ComboFix, and SmitfraudFix. Attempted to clean with SuperAntiSpyware
but it was always freeze. SuperAntiSpyware was the only program that
would find Nullo Trojan in its list.
Windows XP Home, SP3
Thank You for your help.
OTL logfile created on: 12/10/2011 12:32:19 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and
Settings\Paul\Desktop\Malware Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type =
NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date
Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.51 Gb Available Physical Memory |
75.57% Memory free
3.85 Gb Paging File | 3.53 Gb Available in Paging File | 91.61% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% =
C:\Program Files
Drive C: | 146.47 Gb Total Space | 124.26 Gb Free Space | 84.84% Space
Free | Partition Type: NTFS
Computer Name: PAUL_LAPTOP | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company
Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/10 12:26:58 | 000,584,192 | ---- | M] (OldTimer Tools)
-- C:\Documents and Settings\Paul\Desktop\Malware Tools\OTL.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft
Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/05/25 12:38:46 | 000,112,176 | ---- | M] (SingleClick
Systems) -- C:\Program Files\Dell Network Assistant\hnm_svc.exe
========== Modules (No Company Name) ==========
MOD - [2007/12/11 14:21:52 | 000,753,664 | ---- | M] () --
C:\WINDOWS\system32\bcm1xsup.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (getPlus® Helper) getPlus®
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2007/05/25 12:38:46 | 000,112,176 | ---- | M] (SingleClick
Systems) [Auto | Running] -- C:\Program Files\Dell Network
Assistant\hnm_svc.exe -- (hnmsvc)
SRV - [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint
Corporation) [Disabled | Stopped] -- C:\Program
Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager
Service)
========== Driver Services (SafeList) ==========
DRV - [2007/12/11 14:22:24 | 001,123,328 | ---- | M] (Broadcom Corp.)
[Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2007/12/02 19:26:22 | 000,989,952 | ---- | M] (Conexant
Systems, Inc.) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2007/12/02 19:26:20 | 000,731,136 | ---- | M] (Conexant
Systems, Inc.) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2007/12/02 19:26:20 | 000,211,200 | ---- | M] (Conexant
Systems, Inc.) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2007/06/06 16:28:16 | 001,222,840 | ---- | M] (SigmaTel, Inc.)
[Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2007/05/08 22:49:02 | 000,045,568 | ---- | M] (Broadcom
Corporation) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2007/05/08 22:46:12 | 000,037,376 | ---- | M] (REDC) [Kernel |
Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys --
(rismxdp)
DRV - [2007/05/08 22:46:08 | 000,043,520 | ---- | M] (REDC) [Kernel |
Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys --
(rimsptsk)
DRV - [2007/05/08 22:46:06 | 000,032,256 | ---- | M] (REDC) [Kernel |
Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys --
(rimmptsk)
DRV - [2006/12/18 20:01:20 | 000,012,672 | ---- | M] (SingleClick
Systems) [Kernel | Auto | Running] --
C:\WINDOWS\system32\drivers\packet.sys -- (Packet)
DRV - [2006/11/02 13:31:38 | 000,103,168 | ---- | M] (Knowles
Acoustics) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\dxec02.sys -- (DXEC02)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL
= partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2080215
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page =
partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2080215
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:
"ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:
"ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaulturl:
"http://aim.search.ao...rud=07-07-2010"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage:
"http://www.aol.com/?...usaimc00000001"
FF - prefs.js..keyword.URL:
"http://search.avg.co...s&lng=en-US&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:
C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0:
c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll (
Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program
Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]:
C:\Program Files\MyWebSearch\bar\1.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox
3.6.8\extensions\\Components: C:\Program Files\Mozilla
Firefox\components [2010/12/12 16:50:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox
3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/12/02 18:58:46 | 000,000,000 | ---D | M]
[2010/04/16 04:59:19 | 000,000,000 | ---D | M] (No name found) --
C:\Documents and Settings\Paul\Application Data\Mozilla\Extensions
[2011/12/04 21:26:21 | 000,000,000 | ---D | M] (No name found) --
C:\Documents and Settings\Paul\Application
Data\Mozilla\Firefox\Profiles\rkkq2uri.default\extensions
[2010/07/07 16:33:03 | 000,001,490 | ---- | M] () -- C:\Documents and
Settings\Paul\Application
Data\Mozilla\Firefox\Profiles\rkkq2uri.default\searchplugins\AOL
Search.xml
[2010/04/16 04:59:01 | 000,000,000 | ---D | M] (No name found) --
C:\Program Files\Mozilla Firefox\extensions
[2010/07/07 16:33:03 | 000,001,490 | ---- | M] () -- C:\Program
Files\mozilla firefox\searchplugins\AOL Search.xml
O1 HOSTS File: ([2011/12/06 17:00:52 | 000,000,027 | ---- | M]) -
C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No
CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) -
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) -
{A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA
Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate]
C:\WINDOWS\System32\Macromed\Flash\FlashUtil10k_ActiveX.exe (Adobe
Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\Software\Microsoft\Windows\CurrentVersion\Group
Policy Objects\LocalUser\Software\Microsoft\Windows\CurrentVersion\Policies\System:
DisableTaskMgr = 1
O9 - Extra 'Tools' menuitem : Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB}
http://www.worldwinn...ed/wwlaunch.cab (Wwlaunch
Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab
(Java Plug-in 1.5.0_06)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...r/ultrashim.cab
(Reg Error: Key error.)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03}
http://www.worldwinn...eweledtwist.cab
(BejeweledTwist Control)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F}
http://www.worldwinn...v57/wof/wof.cab (WoF Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab
(Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab
(Java Plug-in 1.5.0_06)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A}
http://www.worldwinn.../familyfeud.cab
(FamilyFeud Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key
error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C4CE02C3-ABDD-4611-9C0A-C28702C59C51}:
DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe
(Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe)
-C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:2 () -
http://por-chr.cimco...0.png?rev=32172
O24 - Desktop Components:3 () -
http://www.burlingto...es/index_09.jpg
O24 - Desktop Components:4 () -
http://por-chr.cimco...0.png?rev=34749
O24 - Desktop Components:5 () - http://www.google.co...11/mlk11-hp.jpg
O24 - Desktop Components:6 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Paul\Local
Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/26 22:24:15 | 000,000,050 | ---- | M] ()
- C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/03/18 16:54:23 | 000,002,392 | ---- | M] ()
- C:\autorun.PNF -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days
==========
[2011/12/10 12:26:39 | 000,000,000 | ---D | C] -- C:\Documents and
Settings\Paul\Desktop\Malware Tools
[2011/12/05 21:43:12 | 000,000,000 | ---D | C] -- C:\Documents and
Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/12/05 21:33:22 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/12/03 10:50:20 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/12/03 00:33:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/12/02 23:56:07 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/12/02 23:54:08 | 000,518,144 | ---- | C] (SteelWerX) --
C:\WINDOWS\SWREG.exe
[2011/12/02 23:54:08 | 000,406,528 | ---- | C] (SteelWerX) --
C:\WINDOWS\SWSC.exe
[2011/12/02 23:54:08 | 000,212,480 | ---- | C] (SteelWerX) --
C:\WINDOWS\SWXCACLS.exe
[2011/12/02 23:54:08 | 000,060,416 | ---- | C] (NirSoft) --
C:\WINDOWS\NIRCMD.exe
