malmal
Topic Starter
19049684.exe
Above process running after boot. Easily stopped but fear rootkit is intact.
Wallpaper hacked to info-*.bmp. Easily removed.
I created new gmail account to access this forum on the off chance this will allow some protection.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/09 00:33
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB1C2D000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AED000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB0E5A000 Size: 49152 File Visible: No Signed: -
Status: -
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 0:30:48.85 on Wed 09/09/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.157 [GMT 1:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\sndvol32.exe
svchost
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\mspaint.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\My Documents\Downloads\MALWARE REMOVAL\dds.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
uWindow Title = Windows Internet Explorer provided by Yahoo!
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\hp_owner\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [AlcxMonitor] ALCXMNTR.EXE
mRun: [PS2] c:\windows\system32\ps2.exe
mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [19049684] c:\documents and settings\all users\application data\19049684\19049684.exe
mRun: [PromoReg] c:\windows\temp\_ex-08.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Bpepim] rundll32.exe "c:\windows\uragimog.dll",e
StartupFolder: c:\documents and settings\hp_owner\start menu\programs\startup\ikowin32.exe
StartupFolder: c:\documents and settings\hp_owner\start menu\programs\startup\sndvol32.exe
IE: Add To HP Organize… - c:\progra~1\hewlet~1\hporga~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251083586781
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
LSA: Notification Packages = scecli cpsmsrtx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\hp_owner\applic~1\mozilla\firefox\profiles\458k918k.default\
FF - plugin: c:\documents and settings\hp_owner\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\hp_owner\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPOJI610.dll
FF - HiddenExtension: XUL Cache: {0E245123-471F-4EF8-B8D6-A27722726D2F} - c:\documents and settings\hp_owner\local settings\application data\{0E245123-471F-4EF8-B8D6-A27722726D2F}
FF - HiddenExtension: XUL Cache: {9CEA2E74-9BE8-46A6-8C9C-768342A83B2C} - c:\documents and settings\administrator\local settings\application data\{9cea2e74-9be8-46a6-8c9c-768342a83b2c}\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
S2 bktici;Center Windows;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S2 jnjfrat;Support Helper;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
=============== Created Last 30 ================
2009-09-08 21:33 –d—– c:\program files\Spybot - Search & Destroy
2009-09-08 21:33 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-09-08 21:10 120 a——- c:\windows\Dkisad.dat
2009-09-08 11:41 –d—– c:\program files\WinPcap
2009-09-08 11:39 –d—– c:\docume~1\alluse~1\applic~1\19049684
2009-09-08 02:42 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-08 02:42 73,728 a——- c:\windows\system32\javacpl.cpl
2009-09-08 01:40 3,701 a——- c:\windows\scad3.INI
2009-09-07 06:54 –d—– c:\program files\LTC
2009-09-06 08:44 –d—– c:\docume~1\hp_owner\applic~1\WinBatch
2009-09-05 22:53 –d—– c:\docume~1\hp_owner\applic~1\MathematicaPlayer
2009-09-05 22:53 –d—– c:\docume~1\alluse~1\applic~1\MathematicaPlayer
2009-09-05 21:24 378,152 a——- c:\windows\system32\ml32i3.dll
2009-09-05 21:24 349,480 a——- c:\windows\system32\mltcpip32.mlp
2009-09-05 21:24 267,560 a——- c:\windows\system32\ml32i2.dll
2009-09-05 21:24 259,368 a——- c:\windows\system32\ml32i1.dll
2009-09-05 21:24 185,640 a——- c:\windows\system32\mlmodule32.dll
2009-09-05 21:24 107,816 a——- c:\windows\system32\mltcp32.mlp
2009-09-05 21:24 103,720 a——- c:\windows\system32\mlshm32.mlp
