I did follow the required steps.
I'm trying to fix my dad's computer. He gets frequent anti-virus pop-ups, so I tried to install symantec anti-virus; however, the instillation had problems saying the program required C++ runtime to terminate (or something to that effect). So, then I tried to install MBAM, but the instillation ran into problems as well. I think the malware on my dad's computer is preventing me from taking steps to fix it. So I came here and followed as many as the required steps as I could.
I was able to complete the TFC step.
I was able to complete the system restore step.
I was able to complete the ERUNT step.
I was unable to complete the Malwarebytes' Anti-Malware (MBAM) step.
I was unable to complete the GMER Rootkit Scanner step.
I was able to complete the OTL log step and the results are posted below. Also, as I do this something called Sophos Anti-Virus has a popup from the taskbar saying (message 24 of 24) that File C:\WINDOWS\system32\zokipado.dll belongs to virus/spyware Troj/Virtum-Gen. I don't know if that is a genuine anti-virus program that he installed before or if it is Malware itself. Anyway, OTL is posted below:
OTL logfile created on: 12/25/2009 5:26:24 PM - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = C:\Documents and Settings\smhogen\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 527.00 Mb Available Physical Memory | 52.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 91.79 Gb Total Space | 53.25 Gb Free Space | 58.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: 560A142595
Current User Name: smhogen
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/12/25 17:24:43 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\smhogen\Desktop\OTL.exe
PRC - [2009/12/25 16:37:29 | 00,184,320 | ---- | M] () -- C:\Program Files\Altiris\AClient\AClntUsr.EXE
PRC - [2009/12/25 12:40:52 | 00,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/12/16 22:49:10 | 00,066,560 | ---- | M] (tzuk) -- C:\WINDOWS\srsdllpro.exe
PRC - [2009/09/21 16:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/06/05 11:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/10/06 08:23:59 | 00,172,032 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
PRC - [2008/10/06 08:19:35 | 00,069,632 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
PRC - [2008/10/06 08:03:06 | 00,098,304 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
PRC - [2008/08/30 10:18:14 | 00,029,744 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2008/04/13 17:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/19 02:15:38 | 00,106,496 | ---- | M] (WDC) -- C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
PRC - [2008/02/19 02:13:28 | 00,438,272 | ---- | M] (WDC) -- C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
PRC - [2008/01/11 19:54:31 | 00,623,992 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
PRC - [2007/08/03 10:04:08 | 00,245,760 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\AutoUpdate\ALMon.exe
PRC - [2007/08/01 19:28:48 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/06/08 15:37:55 | 00,654,848 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2006/09/06 10:05:44 | 01,891,416 | ---- | M] (GARMIN Corp.) -- C:\Garmin\gStart.exe
PRC - [2006/04/14 16:21:00 | 05,005,388 | ---- | M] (Altiris, Inc.) -- C:\Program Files\Altiris\AClient\ACLIENT.EXE
PRC - [2006/04/06 10:51:04 | 00,049,152 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
PRC - [2006/03/24 15:30:44 | 00,282,624 | R--- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2006/03/21 18:03:00 | 00,143,428 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2005/11/07 05:20:00 | 00,122,940 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE
PRC - [2004/02/13 17:35:44 | 00,233,472 | ---- | M] (Nikon Corporation) -- C:\Program Files\Nikon\NkView6\NkvMon.exe
========== Modules (SafeList) ==========
MOD - [2009/12/25 17:24:43 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\smhogen\Desktop\OTL.exe
MOD - [2009/09/25 14:02:56 | 00,092,160 | -HS- | M] () -- C:\WINDOWS\system32\kasirora.dll
MOD - [2009/09/11 22:06:52 | 00,051,712 | -HS- | M] () -- C:\WINDOWS\system32\paweharo.dll
MOD - [2009/09/11 22:06:52 | 00,051,712 | -HS- | M] () -- C:\WINDOWS\system32\fedoniko.dll
MOD - [2009/09/11 22:06:52 | 00,051,712 | -HS- | M] () -- C:\WINDOWS\system32\doheyesi.dll
========== Win32 Services (SafeList) ==========