[2011/12/02 23:53:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/12/02 23:52:18 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/02 23:52:13 | 000,000,000 | R--D | C] -- C:\Documents and
Settings\Paul\Start Menu\Programs\Administrative Tools
[2011/12/02 22:58:16 | 000,000,000 | ---D | C] -- C:\Documents and
Settings\All Users\Application Data\MFAData
[2011/12/02 18:56:37 | 000,000,000 | ---D | C] -- C:\Documents and
Settings\Paul\Local Settings\Application Data\SupportSoft
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/10 12:26:39 | 000,027,240 | ---- | M] () --
C:\WINDOWS\System32\nvModes.001
[2011/12/10 12:23:02 | 000,458,854 | ---- | M] () --
C:\WINDOWS\System32\perfh009.dat
[2011/12/10 12:23:02 | 000,076,244 | ---- | M] () --
C:\WINDOWS\System32\perfc009.dat
[2011/12/10 12:19:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/12/10 12:18:54 | 2145,427,456 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/10 12:14:02 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/12/06 17:00:55 | 000,001,286 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2011/12/06 17:00:52 | 000,000,027 | ---- | M] () --
C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/04 23:34:06 | 000,000,100 | ---- | M] () -- C:\Documents and
Settings\Paul\Desktop\Microsoft Fix it.url
[2011/12/02 23:56:13 | 000,000,327 | -H-- | M] () -- C:\boot.ini
[2011/12/02 18:20:06 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/07 18:33:32 | 2145,427,456 | -HS- | C] () -- C:\hiberfil.sys
[2011/12/04 23:34:06 | 000,000,100 | ---- | C] () -- C:\Documents and
Settings\Paul\Desktop\Microsoft Fix it.url
[2011/12/04 21:28:19 | 000,001,286 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2011/12/02 23:56:13 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/12/02 23:56:10 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/12/02 23:54:08 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/12/02 23:54:08 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/12/02 23:54:08 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/12/02 23:54:08 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/12/02 23:54:08 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/01/20 17:50:59 | 000,000,664 | ---- | C] () --
C:\WINDOWS\System32\d3d9caps.dat
[2010/07/11 11:24:54 | 000,000,954 | ---- | C] () -- C:\Documents and
Settings\Paul\Application Data\wklnhst.dat
[2010/05/24 15:58:45 | 000,001,147 | ---- | C] () -- C:\WINDOWS\Jpuyuwuse.dat
[2010/05/24 15:58:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Cbofima.bin
[2010/05/24 15:56:58 | 000,000,020 | ---- | C] () -- C:\Documents and
Settings\NetworkService\Application Data\khiteb.dat
[2010/04/16 04:59:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/04/15 17:51:28 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/08/21 00:26:32 | 000,010,407 | ---- | C] () -- C:\WINDOWS\lyxo.com
[2009/08/12 19:23:10 | 000,010,668 | ---- | C] () -- C:\Documents and
Settings\Paul\Application Data\nogeda.dl
[2009/07/21 13:59:20 | 000,018,667 | ---- | C] () -- C:\Program
Files\Common Files\epijatir.bin
[2009/07/21 13:59:20 | 000,018,538 | ---- | C] () -- C:\Program
Files\Common Files\asajudig.reg
[2009/07/21 13:59:20 | 000,017,647 | ---- | C] () -- C:\Program
Files\Common Files\dijim.bat
[2009/07/21 13:59:20 | 000,017,569 | ---- | C] () -- C:\Documents and
Settings\Paul\Local Settings\Application Data\apesosiluq._sy
[2009/07/21 13:59:20 | 000,016,763 | ---- | C] () -- C:\Documents and
Settings\Paul\Local Settings\Application Data\adynu._dl
[2009/07/21 13:59:20 | 000,015,947 | ---- | C] () --
C:\WINDOWS\System32\ytum.exe
[2009/07/21 13:59:20 | 000,015,871 | ---- | C] () -- C:\Documents and
Settings\All Users\Application Data\ikodo.inf
[2009/07/21 13:59:20 | 000,015,196 | ---- | C] () -- C:\Documents and
Settings\All Users\Application Data\humizu._sy
[2009/07/21 13:59:20 | 000,014,990 | ---- | C] () -- C:\Documents and
Settings\All Users\Application Data\rogyz.dat
[2009/07/21 13:59:20 | 000,014,367 | ---- | C] () -- C:\Documents and
Settings\Paul\Local Settings\Application Data\ihowavo.pif
[2009/07/21 13:59:20 | 000,013,993 | ---- | C] () -- C:\WINDOWS\iwamivusin.com
[2009/07/21 13:59:20 | 000,013,608 | ---- | C] () -- C:\Program
Files\Common Files\ripivav.bat