2009-09-05 21:24 95,528 a——- c:\windows\system32\mlmap32.mlp
2009-09-05 21:23 –d—– c:\program files\Wolfram Research
2009-09-01 00:45 –d—– C:\CM60S
2009-09-01 00:45 363,892 a——- c:\windows\ISUN16.EXE
2009-09-01 00:45 26,768 a——- c:\windows\system\CTL3D.DLL
2009-08-31 21:18 695,642 a——- c:\windows\unins000.exe
2009-08-31 21:18 14,981 a——- c:\windows\unins000.dat
2009-08-31 21:18 –d—– c:\program files\common files\SourceTec
2009-08-31 21:02 67 a——- c:\windows\swf2avi.INI
2009-08-31 21:02 758,018 a——- c:\windows\system32\xvidcore.dll
2009-08-31 21:02 180,224 a——- c:\windows\system32\xvidvfw.dll
2009-08-31 21:02 139,264 a——- c:\windows\system32\xvid.ax
2009-08-31 21:02 –d—– c:\program files\iWisoft Flash SWF to Video Converter
2009-08-30 20:10 –d—– c:\windows\system32\cvirte
2009-08-30 20:10 –d—– c:\program files\SteornLab
2009-08-29 20:52 –d—– c:\program files\Vizimag 3.18
2009-08-28 19:08 368,912 a——- c:\windows\system32\vbar332.dll
2009-08-28 19:08 3,572,224 a——- c:\windows\system32\crpe32.dll
2009-08-28 19:08 1,037,312 a——- c:\windows\system32\msjet35.dll
2009-08-28 19:08 251,664 a——- c:\windows\system32\msrd2x35.dll
2009-08-28 19:08 121,104 a——- c:\windows\system32\msjint35.dll
2009-08-28 19:08 24,336 a——- c:\windows\system32\msjter35.dll
2009-08-28 19:08 17,920 a——- c:\windows\system32\implode.dll
2009-08-28 19:08 416,768 a——- c:\windows\system32\cpeaut32.dll
2009-08-28 19:08 –d—– c:\program files\OrCAD_Demo
2009-08-28 11:27 4 a——- c:\windows\Worddict.xph
2009-08-28 11:27 4 a——- c:\windows\system32\Msxls.dnh
2009-08-28 11:27 –d—– c:\program files\DeltaCad
2009-08-28 10:44 32,397 a——- c:\windows\SGTBox.INI
2009-08-28 10:34 –d—– c:\program files\Canon
2009-08-28 10:33 –d—– c:\temp\ScanGearToolboxCSv223
2009-08-28 10:21 15,104 a——- c:\windows\system32\drivers\usbscan.sys
2009-08-28 10:21 15,104 a——- c:\windows\system32\dllcache\usbscan.sys
2009-08-28 10:17 –d—– c:\temp\CanoScan
2009-08-28 10:17 –d—– C:\Temp
2009-08-27 04:05 –d—– c:\program files\IrfanView
2009-08-25 13:54 –d—– c:\program files\Scope
2009-08-25 13:52 –d—– c:\program files\Scope_131
2009-08-24 04:23 –d—– c:\program files\National Instruments
2009-08-24 04:15 31,768 a——- c:\windows\system32\wucltui.dll.mui
2009-08-24 04:15 23,576 a——- c:\windows\system32\wuaucpl.cpl.mui
2009-08-24 04:15 18,456 a——- c:\windows\system32\wuaueng.dll.mui
2009-08-24 04:15 –d—– c:\windows\system32\SoftwareDistribution
2009-08-23 03:23 –d–r– c:\program files\Skype
2009-08-23 02:20 –d—– c:\program files\Linksys Wireless-G USB Wireless Network Monitor
2009-08-23 01:38 21,504 a——- c:\windows\system32\hidserv.dll
2009-08-23 01:38 21,504 a——- c:\windows\system32\dllcache\hidserv.dll
2009-08-23 01:38 14,848 a——- c:\windows\system32\drivers\kbdhid.sys
2009-08-23 01:38 14,848 a——- c:\windows\system32\dllcache\kbdhid.sys
2009-08-23 01:38 12,160 a——- c:\windows\system32\drivers\mouhid.sys
2009-08-23 01:38 12,160 a——- c:\windows\system32\dllcache\mouhid.sys
2009-08-23 01:37 9,600 a——- c:\windows\system32\drivers\hidusb.sys
2009-08-23 01:37 9,600 a——- c:\windows\system32\dllcache\hidusb.sys
2009-08-23 01:37 31,616 a——- c:\windows\system32\drivers\usbccgp.sys
2009-08-23 01:37 31,616 a——- c:\windows\system32\dllcache\usbccgp.sys
==================== Find3M ====================
2009-09-08 11:38 182,912 a——- c:\windows\system32\drivers\ndis.sys
2009-09-08 11:38 182,912 a——- c:\windows\system32\dllcache\ndis.sys
2009-08-23 02:20 17,119 a——- c:\windows\system32\drivers\AegisP.sys
2009-08-23 01:55 3,645 a——- c:\windows\viassary-hp.reg
2005-11-21 07:56 32 a–sh— c:\windows\sminst\HPCD.SYS
2004-08-04 19:00 164,072 a–shr– c:\windows\system32\bokiybra.dll
============= FINISH: 0:31:13.01 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 1/25/2009 5:21:23 PM
System Uptime: 9/8/2009 10:46:59 PM (2 hours ago)
Motherboard: ASUSTek Computer INC. | | Salmon
Processor: AMD Athlon™ 64 Processor 3200+ | Socket 754 | 2210/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 106 GiB total, 98.194 GiB free.
