Here is the ESET log…
C:\Qoobox\Quarantine\C\Documents and Settings\Jim\Local Settings\Application Data\{F97EE12E-07C1-4585-BCAF-69A0D3AE6E1C}\chrome\content\overlay.xul.vir probably a variant of Win32/Agent.NVQFFQI trojan
C:\Qoobox\Quarantine\C\Documents and Settings\teresa\Local Settings\Application Data\{635308F3-2EBD-411C-979E-FA8579460723}\chrome\content\overlay.xul.vir probably a variant of Win32/Agent.NVQFFQI trojan
C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\msimg32.dll.vir Win32/Toolbar.MyWebSearch application
C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\imapi.sys.vir Win32/Olmarik.ZC trojan
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224427.DLL Win32/Toolbar.MyWebSearch application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224428.DLL a variant of Win32/Toolbar.MyWebSearch.A application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224430.DLL a variant of Win32/Toolbar.MyWebSearch.B application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224431.DLL Win32/Toolbar.MyWebSearch application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224432.DLL Win32/Toolbar.MyWebSearch application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224438.DLL Win32/Toolbar.MyWebSearch application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224440.DLL Win32/Toolbar.MyWebSearch application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224441.DLL Win32/Toolbar.MyWebSearch application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224456.DLL Win32/Toolbar.MyWebSearch application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP253\A0224458.DLL Win32/Toolbar.MyWebSearch application
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP255\A0224524.dll a variant of Win32/Cimag.CK trojan
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP262\A0237802.sys Win32/Olmarik.ZC trojan
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP262\A0237874.dll Win32/Toolbar.MyWebSearch application
OTL.txt…
OTL logfile created on: 9/20/2010 8:45:40 PM - Run 2
OTL by OldTimer - Version 3.2.14.0 Folder = C:\Documents and Settings\teresa\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
502.00 Mb Total Physical Memory | 248.00 Mb Available Physical Memory | 49.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 57.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 61.80 Gb Total Space | 41.79 Gb Free Space | 67.63% Space Free | Partition Type: NTFS
Drive D: | 11.70 Gb Total Space | 1.19 Gb Free Space | 10.17% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-0CDC4F5844
Current User Name: teresa
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/09/19 19:23:25 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\teresa\Desktop\OTL.exe
PRC - [2010/09/13 22:40:39 | 002,065,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/09/13 22:40:37 | 000,515,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/09/13 22:40:36 | 000,620,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/09/13 22:40:33 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/09/13 22:40:29 | 000,916,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/09/13 22:40:29 | 000,722,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/09/13 22:40:28 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/05/09 16:11:10 | 000,176,128 | —- | M] (Starz Entertainment Group LLC) – C:\Program Files\Vongo\VongoService.exe
========== Modules (SafeList) ==========
MOD - [2010/09/19 19:23:25 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\teresa\Desktop\OTL.exe
MOD - [2008/04/13 19:10:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010/09/13 22:40:33 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/09/13 22:40:29 | 000,916,760 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2008/11/09 15:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Disabled | Stopped] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2006/06/12 15:27:28 | 000,126,976 | —- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe – (AddFiltr)
SRV - [2006/05/09 16:11:10 | 000,176,128 | —- | M] (Starz Entertainment Group LLC) [Auto | Running] – C:\Program Files\Vongo\VongoService.exe – (Vongo Service)
SRV - [2005/10/06 20:12:30 | 000,855,552 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Media Connect 2\wmccds.exe – (WMConnectCDS)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\DRIVERS\UIUSYS.SYS – (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\PalmUSBD.sys – (PalmUSBD)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\teresa\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2010/09/13 22:40:38 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/09/13 22:40:37 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2010/09/13 22:40:29 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/06/22 06:48:44 | 000,091,776 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mqac.sys – (MQAC)
DRV - [2009/05/09 01:14:20 | 000,014,736 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nuidfltr.sys – (NuidFltr)
DRV - [2008/05/08 09:02:52 | 000,203,136 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rmcast.sys – (RMCAST)
DRV - [2008/04/13 13:36:39 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 13:36:39 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2008/04/13 11:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2006/09/06 01:34:34 | 001,109,568 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\igxpmp32.sys – (ialm)
DRV - [2006/07/20 00:58:00 | 003,685,152 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2006/06/16 23:40:56 | 000,193,120 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2006/06/06 15:39:56 | 000,061,952 | —- | M] (Ricoh) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\5U870CAP.sys – (5U870CAP_VID_1262&PID;_25FD)