SRV - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/06/14 10:07:22 | 00,183,280 | ---- | M] (Google) [Auto | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2009/06/05 11:48:14 | 00,144,712 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/10/06 08:23:59 | 00,172,032 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\AutoUpdate\ALsvc.exe -- (Sophos AutoUpdate Service)
SRV - [2008/10/06 08:19:35 | 00,069,632 | ---- | M] (Sophos Plc) [Unknown | Running] -- C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe -- (SAVAdminService)
SRV - [2008/10/06 08:03:06 | 00,098,304 | ---- | M] (Sophos Plc) [Unknown | Running] -- C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe -- (SAVService)
SRV - [2008/08/30 10:18:14 | 00,029,744 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-061008-081103)
SRV - [2008/02/19 02:15:38 | 00,106,496 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe -- (WDBtnMgrSvc.exe)
SRV - [2007/06/08 15:37:55 | 00,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2007/03/20 16:41:24 | 00,153,792 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe -- (Adobe Version Cue CS3)
SRV - [2006/08/25 12:00:38 | 02,528,960 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE -- (LiveUpdate)
SRV - [2006/04/14 16:21:00 | 05,005,388 | ---- | M] (Altiris, Inc.) [Auto | Running] -- C:\Program Files\Altiris\AClient\AClient.exe -- (AClient)
SRV - [2006/03/21 18:03:00 | 00,143,428 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...m...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mesasports.org/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.mpsaz.org:8000
FF - HKLM\software\mozilla\Firefox\Extensions\\{400F0BDB-6C49-43A4-BE1F-76D7327A604D}: C:\Program Files\Common Files\fluxDVD\Download Manager\Mozilla [2008/07/19 16:11:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/25 12:41:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/25 12:41:08 | 00,000,000 | ---D | M]
[2009/07/31 21:20:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\smhogen\Application Data\Mozilla\Extensions
[2009/12/24 13:24:04 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/07/19 20:22:48 | 00,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de680400}
[2007/05/09 16:52:20 | 00,000,000 | ---D | M] (IE View Lite) -- C:\Program Files\Mozilla Firefox\extensions\{FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3}
[2009/12/24 13:24:04 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions
[2009/08/26 07:59:31 | 00,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/01 21:01:33 | 00,000,000 | ---D | M] (IE View Lite) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions\{FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3}
[2007/03/02 06:17:24 | 00,095,200 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPAPIX.dll
[2007/01/17 04:18:04 | 00,095,200 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPFluxBrowserHelper.dll
[2007/12/19 05:57:38 | 00,310,272 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
[2007/07/02 08:42:20 | 00,103,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPMPDRM.dll
[2007/02/20 16:04:02 | 02,463,976 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (Download Manager Browser Helper Object) - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\Program Files\Common Files\fluxDVD\Download Manager\XEBDLHelper.dll (Protect Software GmbH)
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (no name) - {a3b4f889-77ad-4aa0-946c-f83b67a6502d} - C:\WINDOWS\System32\fedoniko.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AClntUsr] C:\Program Files\Altiris\AClient\AClntUsr.EXE ()
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe_ID0EYTHM] C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [CinemaNowMediaManagerApp] C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemanowShell.exe File not found
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DVDLauncher] C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [menekuzevi] C:\WINDOWS\System32\doheyesi.dll ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
O4 - HKLM..\Run: [wobewoyob] C:\WINDOWS\System32\kasirora.DLL ()
O4 - HKCU..\Run: [gStart] C:\Garmin\gStart.exe (GARMIN Corp.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [ttool] C:\WINDOWS\srsdllpro.exe (tzuk)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe (Nikon Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: mpsaz.org ([student] https in Local intranet)