D: is FIXED (FAT32) - 5 GiB total, 0.32 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: SiS 900-Based PCI Fast Ethernet Adapter
Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_2A04103C&REV_90\3&61AAA01&0&20
Manufacturer: SiS
Name: SiS 900-Based PCI Fast Ethernet Adapter
PNP Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_2A04103C&REV_90\3&61AAA01&0&20
Service: SISNIC
Class GUID: {4D36E96D-E325-11CE-BFC1-08002BE10318}
Description: Agere Systems PCI Soft Modem
Device ID: PCI\VEN_11C1&DEV_048C&SUBSYS_044C11C1&REV_03\3&61AAA01&0&50
Manufacturer: Agere
Name: Agere Systems PCI Soft Modem
PNP Device ID: PCI\VEN_11C1&DEV_048C&SUBSYS_044C11C1&REV_03\3&61AAA01&0&50
Service: Modem
Class GUID: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
Description: VIA OHCI Compliant IEEE 1394 Host Controller
Device ID: PCI\VEN_1106&DEV_3044&SUBSYS_2A04103C&REV_80\3&61AAA01&0&58
Manufacturer: VIA
Name: VIA OHCI Compliant IEEE 1394 Host Controller
PNP Device ID: PCI\VEN_1106&DEV_3044&SUBSYS_2A04103C&REV_80\3&61AAA01&0&58
Service: ohci1394
Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318}
Description: Communications Port
Device ID: ACPI\PNP0501\1
Manufacturer: (Standard port types)
Name: Communications Port (COM1)
PNP Device ID: ACPI\PNP0501\1
Service: Serial
Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318}
Description: ECP Printer Port
Device ID: ACPI\PNP0401\3&61AAA01&0
Manufacturer: (Standard port types)
Name: ECP Printer Port (LPT1)
PNP Device ID: ACPI\PNP0401\3&61AAA01&0
Service: Parport
==== System Restore Points ===================
RP1: 8/25/2009 2:14:06 PM - System Checkpoint
RP2: 8/26/2009 5:32:06 PM - System Checkpoint
RP3: 8/27/2009 10:03:35 PM - System Checkpoint
RP4: 8/29/2009 12:53:05 AM - System Checkpoint
RP5: 8/29/2009 9:28:29 AM - Removed SteornLab USB Hall Probe
RP6: 8/30/2009 9:51:47 AM - System Checkpoint
RP7: 8/31/2009 9:50:29 PM - System Checkpoint
RP8: 9/1/2009 10:28:57 PM - System Checkpoint
RP9: 9/2/2009 11:58:44 PM - System Checkpoint
RP10: 9/4/2009 12:23:46 AM - System Checkpoint
RP11: 9/6/2009 8:28:14 AM - Installed NI LabVIEW Run-Time Engine 6.1
RP12: 9/6/2009 8:45:07 AM - Removed HP Software Update
RP13: 9/7/2009 11:20:37 AM - System Checkpoint
RP14: 9/8/2009 2:42:07 AM - Installed Java™ 6 Update 16
==== Installed Programs ======================
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0.1
Agere Systems PCI Soft Modem
AiO_Scan
AiOSoftware
Bounce Symphony from Hewlett-Packard Desktops (remove only)
BufferChm
CameraDrivers
Canon ScanGear Toolbox CS 2.2
Copy
CP_AtenaShokunin1Config
cp_dwSharkTaleAlbums1
cp_dwSharkTaleCards1
cp_dwShrek2Albums1
cp_dwShrek2Cards1
CP_PLSBusinessFlyers
CreativeProjects
CreativeProjectsTemplates
CueTour
DeltaCad
Destinations
Director
DocProc
DocumentViewer
ERUNT 1.1j
Fax
Google Chrome
Google Talk Plugin
Help and Support Additions
Hotfix for Windows XP (KB915865)
HP Deskjet Preloaded Printer Drivers
HP Diagnostic Assistant
HP Image Zone 4.5.3
HP Image Zone Plus 4.5.3
HP Organize
HP Photosmart Cameras 4.0
HP PSC & OfficeJet 4.0
HP Update
HPIZplus450
HpSdpAppCoreApp
InstantShare
IntelliMover Data Transfer Demo
InterVideo DiscLabel
InterVideo WinDVD Creator
InterVideo WinDVD Player
IrfanView (remove only)
iWisoft Flash SWF to Video Converter 3.3
Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 16
KBD
Linksys Wireless-G USB Network Adapter
LTspice IV
Mathematica Player (M-WIN-D 7.0.1 1223367)
Microsoft .NET Framework 1.1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.5.2)
muvee autoProducer 3.5 magicMoments - HPD
NI LabVIEW Run-Time Engine 6.1
PanoStandAlone
PC-Doctor for Windows
PhotoGallery
PrintScreen
PS2
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
QFolder
QuickProjects
QuickTime
Readme
RealPlayer
Scan
Scope
Shrek 2 Ogre Bowler from Hewlett-Packard Desktops (remove only)
SiS VGA Utilities
SkinsHP1
Skype™ 4.1
Sonic Express Labeler
Sonic RecordNow!