DRV - [2006/06/02 10:02:36 | 000,572,928 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CHDAud.sys – (HdAudAddService)
DRV - [2006/05/12 15:05:02 | 000,057,320 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btwusb.sys – (BTWUSB)
DRV - [2006/04/21 12:06:24 | 001,429,632 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\w39n51.sys – (w39n51) Intel®
DRV - [2006/04/20 11:03:20 | 000,995,712 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DPV.sys – (HSF_DPV)
DRV - [2006/04/20 11:02:40 | 000,208,000 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWAZL.sys – (HSFHWAZL)
DRV - [2006/04/20 11:02:36 | 000,727,296 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2006/04/11 06:07:48 | 000,179,200 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\e1e5132.sys – (e1express) Intel®
DRV - [2005/12/22 12:02:22 | 000,051,840 | —- | M] (REDC) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2005/11/16 15:28:32 | 000,028,928 | —- | M] (REDC) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2005/11/01 13:08:00 | 000,308,992 | —- | M] (REDC) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2005/10/13 04:07:12 | 000,874,240 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\iaStor.sys – (iaStor)
DRV - [2005/09/19 16:24:20 | 000,005,760 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\EabUsb.sys – (eabusb)
DRV - [2005/09/19 16:24:10 | 000,009,344 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CPQBttn.sys – (HBtnKey)
DRV - [2005/09/19 16:23:52 | 000,007,808 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\eabfiltr.sys – (eabfiltr)
DRV - [2004/08/04 01:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2001/08/18 00:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/18 00:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/18 00:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/18 00:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/18 00:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 23:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 23:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 23:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 23:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 23:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 23:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 23:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 23:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 23:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 23:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {F97EE12E-07C1-4585-BCAF-69A0D3AE6E1C}:1.9.1
FF - prefs.js..extensions.enabledItems: {635308F3-2EBD-411C-979E-FA8579460723}:1.9.1
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/05/23 21:38:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/09/13 22:42:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 16:33:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/01 21:19:56 | 000,000,000 | —D | M]
[2010/09/14 06:58:31 | 000,000,000 | —D | M] – C:\Documents and Settings\teresa\Application Data\Mozilla\Extensions
[2010/09/14 06:58:35 | 000,000,000 | —D | M] – C:\Documents and Settings\teresa\Application Data\Mozilla\Firefox\Profiles\f34uzvji.default\extensions
[2010/09/14 06:58:35 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\teresa\Application Data\Mozilla\Firefox\Profiles\f34uzvji.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/14 06:58:35 | 000,000,000 | —D | M] – C:\Documents and Settings\teresa\Application Data\Mozilla\Firefox\Profiles\f34uzvji.default\extensions\staged-xpis
[2010/04/01 21:19:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/09/18 20:55:02 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E}
https://kingsisle.hs.llnwd.net/e1/static/th…ameLauncher.CAB (Wizard101GameLauncher)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\teresa\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\teresa\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 22:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/09/20 18:32:14 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/09/19 19:26:24 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/09/19 19:25:29 | 000,000,000 | —D | C] – C:\_OTL
[2010/09/19 19:23:23 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\teresa\Desktop\OTL.exe
[2010/09/18 20:36:10 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/09/18 20:32:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/09/18 20:32:54 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/09/18 20:32:54 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/09/18 20:32:54 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/09/18 20:30:17 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/09/18 20:29:47 | 000,000,000 | —D | C] – C:\Qoobox
[2010/09/15 16:41:17 | 000,000,000 | —D | C] – C:\Documents and Settings\teresa\Desktop\gmer
[2010/09/14 17:31:15 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2010/09/14 15:35:50 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/09/14 15:35:30 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\teresa\Desktop\HJTInstall.exe
[2010/09/14 06:58:13 | 000,000,000 | —D | C] – C:\Documents and Settings\teresa\Local Settings\Application Data\Mozilla
[2010/09/14 06:58:12 | 000,000,000 | —D | C] – C:\Documents and Settings\teresa\Application Data\Mozilla
[2010/09/14 03:36:55 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/09/14 03:36:53 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/09/13 22:40:37 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/09/13 22:15:40 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/09/13 21:34:27 | 000,000,000 | —D | C] – C:\Program Files\CleanUp!
