00 | 000,221,696 | ---- | M] (Microsoft Corporation) MD5=6A1CF14D0E7D0B2241F552223769C8A7 -- C:\WINDOWS\$NtUninstallKB842773$\qmgr.dll
               
              < MD5 for: SCECLI.DLL  >
              [2004/08/04 01:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
              [2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
              [2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
               
              < MD5 for: SFCFILES.DLL  >
              [2004/08/04 01:56:45 | 001,580,544 | ---- | M] (Microsoft Corporation) MD5=30A609E00BD1D4FFC49D6B5A432BE7F2 -- C:\WINDOWS\$NtServicePackUninstall$\sfcfiles.dll
              [2008/04/13 18:12:05 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\ServicePackFiles\i386\sfcfiles.dll
              [2008/04/13 18:12:05 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\system32\sfcfiles.dll
               
              < MD5 for: SPOOLSV.EXE  >
              [2004/08/04 01:56:57 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=7435B108B935E42EA92CA94F59C8E717 -- C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
              [2003/03/31 06:00:00 | 000,051,200 | ---- | M] (Microsoft Corporation) MD5=9B4155BA58192D4073082B8FC5D42612 -- C:\WINDOWS\$NtUninstallKB896423_0$\spoolsv.exe
              [2005/06/10 18:17:13 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=AD3D9D191AEA7B5445FE1D82FFBB4788 -- C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
              [2008/04/13 18:12:36 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=D8E14A61ACC1D4A6CD0D38AEBAC7FA3B -- C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
              [2008/04/13 18:12:36 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=D8E14A61ACC1D4A6CD0D38AEBAC7FA3B -- C:\WINDOWS\system32\spoolsv.exe
              [2005/06/10 17:53:32 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=DA81EC57ACD4CDC3D4C51CF3D409AF9F -- C:\WINDOWS\$hf_mig$\KB896423\SP2GDR\spoolsv.exe
              [2005/06/10 17:53:32 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=DA81EC57ACD4CDC3D4C51CF3D409AF9F -- C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
               
              < MD5 for: SRSVC.DLL  >
              [2008/04/13 18:12:07 | 000,171,008 | ---- | M] (Microsoft Corporation) MD5=3805DF0AC4296A34BA4BF93B346CC378 -- C:\WINDOWS\ServicePackFiles\i386\srsvc.dll
              [2008/04/13 18:12:07 | 000,171,008 | ---- | M] (Microsoft Corporation) MD5=3805DF0AC4296A34BA4BF93B346CC378 -- C:\WINDOWS\system32\srsvc.dll
              [2004/08/04 01:56:45 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\$NtServicePackUninstall$\srsvc.dll
               
              < MD5 for: SVCHOST.EXE  >
              [2008/04/13 18:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
              [2008/04/13 18:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
              [2004/08/04 01:56:57 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
               
              < MD5 for: TERMSRV.DLL  >
              [2004/08/04 01:56:46 | 000,295,424 | ---- | M] (Microsoft Corporation) MD5=B60C877D16D9C880B952FDA04ADF16E6 -- C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
              [2008/04/13 18:12:07 | 000,295,424 | ---- | M] (Microsoft Corporation) MD5=FF3477C03BE7201C294C35F684B3479F -- C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
              [2008/04/13 18:12:07 | 000,295,424 | ---- | M] (Microsoft Corporation) MD5=FF3477C03BE7201C294C35F684B3479F -- C:\WINDOWS\system32\termsrv.dll
               
              < MD5 for: USERINIT.EXE  >
              [2004/08/04 01:56:57 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
              [2008/04/13 18:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
              [2008/04/13 18:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
               
              < MD5 for: WS2_32.DLL  >
              [2008/04/13 18:12:10 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
              [2008/04/13 18:12:10 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
              [2004/08/04 01:56:46 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
              [2006/05/19 06:15:33 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=3748E0FC8C1B6ADA49F98C8E69A4228C -- C:\WINDOWS\$NtUninstallKB922819_0$\ws2_32.dll
              [2003/03/31 06:00:00 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=8529C295DF59B564D37A73B5629162B1 -- C:\WINDOWS\$NtUninstallKB914388_0$\ws2_32.dll
               