Sothink SWF Catcher for Internet Explorer
Spybot - Search & Destroy
SteornLab USB Hall Probe
Tradewinds from Hewlett-Packard Desktops (remove only)
TrayApp
Unload
Updates from HP
Vizimag 3.18
WebFldrs XP
WebReg
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB890175
==== Event Viewer Messages From Past Week ========
9/8/2009 8:49:06 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82926da0, parameter3 82926f14, parameter4 805c749a.
9/8/2009 8:17:50 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828b7b88, parameter3 828b7cfc, parameter4 805c749a.
9/8/2009 7:45:28 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82909d78, parameter3 82909eec, parameter4 805c749a.
9/8/2009 7:14:06 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828efda0, parameter3 828eff14, parameter4 805c749a.
9/8/2009 6:41:41 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82aa2020, parameter3 82aa2194, parameter4 805c749a.
9/8/2009 6:10:19 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a2d128, parameter3 82a2d29c, parameter4 805c749a.
9/8/2009 5:37:58 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828c0318, parameter3 828c048c, parameter4 805c749a.
9/8/2009 5:06:36 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a83da0, parameter3 82a83f14, parameter4 805c749a.
9/8/2009 4:34:14 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828c3bb8, parameter3 828c3d2c, parameter4 805c749a.
9/8/2009 4:02:52 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 8291fda0, parameter3 8291ff14, parameter4 805c749a.
9/8/2009 3:30:28 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a9a740, parameter3 82a9a8b4, parameter4 805c749a.
9/8/2009 2:58:06 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 829c41c0, parameter3 829c4334, parameter4 805c749a.
9/8/2009 2:26:43 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a36938, parameter3 82a36aac, parameter4 805c749a.
9/8/2009 12:50:35 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82896180, parameter3 828962f4, parameter4 805c749a.
9/8/2009 12:23:51 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired.
9/8/2009 12:19:10 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82995b10, parameter3 82995c84, parameter4 805c749a.
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The WUSB54Gv4SVC service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 10:37:33 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
9/8/2009 10:22:10 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:21:49 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/8/2009 10:21:39 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
9/8/2009 1:54:18 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 8293dbe8, parameter3 8293dd5c, parameter4 805c749a.
9/8/2009 1:22:56 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 829864d8, parameter3 8298664c, parameter4 805c749a.
9/7/2009 12:08:43 AM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
9/7/2009 1:40:26 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.nist.gov,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
9/6/2009 9:18:02 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {F087771F-D74F-4C1A-BB8A-E16ACA9124EA}
9/6/2009 9:18:02 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {6D18AD12-BDE3-4393-B311-099C346E6DF9}
9/6/2009 8:33:16 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
9/6/2009 6:15:13 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
9/2/2009 8:23:28 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
9/2/2009 8:23:23 AM, error: Service Control Manager [7023] - The Support Helper service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
9/2/2009 8:23:23 AM, error: Service Control Manager [7023] - The Center Windows service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
==== End Of File ===========================
Above process running after boot. Easily stopped but fear rootkit is intact.