O15 - HKCU\..Trusted Domains: mpsaz.org ([stuhs] https in Local intranet)
O15 - HKCU\..Trusted Domains: mpsaz.org ([stujr] https in Local intranet)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell....iler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft....k/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www1.snapfish...fishActivia.cab (Snapfish Activia)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1173217972812 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.micros...ntent/opuc4.cab (Office Update Installation Engine)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (c:\windows\system32\lavufanu.dll) - C:\WINDOWS\System32\lavufanu.dll File not found
O20 - AppInit_DLLs: (mezutilo.dll) - File not found
O20 - AppInit_DLLs: (paweharo.dll) - C:\WINDOWS\System32\paweharo.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\jiponite.dll) - C:\WINDOWS\System32\jiponite.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\rejanote.dll) - C:\WINDOWS\System32\rejanote.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\kasirora.dll) - C:\WINDOWS\system32\kasirora.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (logon.exe) - C:\WINDOWS\System32\logon.exe ()
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O21 - SSODL: liyikatal - {a68f9828-3a76-48c1-8155-50e1b910ff12} - C:\WINDOWS\System32\lavufanu.dll File not found
O21 - SSODL: misokivob - {f07a28ca-bb47-4a11-a897-2b78647b9550} - C:\WINDOWS\system32\kasirora.dll ()
O22 - SharedTaskScheduler: {a68f9828-3a76-48c1-8155-50e1b910ff12} - gahurihor - C:\WINDOWS\System32\lavufanu.dll File not found
O22 - SharedTaskScheduler: {f07a28ca-bb47-4a11-a897-2b78647b9550} - gahurihor - C:\WINDOWS\system32\kasirora.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/03/06 13:53:52 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{b306e176-9d7b-11dd-bca2-00188bcfabe9}\Shell - "" = AutoRun
O33 - MountPoints2\{b306e176-9d7b-11dd-bca2-00188bcfabe9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b306e176-9d7b-11dd-bca2-00188bcfabe9}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O33 - MountPoints2\{fe296b20-77d9-11dd-bc72-00188bcfabe9}\Shell\AutoRun\command - "" = E:\WDSetup.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/03/06 13:53:28 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (206158430208)
========== Files/Folders - Created Within 14 Days ==========
[2009/12/25 17:24:42 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\smhogen\Desktop\OTL.exe
[2009/12/25 16:45:46 | 04,844,272 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\smhogen\Desktop\mbam-setup(2).exe
[2009/12/25 16:45:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/12/25 16:44:45 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/12/25 16:26:22 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\smhogen\Desktop\erunt_setup.exe
[2009/12/25 16:26:07 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\smhogen\Desktop\SysRestorePoint.exe
[2009/12/25 16:24:41 | 00,410,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\smhogen\Desktop\TFC.exe
[2009/12/25 16:18:36 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/25 16:18:34 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/12/25 16:18:34 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/12/25 16:18:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/12/25 12:56:22 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/12/25 12:54:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\smhogen\Local Settings\Application Data\Symantec
[2009/12/25 12:51:53 | 00,000,000 | ---D | C] -- C:\Program Files\Symantec
[2009/12/25 12:51:39 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2009/12/25 12:51:39 | 00,000,000 | ---D | C] -- C:\Program Files\Symantec AntiVirus
[2009/12/25 12:51:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2009/12/16 22:49:27 | 00,066,560 | ---- | C] (tzuk) -- C:\WINDOWS\srsdllpro.exe
[2009/11/21 19:50:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/10/28 15:25:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Temp
[2009/07/22 03:00:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/15 07:10:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2008/09/16 03:10:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/07/19 16:48:55 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/07/19 16:36:50 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2007/07/14 19:11:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