[2009/07/21 13:59:20 | 000,013,138 | ---- | C] () -- C:\Documents and
Settings\Paul\Local Settings\Application Data\nowapi.pif
[2009/07/21 13:59:20 | 000,012,528 | ---- | C] () -- C:\Documents and
Settings\Paul\Local Settings\Application Data\gihadyne.exe
[2009/07/21 13:59:20 | 000,011,701 | ---- | C] () -- C:\Documents and
Settings\Paul\Application Data\ugevejube.db
[2009/07/21 13:59:20 | 000,010,556 | ---- | C] () -- C:\Documents and
Settings\Paul\Application Data\yhyran.ban
[2009/01/09 23:55:04 | 000,000,027 | ---- | C] () -- C:\WINDOWS\sssTbarV2.ini
[2009/01/09 23:35:03 | 000,000,074 | ---- | C] () -- C:\WINDOWS\st_affiliate.ini
[2009/01/08 16:41:15 | 000,017,841 | ---- | C] () --
C:\WINDOWS\System32\soap664.bin
[2009/01/08 16:41:15 | 000,017,709 | ---- | C] () --
C:\WINDOWS\System32\718page.dat
[2009/01/08 16:41:15 | 000,017,285 | ---- | C] () --
C:\WINDOWS\System32\sparse0672.bin
[2009/01/08 16:41:15 | 000,017,153 | ---- | C] () --
C:\WINDOWS\System32\keys726.dat
[2009/01/08 16:41:15 | 000,015,790 | ---- | C] () --
C:\WINDOWS\System32\user681.dat
[2009/01/08 16:41:15 | 000,015,376 | ---- | C] () --
C:\WINDOWS\System32\resource581.bin
[2009/01/08 16:41:15 | 000,014,820 | ---- | C] () --
C:\WINDOWS\System32\soap589.bin
[2009/01/08 16:41:15 | 000,013,326 | ---- | C] () --
C:\WINDOWS\System32\user598.dat
[2009/01/08 16:41:15 | 000,012,769 | ---- | C] () --
C:\WINDOWS\System32\threat606y.dat
[2009/01/08 16:41:15 | 000,012,146 | ---- | C] () --
C:\WINDOWS\System32\797base.bin
[2009/01/08 16:41:15 | 000,011,590 | ---- | C] () --
C:\WINDOWS\System32\cookies805.bin
[2009/01/08 16:41:15 | 000,011,275 | ---- | C] () --
C:\WINDOWS\System32\uninstall267.dat
[2009/01/08 16:41:15 | 000,010,096 | ---- | C] () --
C:\WINDOWS\System32\data032E.bin
[2009/01/08 16:41:15 | 000,009,539 | ---- | C] () --
C:\WINDOWS\System32\keys822.dat
[2009/01/08 16:41:15 | 000,008,045 | ---- | C] () -- C:\WINDOWS\System32\33f.dat
[2009/01/08 16:41:15 | 000,007,489 | ---- | C] () --
C:\WINDOWS\System32\user839.dat
[2009/01/08 16:41:15 | 000,007,206 | ---- | C] () --
C:\WINDOWS\System32\wtl_dt430.bin
[2009/01/08 16:41:15 | 000,005,712 | ---- | C] () --
C:\WINDOWS\System32\user439.bin
[2009/01/08 16:41:15 | 000,005,580 | ---- | C] () -- C:\WINDOWS\System32\1ed.dat
[2009/01/08 16:41:15 | 000,005,024 | ---- | C] () --
C:\WINDOWS\System32\502backup.dat
[2009/01/08 16:41:15 | 000,004,401 | ---- | C] () --
C:\WINDOWS\System32\uninstall2b4.bin
[2009/01/08 16:41:15 | 000,003,845 | ---- | C] () --
C:\WINDOWS\System32\701_data.bin
[2009/01/08 16:41:15 | 000,003,661 | ---- | C] () --
C:\WINDOWS\System32\uninstall1c8.dat
[2009/01/08 16:41:15 | 000,003,420 | ---- | C] () --
C:\WINDOWS\System32\028F.bin
[2009/01/08 16:41:15 | 000,003,288 | ---- | C] () --
C:\WINDOWS\System32\709part.bin
[2009/01/08 16:41:15 | 000,003,105 | ---- | C] () --
C:\WINDOWS\System32\images465.dat
[2009/01/08 16:41:15 | 000,002,549 | ---- | C] () --
C:\WINDOWS\System32\wtl_dt473.dat
[2009/01/08 16:41:14 | 000,013,457 | ---- | C] () --
C:\WINDOWS\System32\0121mixed.bin
[2009/01/08 16:41:14 | 000,012,901 | ---- | C] () --
C:\WINDOWS\System32\297backup.bin
[2009/01/08 16:41:14 | 000,011,407 | ---- | C] () --
C:\WINDOWS\System32\306base.dat
[2009/01/08 16:41:14 | 000,010,850 | ---- | C] () --
C:\WINDOWS\System32\wtl_dt314.dat
[2009/01/08 16:41:14 | 000,009,356 | ---- | C] () --
C:\WINDOWS\System32\323page.dat
[2009/01/08 16:41:14 | 000,008,386 | ---- | C] () --
C:\WINDOWS\System32\231part.dat
[2009/01/08 16:41:14 | 000,006,891 | ---- | C] () --
C:\WINDOWS\System32\240page.dat
[2009/01/08 16:41:14 | 000,005,287 | ---- | C] () --
C:\WINDOWS\System32\139backup.bin
[2009/01/08 16:41:14 | 000,003,793 | ---- | C] () --
C:\WINDOWS\System32\147base.bin
[2009/01/08 16:41:14 | 000,003,237 | ---- | C] () --
C:\WINDOWS\System32\data009C.bin
[2008/06/15 10:18:20 | 000,011,776 | ---- | C] () -- C:\Documents and
Settings\Paul\Local Settings\Application
Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/23 12:01:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2008/02/14 22:52:37 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/02/14 22:47:48 | 000,198,144 | ---- | C] () --
C:\WINDOWS\System32\_psisdecd.dll
[2008/02/14 22:41:06 | 000,139,264 | ---- | C] () --