              < MD5 for: XMLPROV.DLL  >
              [2008/04/13 18:12:11 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=295D21F14C335B53CB8154E5B1F892B9 -- C:\WINDOWS\ServicePackFiles\i386\xmlprov.dll
              [2008/04/13 18:12:11 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=295D21F14C335B53CB8154E5B1F892B9 -- C:\WINDOWS\system32\xmlprov.dll
              [2004/08/04 01:56:46 | 000,129,536 | ---- | M] (Microsoft Corporation) MD5=EEF46DAB68229A14DA3D8E73C99E2959 -- C:\WINDOWS\$NtServicePackUninstall$\xmlprov.dll
               
              < %systemroot%\system32\*.dll /lockedfiles >
              [2008/04/13 18:11:52 | 000,357,888 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
              [2008/04/13 18:11:52 | 000,205,312 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
              [6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
               
              < %systemroot%\Tasks\*.job /lockedfiles >
               
              ========== Alternate Data Streams ==========
               
              @Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D287FACF
              @Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
              @Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B63300D1
              @Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
              < End of report >

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: error message
              « Reply #12 on: March 02, 2010, 11:12:28 AM »
              OTL Extras logfile created on: 3/1/2010 5:04:01 PM - Run 1
              OTL by OldTimer - Version 3.1.32.0     Folder = C:\Documents and Settings\Don\Desktop
              Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
              Internet Explorer (Version = 6.0.2900.5512)
              Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
               
              1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
              2.00 Gb Paging File | 1.00 Gb Available in Paging File | 86.00% Paging File free
              Paging file location(s): C:\pagefile.sys 412 768 [binary data]
               
              %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
              Drive C: | 66.95 Gb Total Space | 49.90 Gb Free Space | 74.53% Space Free | Partition Type: NTFS
              D: Drive not present or media not loaded
              E: Drive not present or media not loaded
              F: Drive not present or media not loaded
              G: Drive not present or media not loaded
              H: Drive not present or media not loaded
              I: Drive not present or media not loaded
               
              Computer Name: DON-7ZNRUN3UQBQ
              Current User Name: Don
              Logged in as Administrator.
               
              Current Boot Mode: Normal
              Scan Mode: Current user
              Company Name Whitelist: On
              Skip Microsoft Files: On
              File Age = 14 Days
              Output = Standard
              Quick Scan
               
              ========== Extra Registry (SafeList) ==========
               
               
              ========== File Associations ==========
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
               
              ========== Shell Spawning ==========
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
              batfile [open] -- "%1" %*
              cmdfile [open] -- "%1" %*
              comfile [open] -- "%1" %*
              exefile [open] -- "%1" %*
              htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
              htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
              piffile [open] -- "%1" %*
              regfile [merge] -- Reg Error: Key error.
              scrfile [config] -- "%1"
              scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
              scrfile [open] -- "%1" /S
              txtfile [edit] -- Reg Error: Key error.
              Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
              Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
              Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
              Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
              Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
               
              ========== Security Center Settings ==========
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
              "AntiVirusDisableNotify" = 0
              "FirewallDisableNotify" = 0
              "UpdatesDisableNotify" = 0
              "AntiVirusOverride" = 0
              "FirewallOverride" = 0
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
              "DisableMonitoring" = 1
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
              "DisableMonitoring" = 1
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
              "DisableMonitoring" = 1
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
               
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
               
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
              "EnableFirewall" = 1
              "DoNotAllowExceptions" = 0
              "DisableNotifications" = 0
               
              ========== Authorized Applications List ==========
               
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
               
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
              "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
              "C:\Documents and Settings\Don\Local Settings\Temp\7zS18.tmp\SymNRT.exe" = C:\Documents and Settings\Don\Local Settings\Temp\7zS18.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool -- File not found
              "C:\Documents and Settings\Don\Local Settings\Temp\7zS1D5.tmp\SymNRT.exe" = C:\Documents and Settings\Don\Local Settings\Temp\7zS1D5.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool -- File not found
               