[2010/09/13 21:27:10 | 000,000,000 | —D | C] – C:\$AVG
[2010/09/13 21:26:10 | 000,242,896 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/09/13 21:25:52 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/09/13 21:25:51 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/09/13 21:25:38 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/09/13 21:25:12 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/09/13 21:25:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/09/13 21:01:50 | 000,000,000 | —D | C] – C:\Documents and Settings\teresa\Application Data\GTek
[2010/09/13 20:59:32 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\teresa\Desktop\ATF-Cleaner.exe
[2010/09/13 18:15:59 | 000,000,000 | —D | C] – C:\Documents and Settings\teresa\Application Data\Malwarebytes
[2010/09/13 15:22:51 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/13 15:22:49 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/13 15:22:49 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/13 15:22:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
========== Files - Modified Within 30 Days ==========
[2010/09/20 20:43:06 | 003,670,016 | -H– | M] () – C:\Documents and Settings\teresa\NTUSER.DAT
[2010/09/20 18:17:28 | 065,076,344 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/09/20 18:10:34 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/20 18:10:28 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/20 18:10:25 | 526,438,400 | -HS- | M] () – C:\hiberfil.sys
[2010/09/20 18:10:25 | 000,308,400 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/20 04:57:09 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/20 04:54:17 | 000,516,178 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/20 04:54:17 | 000,452,638 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/20 04:54:17 | 000,074,646 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/20 04:40:15 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\teresa\ntuser.ini
[2010/09/19 19:23:25 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\teresa\Desktop\OTL.exe
[2010/09/18 21:20:29 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/09/18 20:55:02 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/09/18 20:36:19 | 000,000,325 | RHS- | M] () – C:\boot.ini
[2010/09/18 20:31:50 | 003,846,590 | R— | M] () – C:\Documents and Settings\teresa\Desktop\ComboFix.exe
[2010/09/18 20:17:14 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/09/17 19:10:29 | 000,133,632 | —- | M] () – C:\Documents and Settings\teresa\Desktop\RKUnhookerLE.EXE
[2010/09/15 16:41:19 | 000,293,376 | —- | M] () – C:\Documents and Settings\teresa\Desktop\gmer.exe
[2010/09/15 16:39:35 | 000,284,915 | —- | M] () – C:\Documents and Settings\teresa\Desktop\gmer.zip
[2010/09/14 16:38:47 | 000,359,929 | —- | M] () – C:\Documents and Settings\teresa\Desktop\dds.scr
[2010/09/14 15:35:51 | 000,001,734 | —- | M] () – C:\Documents and Settings\teresa\Desktop\HijackThis.lnk
[2010/09/13 22:40:38 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/09/13 22:40:37 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/09/13 22:40:37 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/09/13 22:40:29 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/09/13 22:23:38 | 000,000,573 | —- | M] () – C:\WINDOWS\win.ini
[2010/09/13 22:23:38 | 000,000,209 | —- | M] () – C:\Boot.bak
[2010/09/13 22:14:09 | 000,001,489 | —- | M] () – C:\hpqp.ini
[2010/09/13 22:13:49 | 000,000,039 | —- | M] () – C:\XP_TV.ini
[2010/09/13 21:26:15 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/09/13 21:25:51 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/09/13 21:25:39 | 006,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/09/13 21:25:39 | 000,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/09/13 21:25:39 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/09/13 21:00:26 | 000,001,487 | —- | M] () – C:\Documents and Settings\teresa\Desktop\Windows Explorer.lnk
[2010/09/13 15:22:53 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/13 14:59:32 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
========== Files Created - No Company Name ==========
[2010/09/18 20:36:18 | 000,000,209 | —- | C] () – C:\Boot.bak