C:\WINDOWS\System32\preflib.dll
[2008/02/14 22:41:05 | 000,753,664 | ---- | C] () --
C:\WINDOWS\System32\bcm1xsup.dll
[2008/02/14 22:41:05 | 000,024,064 | ---- | C] () --
C:\WINDOWS\System32\WLTRYSVC.EXE
[2008/02/14 22:23:49 | 000,027,240 | ---- | C] () --
C:\WINDOWS\System32\nvModes.dat
[2008/02/14 22:17:57 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2008/02/14 22:17:56 | 000,016,480 | ---- | C] () --
C:\WINDOWS\System32\rixdicon.dll
[2008/02/14 22:17:43 | 001,626,112 | ---- | C] () --
C:\WINDOWS\System32\nwiz.exe
[2008/02/14 22:17:43 | 001,019,904 | ---- | C] () --
C:\WINDOWS\System32\nvwimg.dll
[2008/02/14 22:17:42 | 001,703,936 | ---- | C] () --
C:\WINDOWS\System32\nvwdmcpl.dll
[2008/02/14 22:17:42 | 001,018,804 | ---- | C] () --
C:\WINDOWS\System32\nvucode.bin
[2008/02/14 22:17:42 | 000,466,944 | ---- | C] () --
C:\WINDOWS\System32\nvshell.dll
[2008/02/14 22:17:41 | 001,474,560 | ---- | C] () --
C:\WINDOWS\System32\nview.dll
[2008/02/14 22:17:41 | 001,339,392 | ---- | C] () --
C:\WINDOWS\System32\nvdspsch.exe
[2008/02/14 22:17:38 | 000,442,368 | ---- | C] () --
C:\WINDOWS\System32\nvappbar.exe
[2008/02/14 22:17:38 | 000,425,984 | ---- | C] () --
C:\WINDOWS\System32\keystone.exe
[2008/02/14 22:16:12 | 000,001,118 | ---- | C] () --
C:\WINDOWS\System32\OEMINFO.INI
[2007/08/26 21:45:44 | 000,438,272 | ---- | C] () --
C:\WINDOWS\System32\OpenQuicktimeLib_dec.dll
[2004/08/10 14:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | ---- | C] () --
C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 14:01:18 | 000,001,793 | ---- | C] () --
C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 13:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 000,333,072 | ---- | C] () --
C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | ---- | C] () --
C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,458,854 | ---- | C] () --
C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | ---- | C] () --
C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,076,244 | ---- | C] () --
C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | ---- | C] () --
C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | ---- | C] () --
C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | ---- | C] () --
C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | ---- | C] () --
C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | ---- | C] () --
C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | ---- | C] () --
C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | ---- | C] () --
C:\WINDOWS\System32\dcache.bin
========== LOP Check ==========
[2008/10/04 20:03:53 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\All Users\Application Data\Acoustica
[2011/12/02 18:49:04 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\All Users\Application Data\avg9
[2011/07/05 16:11:49 | 000,000,000 | -H-D | M] -- C:\Documents and
Settings\All Users\Application Data\Common Files
[2011/12/05 21:34:15 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\All Users\Application Data\MFAData
[2008/02/14 22:46:04 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\All Users\Application Data\SingleClick Systems
[2008/06/08 14:57:07 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\All Users\Application Data\Viewpoint
[2008/10/04 20:11:19 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\Paul\Application Data\Acoustica
[2008/10/11 11:16:57 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\Paul\Application Data\Audacity
[2010/07/11 11:25:10 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\Paul\Application Data\Template
========== Purity Check ==========
< End of report >
OTL Extras logfile created on: 12/10/2011 12:32:19 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and
Settings\Paul\Desktop\Malware Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type =
NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date
Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.51 Gb Available Physical Memory |
75.57% Memory free
3.85 Gb Paging File | 3.53 Gb Available in Paging File | 91.61% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% =
C:\Program Files
Drive C: | 146.47 Gb Total Space | 124.26 Gb Free Space | 84.84% Space
Free | Partition Type: NTFS