Wallpaper hacked to info-*.bmp. Easily removed.
I created new gmail account to access this forum on the off chance this will allow some protection.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/09 00:33
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB1C2D000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AED000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB0E5A000 Size: 49152 File Visible: No Signed: -
Status: -
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 0:30:48.85 on Wed 09/09/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.157 [GMT 1:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\sndvol32.exe
svchost
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\mspaint.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\My Documents\Downloads\MALWARE REMOVAL\dds.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
uWindow Title = Windows Internet Explorer provided by Yahoo!
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\hp_owner\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [AlcxMonitor] ALCXMNTR.EXE
mRun: [PS2] c:\windows\system32\ps2.exe
mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [19049684] c:\documents and settings\all users\application data\19049684\19049684.exe
mRun: [PromoReg] c:\windows\temp\_ex-08.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Bpepim] rundll32.exe "c:\windows\uragimog.dll",e
StartupFolder: c:\documents and settings\hp_owner\start menu\programs\startup\ikowin32.exe
StartupFolder: c:\documents and settings\hp_owner\start menu\programs\startup\sndvol32.exe
IE: Add To HP Organize… - c:\progra~1\hewlet~1\hporga~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251083586781
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
LSA: Notification Packages = scecli cpsmsrtx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\hp_owner\applic~1\mozilla\firefox\profiles\458k918k.default\
FF - plugin: c:\documents and settings\hp_owner\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\hp_owner\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPOJI610.dll
FF - HiddenExtension: XUL Cache: {0E245123-471F-4EF8-B8D6-A27722726D2F} - c:\documents and settings\hp_owner\local settings\application data\{0E245123-471F-4EF8-B8D6-A27722726D2F}
FF - HiddenExtension: XUL Cache: {9CEA2E74-9BE8-46A6-8C9C-768342A83B2C} - c:\documents and settings\administrator\local settings\application data\{9cea2e74-9be8-46a6-8c9c-768342a83b2c}\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
S2 bktici;Center Windows;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S2 jnjfrat;Support Helper;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
=============== Created Last 30 ================
2009-09-08 21:33 –d—– c:\program files\Spybot - Search & Destroy
2009-09-08 21:33 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-09-08 21:10 120 a——- c:\windows\Dkisad.dat
2009-09-08 11:41 –d—– c:\program files\WinPcap
2009-09-08 11:39 –d—– c:\docume~1\alluse~1\applic~1\19049684
2009-09-08 02:42 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-08 02:42 73,728 a——- c:\windows\system32\javacpl.cpl
2009-09-08 01:40 3,701 a——- c:\windows\scad3.INI
2009-09-07 06:54 –d—– c:\program files\LTC
2009-09-06 08:44 –d—– c:\docume~1\hp_owner\applic~1\WinBatch
2009-09-05 22:53 –d—– c:\docume~1\hp_owner\applic~1\MathematicaPlayer
2009-09-05 22:53 –d—– c:\docume~1\alluse~1\applic~1\MathematicaPlayer
2009-09-05 21:24 378,152 a——- c:\windows\system32\ml32i3.dll
2009-09-05 21:24 349,480 a——- c:\windows\system32\mltcpip32.mlp
2009-09-05 21:24 267,560 a——- c:\windows\system32\ml32i2.dll
2009-09-05 21:24 259,368 a——- c:\windows\system32\ml32i1.dll
2009-09-05 21:24 185,640 a——- c:\windows\system32\mlmodule32.dll
2009-09-05 21:24 107,816 a——- c:\windows\system32\mltcp32.mlp
2009-09-05 21:24 103,720 a——- c:\windows\system32\mlshm32.mlp
2009-09-05 21:24 95,528 a——- c:\windows\system32\mlmap32.mlp