[2010/09/18 20:36:13 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/09/18 20:32:54 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/09/18 20:32:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/09/18 20:32:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/09/18 20:32:54 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/09/18 20:32:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/09/18 20:22:05 | 003,846,590 | R— | C] () – C:\Documents and Settings\teresa\Desktop\ComboFix.exe
[2010/09/17 19:10:29 | 000,133,632 | —- | C] () – C:\Documents and Settings\teresa\Desktop\RKUnhookerLE.EXE
[2010/09/16 20:42:14 | 526,438,400 | -HS- | C] () – C:\hiberfil.sys
[2010/09/15 21:21:28 | 000,293,376 | —- | C] () – C:\Documents and Settings\teresa\Desktop\gmer.exe
[2010/09/15 16:39:34 | 000,284,915 | —- | C] () – C:\Documents and Settings\teresa\Desktop\gmer.zip
[2010/09/14 16:38:47 | 000,359,929 | —- | C] () – C:\Documents and Settings\teresa\Desktop\dds.scr
[2010/09/14 15:35:51 | 000,001,734 | —- | C] () – C:\Documents and Settings\teresa\Desktop\HijackThis.lnk
[2010/09/14 06:54:53 | 000,001,487 | —- | C] () – C:\Documents and Settings\teresa\Desktop\Windows Explorer.lnk
[2010/09/13 21:26:15 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/09/13 21:25:50 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/09/13 21:25:39 | 065,076,344 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/09/13 21:25:39 | 000,492,629 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/09/13 21:25:39 | 000,142,495 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/09/13 21:25:38 | 006,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/09/13 15:22:53 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/27 00:25:02 | 000,000,173 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/11/09 14:04:13 | 000,021,504 | —- | C] () – C:\Documents and Settings\teresa\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/28 03:04:57 | 000,000,386 | —- | C] () – C:\Documents and Settings\teresa\Application Data\wklnhst.dat
[2009/08/23 17:30:32 | 000,000,129 | —- | C] () – C:\Documents and Settings\teresa\Local Settings\Application Data\fusioncache.dat
[2009/08/23 17:30:32 | 000,000,000 | —- | C] () – C:\Documents and Settings\teresa\Local Settings\Application Data\DSwitch.txt
[2009/08/23 17:30:32 | 000,000,000 | —- | C] () – C:\Documents and Settings\teresa\Local Settings\Application Data\AtStart.txt
[2009/08/23 17:30:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\teresa\Local Settings\Application Data\QSwitch.txt
[2008/05/17 23:26:31 | 000,000,116 | —- | C] () – C:\WINDOWS\FileNamesinQueue.ini
[2008/02/04 17:53:56 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2007/10/24 14:20:49 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2007/10/24 13:21:42 | 000,001,353 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/10/24 13:03:59 | 000,000,000 | —- | C] () – C:\WINDOWS\QUICKI~1.INI
[2007/10/03 13:46:12 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4670.dll
[2006/09/13 07:34:55 | 000,000,174 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/09/13 07:30:55 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/09/13 07:16:44 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/13 07:05:15 | 000,028,836 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/07/20 00:58:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/07/20 00:58:00 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/07/20 00:58:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/07/20 00:58:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/07/20 00:58:00 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/06/29 14:18:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/29 13:49:18 | 000,001,835 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/06/29 13:46:56 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/06/29 13:43:40 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/03/04 02:07:34 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/12/02 13:09:10 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/05/06 13:06:32 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2004/09/16 15:24:26 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2003/01/07 17:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== Alternate Data Streams ==========
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C22674B6