========== Files - Modified Within 14 Days ==========
[2009/12/25 17:27:12 | 00,006,456 | -H-- | M] () -- C:\WINDOWS\System32\yikopika
[2009/12/25 17:24:43 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\smhogen\Desktop\OTL.exe
[2009/12/25 17:16:45 | 00,086,571 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2009/12/25 17:16:45 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/12/25 17:16:30 | 00,001,336 | ---- | M] () -- C:\AClient.cfg
[2009/12/25 17:16:29 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009/12/25 17:16:20 | 00,063,783 | ---- | M] () -- C:\WINDOWS\System32\nvwsapps.xml
[2009/12/25 17:16:17 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2009/12/25 17:16:03 | 00,000,298 | ---- | M] () -- C:\WINDOWS\tasks\odyfbkyi.job
[2009/12/25 17:16:03 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/12/25 17:15:58 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/12/25 16:50:44 | 00,284,915 | ---- | M] () -- C:\Documents and Settings\smhogen\Desktop\gmer.zip
[2009/12/25 16:47:07 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/25 16:46:18 | 04,844,272 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\smhogen\Desktop\mbam-setup(2).exe
[2009/12/25 16:44:45 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\smhogen\Desktop\NTREGOPT.lnk
[2009/12/25 16:44:45 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\smhogen\Desktop\ERUNT.lnk
[2009/12/25 16:29:35 | 04,980,736 | -H-- | M] () -- C:\Documents and Settings\smhogen\ntuser.dat
[2009/12/25 16:29:27 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\smhogen\ntuser.ini
[2009/12/25 16:26:24 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\smhogen\Desktop\erunt_setup.exe
[2009/12/25 16:26:07 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Documents and Settings\smhogen\Desktop\SysRestorePoint.exe
[2009/12/25 16:24:42 | 00,410,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\smhogen\Desktop\TFC.exe
[2009/12/25 16:03:37 | 00,000,000 | ---- | M] () -- C:\WINDOWS\vpc32.INI
[2009/12/25 12:40:16 | 00,007,680 | ---- | M] () -- C:\Documents and Settings\smhogen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/24 17:22:12 | 00,060,416 | ---- | M] () -- C:\Documents and Settings\smhogen\Desktop\Athletics 2010-2011.doc
[2009/12/16 22:49:10 | 00,066,560 | ---- | M] (tzuk) -- C:\WINDOWS\srsdllpro.exe
[2009/12/16 22:29:19 | 00,076,800 | ---- | M] () -- C:\Documents and Settings\smhogen\Desktop\Product for MLK.doc
========== Files Created - No Company Name ==========
[2009/12/25 16:50:43 | 00,284,915 | ---- | C] () -- C:\Documents and Settings\smhogen\Desktop\gmer.zip
[2009/12/25 16:47:07 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/25 16:44:45 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\smhogen\Desktop\NTREGOPT.lnk
[2009/12/25 16:44:45 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\smhogen\Desktop\ERUNT.lnk
[2009/12/25 16:03:37 | 00,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2009/12/25 14:02:58 | 00,000,298 | ---- | C] () -- C:\WINDOWS\tasks\odyfbkyi.job
[2009/12/24 15:15:34 | 00,060,416 | ---- | C] () -- C:\Documents and Settings\smhogen\Desktop\Athletics 2010-2011.doc
[2009/12/16 22:29:19 | 00,076,800 | ---- | C] () -- C:\Documents and Settings\smhogen\Desktop\Product for MLK.doc
[2009/12/06 14:20:53 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\zomuhiwu.dll
[2009/11/01 20:36:39 | 00,018,941 | ---- | C] () -- C:\WINDOWS\microsoftdef.dll
[2009/09/25 14:02:56 | 00,092,160 | -HS- | C] () -- C:\WINDOWS\System32\kasirora.dll
[2009/09/25 14:02:56 | 00,061,440 | -HS- | C] () -- C:\WINDOWS\System32\tavegebi.dll
[2009/09/25 14:02:56 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\mejejaza.dll
[2009/09/25 02:02:21 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\vumehito.dll
[2009/09/24 14:05:05 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\vobulite.dll
[2009/09/24 14:05:05 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\muturebe.dll
[2009/09/19 04:23:26 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\gokefena.dll
[2009/09/19 04:23:26 | 00,037,888 | -HS- | C] () -- C:\WINDOWS\System32\medusuli.dll
[2009/09/18 16:23:11 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\dejufedu.dll
[2009/09/18 16:23:11 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\kuvimulo.dll