2009-09-05 21:23 –d—– c:\program files\Wolfram Research
2009-09-01 00:45 –d—– C:\CM60S
2009-09-01 00:45 363,892 a——- c:\windows\ISUN16.EXE
2009-09-01 00:45 26,768 a——- c:\windows\system\CTL3D.DLL
2009-08-31 21:18 695,642 a——- c:\windows\unins000.exe
2009-08-31 21:18 14,981 a——- c:\windows\unins000.dat
2009-08-31 21:18 –d—– c:\program files\common files\SourceTec
2009-08-31 21:02 67 a——- c:\windows\swf2avi.INI
2009-08-31 21:02 758,018 a——- c:\windows\system32\xvidcore.dll
2009-08-31 21:02 180,224 a——- c:\windows\system32\xvidvfw.dll
2009-08-31 21:02 139,264 a——- c:\windows\system32\xvid.ax
2009-08-31 21:02 –d—– c:\program files\iWisoft Flash SWF to Video Converter
2009-08-30 20:10 –d—– c:\windows\system32\cvirte
2009-08-30 20:10 –d—– c:\program files\SteornLab
2009-08-29 20:52 –d—– c:\program files\Vizimag 3.18
2009-08-28 19:08 368,912 a——- c:\windows\system32\vbar332.dll
2009-08-28 19:08 3,572,224 a——- c:\windows\system32\crpe32.dll
2009-08-28 19:08 1,037,312 a——- c:\windows\system32\msjet35.dll
2009-08-28 19:08 251,664 a——- c:\windows\system32\msrd2x35.dll
2009-08-28 19:08 121,104 a——- c:\windows\system32\msjint35.dll
2009-08-28 19:08 24,336 a——- c:\windows\system32\msjter35.dll
2009-08-28 19:08 17,920 a——- c:\windows\system32\implode.dll
2009-08-28 19:08 416,768 a——- c:\windows\system32\cpeaut32.dll
2009-08-28 19:08 –d—– c:\program files\OrCAD_Demo
2009-08-28 11:27 4 a——- c:\windows\Worddict.xph
2009-08-28 11:27 4 a——- c:\windows\system32\Msxls.dnh
2009-08-28 11:27 –d—– c:\program files\DeltaCad
2009-08-28 10:44 32,397 a——- c:\windows\SGTBox.INI
2009-08-28 10:34 –d—– c:\program files\Canon
2009-08-28 10:33 –d—– c:\temp\ScanGearToolboxCSv223
2009-08-28 10:21 15,104 a——- c:\windows\system32\drivers\usbscan.sys
2009-08-28 10:21 15,104 a——- c:\windows\system32\dllcache\usbscan.sys
2009-08-28 10:17 –d—– c:\temp\CanoScan
2009-08-28 10:17 –d—– C:\Temp
2009-08-27 04:05 –d—– c:\program files\IrfanView
2009-08-25 13:54 –d—– c:\program files\Scope
2009-08-25 13:52 –d—– c:\program files\Scope_131
2009-08-24 04:23 –d—– c:\program files\National Instruments
2009-08-24 04:15 31,768 a——- c:\windows\system32\wucltui.dll.mui
2009-08-24 04:15 23,576 a——- c:\windows\system32\wuaucpl.cpl.mui
2009-08-24 04:15 18,456 a——- c:\windows\system32\wuaueng.dll.mui
2009-08-24 04:15 –d—– c:\windows\system32\SoftwareDistribution
2009-08-23 03:23 –d–r– c:\program files\Skype
2009-08-23 02:20 –d—– c:\program files\Linksys Wireless-G USB Wireless Network Monitor
2009-08-23 01:38 21,504 a——- c:\windows\system32\hidserv.dll
2009-08-23 01:38 21,504 a——- c:\windows\system32\dllcache\hidserv.dll
2009-08-23 01:38 14,848 a——- c:\windows\system32\drivers\kbdhid.sys
2009-08-23 01:38 14,848 a——- c:\windows\system32\dllcache\kbdhid.sys
2009-08-23 01:38 12,160 a——- c:\windows\system32\drivers\mouhid.sys
2009-08-23 01:38 12,160 a——- c:\windows\system32\dllcache\mouhid.sys
2009-08-23 01:37 9,600 a——- c:\windows\system32\drivers\hidusb.sys
2009-08-23 01:37 9,600 a——- c:\windows\system32\dllcache\hidusb.sys
2009-08-23 01:37 31,616 a——- c:\windows\system32\drivers\usbccgp.sys
2009-08-23 01:37 31,616 a——- c:\windows\system32\dllcache\usbccgp.sys
==================== Find3M ====================
2009-09-08 11:38 182,912 a——- c:\windows\system32\drivers\ndis.sys
2009-09-08 11:38 182,912 a——- c:\windows\system32\dllcache\ndis.sys
2009-08-23 02:20 17,119 a——- c:\windows\system32\drivers\AegisP.sys
2009-08-23 01:55 3,645 a——- c:\windows\viassary-hp.reg
2005-11-21 07:56 32 a–sh— c:\windows\sminst\HPCD.SYS
2004-08-04 19:00 164,072 a–shr– c:\windows\system32\bokiybra.dll
============= FINISH: 0:31:13.01 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 1/25/2009 5:21:23 PM
System Uptime: 9/8/2009 10:46:59 PM (2 hours ago)
Motherboard: ASUSTek Computer INC. | | Salmon
Processor: AMD Athlon™ 64 Processor 3200+ | Socket 754 | 2210/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 106 GiB total, 98.194 GiB free.