< End of report >
And Extras.txt…
OTL Extras logfile created on: 9/19/2010 7:33:30 PM - Run 1
OTL by OldTimer - Version 3.2.14.0 Folder = C:\Documents and Settings\teresa\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
502.00 Mb Total Physical Memory | 73.00 Mb Available Physical Memory | 14.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 61.80 Gb Total Space | 42.47 Gb Free Space | 68.73% Space Free | Partition Type: NTFS
Drive D: | 11.70 Gb Total Space | 1.19 Gb Free Space | 10.17% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-0CDC4F5844
Current User Name: teresa
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"" =
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"" =
"C:\Program Files\Vongo\VongoService.exe" = C:\Program Files\Vongo\VongoService.exe:*:enabled:VongoService – (Starz Entertainment Group LLC)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{09D8492A-C8E2-421E-927D-46800FB327A3}" = Wireless Home Network Setup
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1CB34CE9-0E6B-493F-BB66-3425E5DF76E5}" = CP_CalendarTemplates1
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2A548002-9042-4083-A270-B67473DE1073}" = SkinsHP1
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 A2
"{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}" = Unload
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{3819891A-030B-4a4e-98ED-B28A649E48AB}" = HP Deskjet 3900 series
"{3E8DD348-4174-4fe8-8FDC-238AAFBD2488}" = HP Photosmart All-In-One Driver Software 9.0.A Corporate Edition
"{3FE0CFAB-584A-4AA5-B8CD-C32284CFA308}" = RandMap
"{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{42F6BED9-41DD-40F1-85A8-8E0350493626}" = HPDeskjet3900Series
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 2.3
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{494D17B5-3369-4905-8C4B-80C972C5E0FF}" = CP_Panorama1Config
"{4DA4012B-39AF-48c2-B23B-A4D570D233A6}" = cp_LightScribeConfig
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{52FBAE98-D389-4281-8C14-21B4046CCB4E}" = SonicAC3Encoder
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54F0998F-73C8-4b51-8286-FE903C231BED}" = cp_PosterPrintConfig
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{766633B3-1AFA-44B6-A3FC-1DE991CD9C52}" = CP_Package_Basic1
"{79F8E1D4-36C1-439C-95FA-F695050B5B07}" = Sonic_PrimoSDK
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{80AE27BA-B0ED-4288-A8B9-D8194BCF4115}" = cp_UpdateProjectsConfig
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}" = Macromedia Shockwave Player
"{869C3062-4745-4949-B6C9-98AF24D89030}" = PhotoGallery
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{939F8208-C8CE-4AFF-B7BA-ACEB2E74A6CB}" =
"{9D4ABB0C-F60B-44A6-956C-A4A63D5495C9}" = CueTour
"{A03848C5-77D2-457a-8404-A1D5A769C87F}" = ps_aio_02_corporate
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A35C2323-3CEA-405C-9569-EF5DDE930B2F}" = PrintMaster
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{AF7733C1-FB0B-4FED-9730-E0433AF7A2EF}" = Magic Online
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B16AF568-A644-483C-A6DA-5028CD019C8C}" = SonicMPEGEncoder
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Update
"{BBD3BF67-5B89-4CBB-BA58-5818ED5F3290}" = cp_OnlineProjectsConfig
"{BDFE199D-E889-4BB6-BECB-C4BDF5700849}" = Documents To Go
"{BE247E71-C143-40BB-ADF2-A465DF062BAB}" = HP User Guides 0035
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2B676E6-FA49-48B9-A616-5FC5DD488006}" = W Photo Studio
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3161124-2B4D-478F-901A-D21BCAD72C7E}" = Addit
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DB7E00C9-6DEF-489A-8112-D8F81614F45A}" = Vongo
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EF0D2E55-6FE2-4e35-BE22-A742E85D84E3}" = PS_AIO_02_Software_min
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{FB09F05F-85C6-4205-B28D-5BF071D276C3}" = muvee autoProducer 5.0
"{FC8D25A7-FF1B-41BB-BB3B-9A06C0A60AE0}" = InstantShareDevices
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AVG9Uninstall" = AVG Free 9.0
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"BFGC" = Big Fish Games Client
"BFG-Mystery Case Files - Return to Ravenhearst" = Mystery Case Files: Return to Ravenhearst ™
"CleanUp!" = CleanUp!