               
              ========== HKEY_LOCAL_MACHINE Uninstall List ==========
               
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
              "{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
              "{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
              "{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
              "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
              "{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
              "{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 18
              "{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
              "{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
              "{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
              "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
              "{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
              "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
              "{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
              "{5E06C076-E4E7-4239-A886-B3D8AC84C166}" = HP Print Diagnostic Utility
              "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
              "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
              "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
              "{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
              "{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
              "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
              "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
              "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
              "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
              "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
              "{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = RTLSetup for Realtek RTL8139/810x Family NIC 3.00
              "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
              "{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
              "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
              "{AC76BA86-1033-F400-7760-000000000002}" = Adobe Acrobat 7.0 Professional - English, Français, Deutsch
              "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
              "{ACA85783-8EEA-4f0a-B2A3-A8173F30209F}" = C4200_doccd
              "{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
              "{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
              "{B09BCBF6-87EE-4403-A336-3A9510856535}" = HP Photosmart All-In-One Software 9.0
              "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
              "{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
              "{BFDE4176-5DFE-4db9-AA00-8F30CB001BDA}" = c4200_Help
              "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
              "{C39E671D-0528-4c5e-A034-8470C5BC393A}" = C4200
              "{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
              "{CC0E1AE3-091D-4969-B151-7AC142062C28}" = SmartWebPrinting
              "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
              "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
              "{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
              "{D8B7A682-20DA-4797-8415-B1FB14D4D32B}" = PS_AIO_Software
              "{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
              "{E28750A2-45F2-4b63-99F7-9F81A94B1E2D}" = PS_AIO_Software_min
              "{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
              "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
              "{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
              "{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
              "{FCC3BD6A-F118-475D-8748-7EE08EA0AF56}" = HDView for Internet Explorer
              "{FD7F242B-9AA0-40c3-941E-3A9821D19C09}" = PS_AIO_ProductContext
              "{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
              "Adobe Acrobat 7.0 Professional - EFG" = Adobe Acrobat 7.1.0 Professional - English, Français, Deutsch
              "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
              "avast5" = avast! Free Antivirus
              "CCleaner" = CCleaner (remove only)
              "ESET Online Scanner" = ESET Online Scanner v3
              "HijackThis" = HijackThis 2.0.2
              "HP Imaging Device Functions" = HP Imaging Device Functions 9.0
              "HP Photosmart Essential" = HP Photosmart Essential 2.01
              "HP Smart Web Printing" = HP Smart Web Printing
              "HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
              "HPOCR" = HP OCR Software 9.0
              "Juniper Network Connect 5.3.0" = Juniper Networks Network Connect 5.3.0
              "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
              "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
              "Microsoft.Net.Client.3.5" = Microsoft .NET Framework Client Profile - PREVIEW
              "NVIDIA Drivers" = NVIDIA Drivers
              "PCI Audio Driver" = PCI Audio Driver
              "RealPlayer 12.0" = RealPlayer
              "Windows Media Format Runtime" = Windows Media Format 11 runtime
              "Windows Media Player" = Windows Media Player 11
               
              ========== HKEY_CURRENT_USER Uninstall List ==========
               
              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
              "Move Media Player" = Move Media Player
              "Neoteris_Host_Checker" = Juniper Networks Host Checker
               
              ========== Last 10 Event Log Errors ==========
               
              [ Application Events ]
              Error - 2/17/2010 2:47:18 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 11311
              Description = Product: Microsoft Office Professional Edition 2003 -- Error 1311.
               Source file not found(cabinet): C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\PA561401.CAB.
                Verify that the file exists and that you can access it.
               