D: is FIXED (FAT32) - 5 GiB total, 0.32 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: SiS 900-Based PCI Fast Ethernet Adapter
Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_2A04103C&REV_90\3&61AAA01&0&20
Manufacturer: SiS
Name: SiS 900-Based PCI Fast Ethernet Adapter
PNP Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_2A04103C&REV_90\3&61AAA01&0&20
Service: SISNIC
Class GUID: {4D36E96D-E325-11CE-BFC1-08002BE10318}
Description: Agere Systems PCI Soft Modem
Device ID: PCI\VEN_11C1&DEV_048C&SUBSYS_044C11C1&REV_03\3&61AAA01&0&50
Manufacturer: Agere
Name: Agere Systems PCI Soft Modem
PNP Device ID: PCI\VEN_11C1&DEV_048C&SUBSYS_044C11C1&REV_03\3&61AAA01&0&50
Service: Modem
Class GUID: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
Description: VIA OHCI Compliant IEEE 1394 Host Controller
Device ID: PCI\VEN_1106&DEV_3044&SUBSYS_2A04103C&REV_80\3&61AAA01&0&58
Manufacturer: VIA
Name: VIA OHCI Compliant IEEE 1394 Host Controller
PNP Device ID: PCI\VEN_1106&DEV_3044&SUBSYS_2A04103C&REV_80\3&61AAA01&0&58
Service: ohci1394
Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318}
Description: Communications Port
Device ID: ACPI\PNP0501\1
Manufacturer: (Standard port types)
Name: Communications Port (COM1)
PNP Device ID: ACPI\PNP0501\1
Service: Serial
Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318}
Description: ECP Printer Port
Device ID: ACPI\PNP0401\3&61AAA01&0
Manufacturer: (Standard port types)
Name: ECP Printer Port (LPT1)
PNP Device ID: ACPI\PNP0401\3&61AAA01&0
Service: Parport
==== System Restore Points ===================
RP1: 8/25/2009 2:14:06 PM - System Checkpoint
RP2: 8/26/2009 5:32:06 PM - System Checkpoint
RP3: 8/27/2009 10:03:35 PM - System Checkpoint
RP4: 8/29/2009 12:53:05 AM - System Checkpoint
RP5: 8/29/2009 9:28:29 AM - Removed SteornLab USB Hall Probe
RP6: 8/30/2009 9:51:47 AM - System Checkpoint
RP7: 8/31/2009 9:50:29 PM - System Checkpoint
RP8: 9/1/2009 10:28:57 PM - System Checkpoint
RP9: 9/2/2009 11:58:44 PM - System Checkpoint
RP10: 9/4/2009 12:23:46 AM - System Checkpoint
RP11: 9/6/2009 8:28:14 AM - Installed NI LabVIEW Run-Time Engine 6.1
RP12: 9/6/2009 8:45:07 AM - Removed HP Software Update
RP13: 9/7/2009 11:20:37 AM - System Checkpoint
RP14: 9/8/2009 2:42:07 AM - Installed Java™ 6 Update 16
==== Installed Programs ======================
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0.1
Agere Systems PCI Soft Modem
AiO_Scan
AiOSoftware
Bounce Symphony from Hewlett-Packard Desktops (remove only)
BufferChm
CameraDrivers
Canon ScanGear Toolbox CS 2.2
Copy
CP_AtenaShokunin1Config
cp_dwSharkTaleAlbums1
cp_dwSharkTaleCards1
cp_dwShrek2Albums1
cp_dwShrek2Cards1
CP_PLSBusinessFlyers
CreativeProjects
CreativeProjectsTemplates
CueTour
DeltaCad
Destinations
Director
DocProc
DocumentViewer
ERUNT 1.1j
Fax
Google Chrome
Google Talk Plugin
Help and Support Additions
Hotfix for Windows XP (KB915865)
HP Deskjet Preloaded Printer Drivers
HP Diagnostic Assistant
HP Image Zone 4.5.3
HP Image Zone Plus 4.5.3
HP Organize
HP Photosmart Cameras 4.0
HP PSC & OfficeJet 4.0
HP Update
HPIZplus450
HpSdpAppCoreApp
InstantShare
IntelliMover Data Transfer Demo
InterVideo DiscLabel
InterVideo WinDVD Creator
InterVideo WinDVD Player
IrfanView (remove only)
iWisoft Flash SWF to Video Converter 3.3
Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 16
KBD
Linksys Wireless-G USB Network Adapter
LTspice IV
Mathematica Player (M-WIN-D 7.0.1 1223367)
Microsoft .NET Framework 1.1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.5.2)
muvee autoProducer 3.5 magicMoments - HPD
NI LabVIEW Run-Time Engine 6.1
PanoStandAlone
PC-Doctor for Windows
PhotoGallery
PrintScreen
PS2
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
QFolder
QuickProjects
QuickTime
Readme
RealPlayer
Scan
Scope
Shrek 2 Ogre Bowler from Hewlett-Packard Desktops (remove only)
SiS VGA Utilities
SkinsHP1
Skype™ 4.1