Computer Name: PAUL_LAPTOP | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company
Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla
Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe
%SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L
(Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC
"8085:TCP" = 8085:TCP:*:Enabled:LitvinenKO
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dell\MediaDirect\PCMService.exe" = C:\Program
Files\Dell\MediaDirect\PCMService.exe:*:Enabled:CyberLink PowerCinema
Resident Program -- (CyberLink Corp.)
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program
Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network
Assistant -- (SingleClick Systems)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program
Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008
ATL Update kb973924 - x86 9.0.30729.4148
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008
Redistributable - x86 9.0.30729.4148
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4
Client Profile
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005
ATL Update kb973923 - x86 8.0.50727.4053
"{82CA0A0C-A3EC-4167-B694-909205B2EDEC}" = muvee Plugin 1.0
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005
Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update
for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI
(English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI
(English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint
MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher
MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook
MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI
(English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}"
= Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}"
= Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}"
= Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the
2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing
(English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}"
= Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath
MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI
(English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote
MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI
(English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove
Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared
Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access
Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}"
= Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint
Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008
Redistributable - x86 9.0.30729.17
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D1B5E9C8-4CCF-44E3-87D6-7C00D7DA5370}" = IntelliSonic Speech Enhancement
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"3ivx MPEG-4 5.0.1 Decoder" = 3ivx MPEG-4 5.0.1 Decoder (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA
D330 MDC V.92 Modem
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework
4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"NVIDIA Drivers" = NVIDIA Drivers
"SynTPDeinstKey" = Dell Touchpad
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows XP Service Pack" = Windows XP Service Pack 3
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12/2/2011 7:16:29 PM | Computer Name = PAUL_LAPTOP | Source =
EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during
its internal
processing. HRESULT was 8007041D from line 44 of
d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro
Error - 12/2/2011 7:16:59 PM | Computer Name = PAUL_LAPTOP | Source =
EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during
its internal
processing. HRESULT was 8007041D from line 44 of
d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro
Error - 12/2/2011 7:17:29 PM | Computer Name = PAUL_LAPTOP | Source =
EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during
its internal
processing. HRESULT was 8007041D from line 44 of
d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro
Error - 12/2/2011 8:03:36 PM | Computer Name = PAUL_LAPTOP | Source =
MsiInstaller | ID = 11706
Description = Product: Microsoft Works -- Error 1706.No valid source
could be found
for product Microsoft Works. The Windows installer cannot continue.