[2009/09/17 18:38:30 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\zifubogu.dll
[2009/09/17 18:38:30 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\sadotawa.dll
[2009/09/16 17:20:48 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\govegomu.dll
[2009/09/15 17:10:29 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\yokamuye.dll
[2009/09/15 17:10:29 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\majudusu.dll
[2009/09/14 11:42:37 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\kamideva.dll
[2009/09/13 22:48:57 | 00,092,160 | -HS- | C] () -- C:\WINDOWS\System32\letuyami.dll
[2009/09/13 22:48:57 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\jelulede.dll
[2009/09/13 10:49:07 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\piwihivo.dll
[2009/09/13 10:49:07 | 00,000,001 | -HS- | C] () -- C:\WINDOWS\System32\susopaya.dll
[2009/09/12 12:54:15 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\tewehipo.dll
[2009/09/12 12:54:15 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\zewewegi.dll
[2009/09/11 22:06:52 | 00,051,712 | -HS- | C] () -- C:\WINDOWS\System32\paweharo.dll
[2009/09/11 22:06:52 | 00,051,712 | -HS- | C] () -- C:\WINDOWS\System32\fedoniko.dll
[2009/09/11 22:06:52 | 00,051,712 | -HS- | C] () -- C:\WINDOWS\System32\doheyesi.dll
[2009/09/11 22:06:14 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\hesudobu.dll
[2009/09/11 22:06:14 | 00,051,712 | -HS- | C] () -- C:\WINDOWS\System32\rovoyato.dll
[2009/09/11 22:06:14 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\zoroviro.dll
[2009/09/06 14:18:52 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\buyenayo.dll
[2009/09/05 22:38:30 | 00,092,160 | -HS- | C] () -- C:\WINDOWS\System32\rosovoti.dll
[2009/09/05 22:38:30 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\jigedohu.dll
[2009/09/05 10:39:49 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\yemibumi.dll
[2009/08/29 19:30:45 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\wirijepi.dll
[2009/08/28 21:52:26 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\munemume.dll
[2009/08/28 09:53:18 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\tasasifu.dll
[2009/08/27 21:13:41 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\gupupehi.dll
[2009/08/27 09:14:58 | 00,092,672 | -HS- | C] () -- C:\WINDOWS\System32\yerehute.dll
[2009/08/27 09:14:58 | 00,052,224 | -HS- | C] () -- C:\WINDOWS\System32\doluwuhi.dll
[2009/08/27 09:14:58 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\hetuyevo.dll
[2009/08/22 20:06:56 | 00,092,160 | -HS- | C] () -- C:\WINDOWS\System32\filoloye.dll
[2009/08/22 20:06:56 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\wunipilo.dll
[2009/08/21 19:47:45 | 00,052,224 | -HS- | C] () -- C:\WINDOWS\System32\gedekuye.dll
[2009/08/21 19:47:45 | 00,044,544 | -HS- | C] () -- C:\WINDOWS\System32\loyuwisa.dll
[2009/08/21 19:47:45 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\tarozahi.dll
[2009/08/16 19:06:03 | 00,092,672 | -HS- | C] () -- C:\WINDOWS\System32\sazukojo.dll
[2009/08/16 19:06:03 | 00,051,200 | -HS- | C] () -- C:\WINDOWS\System32\dukotova.dll
[2009/08/16 19:06:02 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\dimadadu.dll
[2009/08/11 21:55:47 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\fovisuga.dll
[2009/08/10 20:03:54 | 00,051,712 | -HS- | C] () -- C:\WINDOWS\System32\yubuguyi.dll
[2009/08/10 20:03:54 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\zokipado.dll
[2009/08/09 20:49:35 | 00,051,200 | -HS- | C] () -- C:\WINDOWS\System32\matidaha.dll
[2009/08/09 20:49:35 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\jotumumu.dll
[2009/08/08 19:44:17 | 00,038,400 | -HS- | C] () -- C:\WINDOWS\System32\foyorere.dll
[2009/08/03 15:07:42 | 00,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/01 20:32:54 | 00,093,184 | -HS- | C] () -- C:\WINDOWS\System32\sinehotu.dll
[2009/08/01 20:32:54 | 00,052,224 | -HS- | C] () -- C:\WINDOWS\System32\pujawewo.dll
[2009/07/25 22:09:57 | 00,088,064 | -HS- | C] () -- C:\WINDOWS\System32\sodiluha.dll
[2008/01/18 15:59:23 | 00,000,145 | ---- | C] () -- C:\WINDOWS\BRVIDEO.INI
[2008/01/18 15:59:23 | 00,000,040 | ---- | C] () -- C:\WINDOWS\BRDIAG.INI
[2008/01/18 15:59:23 | 00,000,023 | ---- | C] () -- C:\WINDOWS\Brownie.ini
[2008/01/18 15:59:09 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\BROSNMP.DLL
[2008/01/18 15:59:09 | 00,026,624 | ---- | C] () -- C:\WINDOWS\System32\BRGSRC32.DLL