Sonic Express Labeler
Sonic RecordNow!
Sothink SWF Catcher for Internet Explorer
Spybot - Search & Destroy
SteornLab USB Hall Probe
Tradewinds from Hewlett-Packard Desktops (remove only)
TrayApp
Unload
Updates from HP
Vizimag 3.18
WebFldrs XP
WebReg
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB890175
==== Event Viewer Messages From Past Week ========
9/8/2009 8:49:06 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82926da0, parameter3 82926f14, parameter4 805c749a.
9/8/2009 8:17:50 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828b7b88, parameter3 828b7cfc, parameter4 805c749a.
9/8/2009 7:45:28 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82909d78, parameter3 82909eec, parameter4 805c749a.
9/8/2009 7:14:06 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828efda0, parameter3 828eff14, parameter4 805c749a.
9/8/2009 6:41:41 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82aa2020, parameter3 82aa2194, parameter4 805c749a.
9/8/2009 6:10:19 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a2d128, parameter3 82a2d29c, parameter4 805c749a.
9/8/2009 5:37:58 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828c0318, parameter3 828c048c, parameter4 805c749a.
9/8/2009 5:06:36 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a83da0, parameter3 82a83f14, parameter4 805c749a.
9/8/2009 4:34:14 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828c3bb8, parameter3 828c3d2c, parameter4 805c749a.
9/8/2009 4:02:52 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 8291fda0, parameter3 8291ff14, parameter4 805c749a.
9/8/2009 3:30:28 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a9a740, parameter3 82a9a8b4, parameter4 805c749a.
9/8/2009 2:58:06 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 829c41c0, parameter3 829c4334, parameter4 805c749a.
9/8/2009 2:26:43 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a36938, parameter3 82a36aac, parameter4 805c749a.
9/8/2009 12:50:35 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82896180, parameter3 828962f4, parameter4 805c749a.
9/8/2009 12:23:51 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired.
9/8/2009 12:19:10 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82995b10, parameter3 82995c84, parameter4 805c749a.
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The WUSB54Gv4SVC service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 10:37:33 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
9/8/2009 10:22:10 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:21:49 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/8/2009 10:21:39 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
9/8/2009 1:54:18 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 8293dbe8, parameter3 8293dd5c, parameter4 805c749a.
9/8/2009 1:22:56 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 829864d8, parameter3 8298664c, parameter4 805c749a.
9/7/2009 12:08:43 AM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
9/7/2009 1:40:26 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.nist.gov,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
9/6/2009 9:18:02 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {F087771F-D74F-4C1A-BB8A-E16ACA9124EA}
9/6/2009 9:18:02 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {6D18AD12-BDE3-4393-B311-099C346E6DF9}
9/6/2009 8:33:16 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
9/6/2009 6:15:13 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
9/2/2009 8:23:28 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
9/2/2009 8:23:23 AM, error: Service Control Manager [7023] - The Support Helper service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
9/2/2009 8:23:23 AM, error: Service Control Manager [7023] - The Center Windows service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
==== End Of File ===========================