Tried to upload to both sites the file kerigexe.dll but VirusTotal did'n say anything and jotti replied that the file was empty (0 bytes) even though in the windows folder it has 808Kb
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8242
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
11/29/2011 2:57:10 PM
mbam-log-2011-11-29 (14-57-10).txt
Scan type: Quick scan
Objects scanned: 393901
Time elapsed: 6 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
******************************************************
aswMBR version 0.9.8.986 Copyrightยฉ 2011 AVAST Software
Run date: 2011-11-29 15:00:26
โโโโโโโโโโ
15:00:26.481 OS Version: Windows 5.1.2600 Service Pack 3
15:00:26.481 Number of processors: 2 586 0x170A
15:00:26.481 ComputerName: SQ1-PC-053 UserName:
15:00:28.231 Initialize success
15:00:33.184 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:00:33.184 Disk 0 Vendor: ST325031 CC45 Size: 238418MB BusType: 3
15:00:33.200 Disk 0 MBR read successfully
15:00:33.215 Disk 0 MBR scan
15:00:33.215 Disk 0 Windows VISTA default MBR code
15:00:33.215 Disk 0 scanning sectors +488263545
15:00:33.294 Disk 0 scanning C:\WINDOWS\system32\drivers
15:00:40.934 Service scanning
15:00:41.090 Service ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys **LOCKED** 32
15:00:41.168 Service MpKsla4227d17 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9980B518-1C69-4A40-BF13-17C04CFD6695}\MpKsla4227d17.sys **LOCKED** 32
15:00:41.762 Modules scanning
15:00:45.309 Disk 0 trace - called modules:
15:00:45.324 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys >>UNKNOWN [0x8ad51409]<<
15:00:45.324 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8acceab8]
15:00:45.340 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8ad29028]
15:00:45.340 Scan finished successfully
15:01:04.245 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\administrator.BTE\Desktop\MBR.dat"
15:01:04.245 The log file has been saved successfully to "C:\Documents and Settings\administrator.BTE\Desktop\aswMBR.txt"
OTL logfile created on: 11/29/2011 3:02:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\administrator.BTE\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.20 Gb Available Physical Memory | 73.38% Memory free
4.84 Gb Paging File | 4.11 Gb Available in Paging File | 84.94% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.78 Gb Total Space | 193.71 Gb Free Space | 83.22% Space Free | Partition Type: NTFS
Computer Name: SQ1-PC-053 | User Name: administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\administrator.BTE\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ()
MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.FRA ()
MOD - C:\WINDOWS\system32\BiImg.dll ()
========== Win32 Services (SafeList) ==========
SRV - (LMIMaint) โ C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) โ C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (MsMpSvc) โ c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) โ C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (LogMeIn) โ C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (tmproxy) โ C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (TmPfw) โ C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV - (SfCtlCom) โ C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (IAANTMON) Intelยฎ โ C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (TMBMServer) โ C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
========== Driver Services (SafeList) ==========
DRV - (MpKsla4227d17) โ c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9980B518-1C69-4A40-BF13-17C04CFD6695}\MpKsla4227d17.sys (Microsoft Corporation)
DRV - (LMIRfsClientNP) โ C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver) โ C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) โ C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (tmxpflt) โ C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) โ C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) โ C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (NVHDA) โ C:\WINDOWS\system32\drivers\nvhda32.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) โ C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (tmcomm) โ C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmactmon) โ C:\WINDOWS\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) โ C:\WINDOWS\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmcfw) โ C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) โ C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (RTLE8023xp) โ C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (RTLVLAN) โ C:\WINDOWS\system32\drivers\RTLVLAN.SYS (Realtek Semiconductor Corporation )