[2008/01/18 15:59:09 | 00,004,608 | ---- | C] () -- C:\WINDOWS\System32\BRGSRC16.DLL
[2008/01/18 15:59:08 | 00,008,975 | ---- | C] () -- C:\WINDOWS\HL-2040.INI
[2008/01/18 15:58:33 | 00,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2007/11/09 12:17:46 | 00,001,778 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/11/01 10:02:14 | 00,000,000 | ---- | C] () -- C:\WINDOWS\hpmnwun.ini
[2007/10/11 14:05:57 | 00,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2007/07/20 12:16:48 | 00,007,680 | ---- | C] () -- C:\Documents and Settings\smhogen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/06/11 10:37:06 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\setupw2k.dll
[2007/06/11 10:37:02 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\nwslog32.dll
[2007/06/08 15:47:13 | 02,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2007/05/09 17:04:31 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/05/09 16:24:30 | 00,000,172 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/05/09 15:30:29 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/03/06 14:33:06 | 00,002,401 | ---- | C] () -- C:\WINDOWS\System32\drivers\AlKernel.sys
[2007/03/06 14:19:19 | 00,000,234 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2007/03/06 14:09:18 | 00,016,480 | R--- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/03/21 18:03:00 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/03/21 18:03:00 | 01,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/03/21 18:03:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/03/21 18:03:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/03/21 18:03:00 | 00,098,304 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
========== LOP Check ==========
[2008/07/19 16:11:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fluxDVD
[2008/10/17 17:33:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GARMIN
[2008/07/19 16:11:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\mpDRM
[2007/11/29 08:12:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sophos
[2009/09/29 19:13:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/07 20:37:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/06/23 18:55:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\smhogen\Application Data\Nikon
[2007/05/09 16:14:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\smhogen\Application Data\OfficeUpdate12
[2008/07/19 16:50:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\smhogen\Application Data\Snapfish
[2009/12/25 17:16:03 | 00,000,298 | ---- | M] () -- C:\WINDOWS\Tasks\odyfbkyi.job
[2009/12/25 17:16:17 | 00,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/04/13 11:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2008/04/13 11:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 00:56:44 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 00:56:46 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:46 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 17:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< End of report >
OTL Extras logfile created on: 12/25/2009 5:26:24 PM - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = C:\Documents and Settings\smhogen\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 527.00 Mb Available Physical Memory | 52.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 91.79 Gb Total Space | 53.25 Gb Free Space | 58.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: 560A142595
Current User Name: smhogen
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS3 Server
"3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS3 Server
"50900:TCP" = 50900:TCP:*:Enabled:Adobe Version Cue CS3 Server
"50901:TCP" = 50901:TCP:*:Enabled:Adobe Version Cue CS3 Server
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"1700:TCP" = 1700:TCP:*:Enabled:MioNet Remote Drive Access 0
"1701:TCP" = 1701:TCP:*:Enabled:MioNet Remote Drive Access 1
"1702:TCP" = 1702:TCP:*:Enabled:MioNet Remote Drive Access 2
"1703:TCP" = 1703:TCP:*:Enabled:MioNet Remote Drive Access 3
"1704:TCP" = 1704:TCP:*:Enabled:MioNet Remote Drive Access 4
"1705:TCP" = 1705:TCP:*:Enabled:MioNet Remote Drive Access 5
"1706:TCP" = 1706:TCP:*:Enabled:MioNet Remote Drive Access 6
"1707:TCP" = 1707:TCP:*:Enabled:MioNet Remote Drive Access 7
"1708:TCP" = 1708:TCP:*:Enabled:MioNet Remote Drive Access 8
"1709:TCP" = 1709:TCP:*:Enabled:MioNet Remote Drive Access 9