Error - 12/5/2011 12:39:47 AM | Computer Name = PAUL_LAPTOP | Source =
MsiInstaller | ID = 11921
Description = Product: Microsoft Fix it 50202 -- Error 1921. Service 'Automatic
Updates' (WUAUSERV) could not be stopped. Verify that you have
sufficient privileges
to stop system services.
Error - 12/5/2011 12:59:54 AM | Computer Name = PAUL_LAPTOP | Source =
MsiInstaller | ID = 11920
Description = Product: Microsoft Fix it 50202 -- Error 1920. Service 'Automatic
Updates' (WUAUSERV) failed to start. Verify that you have sufficient privileges
to start system services.
Error - 12/5/2011 10:39:24 PM | Computer Name = PAUL_LAPTOP | Source =
Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module shlwapi.dll, version 6.0.2900.5912, fault address 0x0002c4d8.
Error - 12/7/2011 1:04:19 PM | Computer Name = PAUL_LAPTOP | Source =
Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module shlwapi.dll, version 6.0.2900.5912, fault address 0x0002c4d8.
Error - 12/7/2011 1:06:26 PM | Computer Name = PAUL_LAPTOP | Source =
Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module shlwapi.dll, version 6.0.2900.5912, fault address 0x0002c4d8.
Error - 12/7/2011 1:10:45 PM | Computer Name = PAUL_LAPTOP | Source =
Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module shlwapi.dll, version 6.0.2900.5912, fault address 0x0002c4d8.
[ System Events ]
Error - 12/7/2011 7:28:15 PM | Computer Name = PAUL_LAPTOP | Source =
DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12/7/2011 7:28:33 PM | Computer Name = PAUL_LAPTOP | Source =
Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBios over Tcpip service
which failed to start because of the following error: %%31
Error - 12/7/2011 7:28:33 PM | Computer Name = PAUL_LAPTOP | Source =
Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol
Driver service
which failed to start because of the following error: %%31
Error - 12/7/2011 7:28:33 PM | Computer Name = PAUL_LAPTOP | Source =
Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31
Error - 12/7/2011 7:28:33 PM | Computer Name = PAUL_LAPTOP | Source =
Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver
service which
failed to start because of the following error: %%31
Error - 12/7/2011 7:28:33 PM | Computer Name = PAUL_LAPTOP | Source =
Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss
SASDIFSV SASKUTIL Tcpip
Error - 12/7/2011 7:32:42 PM | Computer Name = PAUL_LAPTOP | Source =
DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 12/7/2011 7:32:52 PM | Computer Name = PAUL_LAPTOP | Source =
DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12/10/2011 1:14:26 PM | Computer Name = PAUL_LAPTOP | Source =
W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS
lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try
the DNS lookup
again in 15 minutes. The error was: A socket operation was
attempted to an unreachable
host. (0x80072751)
Error - 12/10/2011 1:14:26 PM | Computer Name = PAUL_LAPTOP | Source =
W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently
accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no
source of accurate
time.
< End of report >