DRV - (RTLTEAMING) โ C:\WINDOWS\system32\drivers\RTLTEAMING.SYS (Realtek Semiconductor Corporation)
DRV - (Ambfilt) โ C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (RtNdPt5x) โ C:\WINDOWS\system32\drivers\RtNdPt5x.sys (Realtek Semiconductor Corporation )
DRV - (ACPI) โ C:\WINDOWS\system32\DRIVERS\ACPI.sys ()
DRV - (Monfilt) โ C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL =
http://g.msn.com/USSMB/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page =
http://g.msn.com/USSMB/1
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/USSMB/1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/USSMB/1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1957994488-2111687655-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/USSMB/1
IE - HKU\S-1-5-21-1957994488-2111687655-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2011/11/29 10:43:23 | 000,000,027 | โ- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\RunOnce: [DBRMTray] C:\dell\DBRM\Reminder\TrayApp.exe (Microsoft)
O4 - Startup: C:\Documents and Settings\khughes\Start Menu\Programs\Startup\Fonality HUD.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1957994488-2111687655-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.7.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = BTE.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C9E4DA4-71FF-4660-8D88-FB5BFF04DFD4}: DhcpNameServer = 192.168.7.2
O20 - AppInit_DLLs: (C:\WINDOWS\system32\acaptuser32.dll) -C:\WINDOWS\system32\acaptuser32.dll (Adobe Systems Incorporated)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O21 - SSODL: Miduclib - {8F7544C6-B2E9-45B6-B7F6-4A99B0D21A76} - C:\WINDOWS\system32\kerigexe.dll File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 16:29:32 | 000,000,000 | โ- | M] () - C:\AUTOEXEC.BAT โ [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] โ "%1" %*
O35 - HKLM\..exefile [open] โ "%1" %*
O37 - HKLM\โฆcom [@ = ComFile] โ "%1" %*
O37 - HKLM\โฆexe [@ = exefile] โ "%1" %*
========== Files/Folders - Created Within 30 Days ==========
File not found โ C:\WINDOWS\System32\urlonlib.dll
File not found โ C:\WINDOWS\System32\maculext.dll
File not found โ C:\WINDOWS\System32\kerigexe.dll
File not found โ C:\WINDOWS\System32\bmpuvzip.dll
File not found โ C:\WINDOWS\System32\anselbio.dll
File not found โ C:\WINDOWS\System32\adipdir32.dll
[2011/11/29 15:00:13 | 000,584,192 | โ- | C] (OldTimer Tools) โ C:\Documents and Settings\administrator.BTE\Desktop\OTL.exe
[2011/11/29 14:59:36 | 001,916,416 | โ- | C] (AVAST Software) โ C:\Documents and Settings\administrator.BTE\Desktop\aswMBR.exe
[2011/11/29 14:59:36 | 000,607,260 | Rโ | C] (Swearware) โ C:\Documents and Settings\administrator.BTE\Desktop\dds.scr
[2011/11/29 11:15:15 | 000,000,000 | -HSD | C] โ C:\RECYCLER
[2011/11/29 10:31:24 | 000,000,000 | RโD | C] โ C:\Documents and Settings\administrator.BTE\Start Menu\Programs\Administrative Tools
[2011/11/29 10:30:47 | 004,321,290 | Rโ | C] (Swearware) โ C:\Documents and Settings\administrator.BTE\Desktop\ComboFix.exe
[2011/11/29 10:28:45 | 000,000,000 | โD | C] โ C:\WINDOWS\Minidump
[2011/11/29 10:23:22 | 000,000,000 | RHSD | C] โ C:\cmdcons
[2011/11/29 10:20:38 | 000,518,144 | โ- | C] (SteelWerX) โ C:\WINDOWS\SWREG.exe
[2011/11/29 10:20:38 | 000,406,528 | โ- | C] (SteelWerX) โ C:\WINDOWS\SWSC.exe
[2011/11/29 10:20:38 | 000,212,480 | โ- | C] (SteelWerX) โ C:\WINDOWS\SWXCACLS.exe
[2011/11/29 10:20:38 | 000,060,416 | โ- | C] (NirSoft) โ C:\WINDOWS\NIRCMD.exe
[2011/11/29 10:20:31 | 000,000,000 | โD | C] โ C:\WINDOWS\ERDNT
[2011/11/29 10:20:00 | 000,000,000 | โD | C] โ C:\Qoobox
[2011/11/25 17:56:40 | 000,222,080 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\MpSigStub.exe
[2011/11/25 17:52:12 | 000,000,000 | โD | C] โ C:\Program Files\Microsoft Security Client
[2011/11/25 17:30:06 | 000,000,000 | โD | C] โ C:\Documents and Settings\administrator.BTE\Application Data\Malwarebytes