"1641:TCP" = 1641:TCP:*:Enabled:MioNet Remote Drive Verification
"1647:TCP" = 1647:TCP:*:Enabled:MioNet Storage Device Configuration
"5432:UDP" = 5432:UDP:*:Enabled:MioNet Storage Device Discovery
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Altiris\AClient\AClntUsr.EXE" = C:\Program Files\Altiris\AClient\AClntUsr.EXE:*:Enabled:AClntUsr - AClient Interactive User Service -- ()
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" = C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:*:Enabled:Adobe Version Cue CS3 Server -- (Adobe Systems Incorporated)
"C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe" = C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe:*:Enabled:CinemaNow Media Manager -- File not found
"C:\Program Files\Hewlett-Packard\HP MediaSmart\Gateway\HPMediaSmartServicesGatewayService.exe" = C:\Program Files\Hewlett-Packard\HP MediaSmart\Gateway\HPMediaSmartServicesGatewayService.exe:*:Enabled:MediasmartService -- File not found
"C:\Program Files\Hewlett-Packard\HP MediaSmart\Gateway\HP MediaSmart Services Gateway.exe" = C:\Program Files\Hewlett-Packard\HP MediaSmart\Gateway\HP MediaSmart Services Gateway.exe:*:Enabled:MediaSmartTrayApp -- File not found
"C:\Program Files\MioNet\MioNetManager.exe" = C:\Program Files\MioNet\MioNetManager.exe:*:Enabled:MioNetManager -- File not found
"C:\Program Files\MioNet\jvm\bin\MioNet.exe" = C:\Program Files\MioNet\jvm\bin\MioNet.exe:*:Enabled:MioNet -- File not found
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer -- (Microsoft Corporation)
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe:*:Enabled:Acrotray -- (Adobe Systems Inc.)
"C:\WINDOWS\Temp\rdlF.tmp.exe" = C:\WINDOWS\Temp\rdlF.tmp.exe:*:Enabled:rdlF.tmp -- File not found
"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" = C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe:*:Enabled:GoogleUpdaterService -- (Google)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Disc 2
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{034759DA-E21A-4795-BFB3-C66D17FAD183}" = Sophos Anti-Virus
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{082BDF7B-4810-4599-BF0D-E3AC44EC8524}" = Microsoft ASP.NET 2.0 AJAX Extensions 1.0
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4}" = RemoteCapture 2.7.5
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1D58229F-C505-45CA-8223-F35F3A34B963}" = Adobe Version Cue CS3 Server {ko_KR}
"{2236B741-6631-49AE-B76E-3E14CA01CC87}" = RemoteCapture Task
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2D1C2321-8FDB-49B8-A66B-4008DC0B6B5D}" = File Viewer Utility 1.3.2
"{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
"{31A57C3E-30DD-421F-B5C7-974DACB0D05F}" = Canon Camera WIA Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.9
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A5D1A94-624A-4D20-B178-3A283B500370}" = Adobe Setup
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}" = Adobe Dreamweaver CS3
"{7DFC1012-D346-46CE-B03E-FF79125AE029}" = Adobe Fireworks CS3
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}" = Adobe Flash Player 9 Plugin
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{92CA58DD-4475-461C-828B-4A832B1EC080}" = Noiseware Community Edition
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A29EA741-24F7-4C07-9B2C-06CB6491BE4A}" = Camera Window
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A349ACBB-BFFD-4A5B-9C26-062BB1EA98A1}" = Brother HL-2040
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{AAB84E83-C8DF-4752-9DFC-2E2A48EE5E9F}" = Nikon View 6
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B7F560B3-6EFF-4026-A982-843895A41149}" = Adobe BridgeTalk Plugin CS3
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{BEF56F2D-56ED-4176-BF72-7B68D4A3B98D}" = Canon PhotoRecord
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon Utilities ZoomBrowser EX
"{C347D234-93D8-4595-BDAA-C04638B23B48}" = Adobe Creative Suite 3 Web Premium
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DE659AC8-EEF0-4115-AA0C-6500D194FB10}" = Garmin Training Center v5
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = PhotoStitch
"{F2E6CAF1-D651-4A74-8CC6-D92FE81FDBCC}" = WD Drive Manager (x86)
"{FAF0DAD8-1EA7-4FEF-80E5-8D8D6EBD5A23}" = RAW Image Task
"{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}" = Adobe Contribute CS3