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_PCI_VEN_14F1&DEV;_5045_at8ven5m" = Soft Data Fax Modem with SmartCP
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 6.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.0
"HP Rhapsody" = HP Rhapsody
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"LimeWire" = LimeWire 4.18.8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2006b" = Microsoft Money 2006
"Mozilla Firefox (3.6.2)" = Mozilla Firefox (3.6.2)
"Mystery P.I. - Lost in Los Angeles" = Mystery P.I. - Lost in Los Angeles (remove only)
"Mystery P.I. - The Vegas Heist" = Mystery P.I. - The Vegas Heist (remove only)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Connections Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"Shockwave" = Shockwave
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebPost" = Microsoft Web Publishing Wizard 1.52
"WGA" = Windows Genuine Advantage Validation Tool
"WildTangent CDA" = WildTangent Web Driver
"WildTangent hplaptop Master Uninstall" = My HP Games
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"WT015792" = FATE
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager
"Zombie Bowl-O-Rama" = Zombie Bowl-O-Rama (remove only)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/14/2010 3:44:04 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 9/14/2010 6:05:29 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 9/14/2010 6:05:29 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 9/14/2010 6:05:35 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 9/14/2010 6:05:35 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 9/14/2010 6:05:35 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 9/17/2010 10:28:02 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 9/17/2010 10:28:02 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 9/18/2010 7:22:00 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 9/18/2010 7:22:01 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
[ Application Events ]
Error - 9/14/2010 3:44:04 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 9/14/2010 6:05:29 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 9/14/2010 6:05:29 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 9/14/2010 6:05:35 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 9/14/2010 6:05:35 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 9/14/2010 6:05:35 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 9/17/2010 10:28:02 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 9/17/2010 10:28:02 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 9/18/2010 7:22:00 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 9/18/2010 7:22:01 PM | Computer Name = YOUR-0CDC4F5844 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
[ System Events ]
Error - 9/18/2010 10:05:25 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126
Error - 9/18/2010 10:05:44 PM | Computer Name = YOUR-0CDC4F5844 | Source = System Error | ID = 1003
Description = Error code 1000000a, parameter1 ff8c7cc4, parameter2 0000001c, parameter3
00000001, parameter4 80502cd8.
Error - 9/19/2010 8:01:05 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126
Error - 9/19/2010 8:25:33 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7031
Description = The AVG Free WatchDog service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.
Error - 9/19/2010 8:25:34 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).
Error - 9/19/2010 8:25:34 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7034
Description = The LightScribeService Direct Disc Labeling Service service terminated
unexpectedly. It has done this 1 time(s).
Error - 9/19/2010 8:25:34 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7034
Description = The Vongo Service service terminated unexpectedly. It has done this
1 time(s).
Error - 9/19/2010 8:25:35 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7034
Description = The AVG Free E-mail Scanner service terminated unexpectedly. It has
done this 1 time(s).
Error - 9/19/2010 8:25:36 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7034
Description = The hpqwmiex service terminated unexpectedly. It has done this 1
time(s).
Error - 9/19/2010 8:30:11 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126
< End of report >