              Error - 2/17/2010 2:47:24 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 1024
              Description = Product: Microsoft Office Professional Edition 2003 - Update 'Security
               Update for Excel 2003 (KB973475): EXCEL' could not be installed. Error code 1603.
               Windows Installer can create logs to help troubleshoot issues with installing software
               packages. Use the following link for instructions on turning on logging support:
               http://go.microsoft.com/fwlink/?LinkId=23127
               
              Error - 2/17/2010 2:48:08 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 11311
              Description = Product: Microsoft Office Professional Edition 2003 -- Error 1311.
               Source file not found(cabinet): C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\PA561401.CAB.
                Verify that the file exists and that you can access it.
               
              Error - 2/17/2010 2:48:09 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 1024
              Description = Product: Microsoft Office Professional Edition 2003 - Update 'Security
               Update for Office 2003 (KB974554): FM20' could not be installed. Error code 1603.
               Windows Installer can create logs to help troubleshoot issues with installing software
               packages. Use the following link for instructions on turning on logging support:
               http://go.microsoft.com/fwlink/?LinkId=23127
               
              Error - 2/17/2010 2:48:50 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 11311
              Description = Product: Microsoft Office Professional Edition 2003 -- Error 1311.
               Source file not found(cabinet): C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\PA561401.CAB.
                Verify that the file exists and that you can access it.
               
              Error - 2/17/2010 2:48:50 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 1024
              Description = Product: Microsoft Office Professional Edition 2003 - Update 'Security
               Update for Office 2003 (KB975051): MSCONV' could not be installed. Error code 1603.
               Windows Installer can create logs to help troubleshoot issues with installing software
               packages. Use the following link for instructions on turning on logging support:
               http://go.microsoft.com/fwlink/?LinkId=23127
               
              Error - 2/17/2010 2:49:35 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 11311
              Description = Product: Microsoft Office Professional Edition 2003 -- Error 1311.
               Source file not found(cabinet): C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\PA561401.CAB.
                Verify that the file exists and that you can access it.
               
              Error - 2/17/2010 2:49:35 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 1024
              Description = Product: Microsoft Office Professional Edition 2003 - Update 'Security
               Update for Outlook 2003 (KB973705): OUTLOOK' could not be installed. Error code
               1603. Windows Installer can create logs to help troubleshoot issues with installing
               software packages. Use the following link for instructions on turning on logging
               support: http://go.microsoft.com/fwlink/?LinkId=23127
               
              Error - 2/17/2010 2:50:21 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 11311
              Description = Product: Microsoft Office Professional Edition 2003 -- Error 1311.
               Source file not found(cabinet): C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\PA561401.CAB.
                Verify that the file exists and that you can access it.
               
              Error - 2/17/2010 2:50:21 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = MsiInstaller | ID = 1024
              Description = Product: Microsoft Office Professional Edition 2003 - Update 'Update
               for Outlook 2003: Junk E-mail Filter (KB977713): OUTLFLTR' could not be installed.
               Error code 1603. Windows Installer can create logs to help troubleshoot issues
              with installing software packages. Use the following link for instructions on turning
               on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
               
              [ System Events ]
              Error - 2/19/2010 9:53:01 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
              Error - 2/20/2010 1:47:31 PM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
              Error - 2/21/2010 5:19:58 PM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
              Error - 2/22/2010 1:09:03 PM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
              Error - 2/23/2010 11:32:55 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
              Error - 2/24/2010 11:58:20 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
              Error - 2/25/2010 11:15:11 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
              Error - 2/26/2010 10:53:48 AM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
              Error - 2/27/2010 12:15:15 PM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
              Error - 3/1/2010 2:16:07 PM | Computer Name = DON-7ZNRUN3UQBQ | Source = Service Control Manager | ID = 7022
              Description = The Windows Image Acquisition (WIA) service hung on starting.
               
               
              < End of report >

              Dr Jay

              • Malware Removal Specialist


              • Specialist
              • Moderator emeritus
              • Thanked: 119
              • Experience: Guru
              • OS: Windows 10
              Re: error message
              « Reply #13 on: March 02, 2010, 10:41:02 PM »
              ~Dr Jay