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8.1.2 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe_247961ef275e20c5cb073c36394ac32" = Add or Remove Adobe Creative Suite 3 Web Premium
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"ERUNT_is1" = ERUNT 1.1j
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"hpc470bc" = HP Color LaserJet 4700 PCL 6 (Black) (02/24/2007 61.071.661.41)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4}" = Canon Utilities RemoteCapture 2.7
"InstallShield_{2236B741-6631-49AE-B76E-3E14CA01CC87}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{2D1C2321-8FDB-49B8-A66B-4008DC0B6B5D}" = Canon Utilities File Viewer Utility 1.3
"InstallShield_{31A57C3E-30DD-421F-B5C7-974DACB0D05F}" = Canon EOS Kiss REBEL 300D WIA Driver
"InstallShield_{A29EA741-24F7-4C07-9B2C-06CB6491BE4A}" = Canon Camera Window for ZoomBrowser EX
"InstallShield_{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{FAF0DAD8-1EA7-4FEF-80E5-8D8D6EBD5A23}" = Canon RAW Image Task for ZoomBrowser EX
"LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Picasa 3" = Picasa 3
"VLC media player" = VLC media player 0.9.4
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/8/2009 12:06:25 PM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
Error - 10/8/2009 1:06:34 PM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
Error - 10/8/2009 2:06:34 PM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
Error - 10/8/2009 3:06:34 PM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
Error - 10/8/2009 4:06:34 PM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
Error - 10/8/2009 5:06:34 PM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
Error - 10/8/2009 6:06:34 PM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
Error - 10/8/2009 7:06:34 PM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
Error - 10/16/2009 11:40:51 AM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
Error - 10/16/2009 11:50:31 AM | Computer Name = 560A142595 | Source = Google Update | ID = 20
Description =
[ System Events ]
Error - 12/25/2009 7:51:31 PM | Computer Name = 560A142595 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference
error message: The referenced assembly is not installed on your system. .
Error - 12/25/2009 7:51:31 PM | Computer Name = 560A142595 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00\MFC80U.DLL.
Reference
error message: The operation completed successfully. .
Error - 12/25/2009 8:16:21 PM | Computer Name = 560A142595 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last
Error was The referenced assembly is not installed on your system.
Error - 12/25/2009 8:16:21 PM | Computer Name = 560A142595 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference
error message: The referenced assembly is not installed on your system. .
Error - 12/25/2009 8:16:21 PM | Computer Name = 560A142595 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Western Digital\WD
Drive Manager\MFC80.DLL. Reference error message: The operation completed successfully.
.
Error - 12/25/2009 8:16:25 PM | Computer Name = 560A142595 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last
Error was The referenced assembly is not installed on your system.
Error - 12/25/2009 8:16:25 PM | Computer Name = 560A142595 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference
error message: The referenced assembly is not installed on your system. .
Error - 12/25/2009 8:16:25 PM | Computer Name = 560A142595 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Western Digital\WD
Drive Manager\MFC80.DLL. Reference error message: The operation completed successfully.
.
Error - 12/25/2009 8:16:50 PM | Computer Name = 560A142595 | Source = WMPNetworkSvc | ID = 866312
Description = A new media server was not initialized because WMCreateDeviceRegistration()
encountered error '0xc00d2781'. The Windows Media DRM components on your computer
might be corrupted. Verify that protected files play correctly in Windows Media
Player, and then restart the WMPNetworkSvc service.
Error - 12/25/2009 8:16:50 PM | Computer Name = 560A142595 | Source = WMPNetworkSvc | ID = 866312
Description = A new media server was not initialized because WMCreateDeviceRegistration()
encountered error '0xc00d2781'. The Windows Media DRM components on your computer
might be corrupted. Verify that protected files play correctly in Windows Media
Player, and then restart the WMPNetworkSvc service.
< End of report >
Thank you.