[2011/11/25 17:30:03 | 000,000,000 | โD | C] โ C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/25 17:30:03 | 000,000,000 | โD | C] โ C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/11/25 17:30:00 | 000,022,216 | โ- | C] (Malwarebytes Corporation) โ C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/25 17:30:00 | 000,000,000 | โD | C] โ C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/25 17:29:47 | 009,852,544 | โ- | C] (Malwarebytes Corporation ) โ C:\Documents and Settings\administrator.BTE\My Documents\mbam-setup-1.51.2.1300.exe
[2011/11/25 17:26:52 | 000,000,000 | โD | C] โ C:\Documents and Settings\administrator.BTE\Tracing
[2011/11/25 17:25:02 | 000,000,000 | -HSD | C] โ C:\Documents and Settings\administrator.BTE\IECompatCache
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
File not found โ C:\WINDOWS\System32\urlonlib.dll
File not found โ C:\WINDOWS\System32\maculext.dll
File not found โ C:\WINDOWS\System32\kerigexe.dll
File not found โ C:\WINDOWS\System32\bmpuvzip.dll
File not found โ C:\WINDOWS\System32\anselbio.dll
File not found โ C:\WINDOWS\System32\adipdir32.dll
[2011/11/29 15:01:04 | 000,000,512 | โ- | M] () โ C:\Documents and Settings\administrator.BTE\Desktop\MBR.dat
[2011/11/29 15:00:15 | 000,584,192 | โ- | M] (OldTimer Tools) โ C:\Documents and Settings\administrator.BTE\Desktop\OTL.exe
[2011/11/29 14:53:00 | 000,000,986 | โ- | M] () โ C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-2111687655-839522115-3098UA.job
[2011/11/29 14:51:29 | 000,000,424 | -Hโ | M] () โ C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/11/29 14:47:12 | 000,253,708 | โ- | M] () โ C:\WINDOWS\System32\NvApps.xml
[2011/11/29 14:47:06 | 000,001,158 | โ- | M] () โ C:\WINDOWS\System32\wpa.dbl
[2011/11/29 14:46:26 | 000,002,048 | โS- | M] () โ C:\WINDOWS\bootstat.dat
[2011/11/29 14:46:22 | 3220,160,512 | -HS- | M] () โ C:\hiberfil.sys
[2011/11/29 14:45:00 | 000,000,327 | RHS- | M] () โ C:\boot.ini
[2011/11/29 14:28:01 | 000,000,036 | โ- | M] () โ C:\WINDOWS\iltwain.ini
[2011/11/29 10:43:23 | 000,000,027 | โ- | M] () โ C:\WINDOWS\System32\drivers\etc\hosts
[2011/11/29 10:13:42 | 004,321,290 | Rโ | M] (Swearware) โ C:\Documents and Settings\administrator.BTE\Desktop\ComboFix.exe
[2011/11/29 08:56:45 | 001,916,416 | โ- | M] (AVAST Software) โ C:\Documents and Settings\administrator.BTE\Desktop\aswMBR.exe
[2011/11/28 16:06:54 | 000,013,334 | โ- | M] () โ C:\WINDOWS\setscan.ini
[2011/11/28 16:04:24 | 000,000,211 | โ- | M] () โ C:\Boot.bak
[2011/11/28 15:27:35 | 000,607,260 | Rโ | M] (Swearware) โ C:\Documents and Settings\administrator.BTE\Desktop\dds.scr
[2011/11/25 17:52:28 | 000,001,945 | โ- | M] () โ C:\WINDOWS\epplauncher.mif
[2011/11/25 17:30:04 | 000,000,786 | โ- | M] () โ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/25 17:29:51 | 009,852,544 | โ- | M] (Malwarebytes Corporation ) โ C:\Documents and Settings\administrator.BTE\My Documents\mbam-setup-1.51.2.1300.exe
[2011/11/25 05:53:00 | 000,000,934 | โ- | M] () โ C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-2111687655-839522115-3098Core.job
[2011/11/23 18:26:00 | 000,000,284 | โ- | M] () โ C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/22 11:25:03 | 000,466,796 | โ- | M] () โ C:\WINDOWS\System32\perfh009.dat
[2011/11/22 11:25:03 | 000,079,886 | โ- | M] () โ C:\WINDOWS\System32\perfc009.dat
[2011/11/16 09:10:02 | 000,414,368 | โ- | M] (Adobe Systems Incorporated) โ C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/29 15:01:04 | 000,000,512 | โ- | C] () โ C:\Documents and Settings\administrator.BTE\Desktop\MBR.dat
[2011/11/29 10:23:25 | 000,000,211 | โ- | C] () โ C:\Boot.bak
[2011/11/29 10:23:23 | 000,260,272 | RHS- | C] () โ C:\cmldr
[2011/11/29 10:20:38 | 000,256,000 | โ- | C] () โ C:\WINDOWS\PEV.exe
[2011/11/29 10:20:38 | 000,208,896 | โ- | C] () โ C:\WINDOWS\MBR.exe
[2011/11/29 10:20:38 | 000,098,816 | โ- | C] () โ C:\WINDOWS\sed.exe
[2011/11/29 10:20:38 | 000,080,412 | โ- | C] () โ C:\WINDOWS\grep.exe
[2011/11/29 10:20:38 | 000,068,096 | โ- | C] () โ C:\WINDOWS\zip.exe
[2011/11/28 16:00:53 | 3220,160,512 | -HS- | C] () โ C:\hiberfil.sys
[2011/11/25 17:57:24 | 000,000,424 | -Hโ | C] () โ C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/11/25 17:52:28 | 000,001,945 | โ- | C] () โ C:\WINDOWS\epplauncher.mif
[2011/11/25 17:52:17 | 000,001,682 | โ- | C] () โ C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/11/25 17:30:04 | 000,000,786 | โ- | C] () โ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/01 13:12:16 | 000,167,072 | โ- | C] () โ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/06/17 16:21:15 | 000,000,033 | โ- | C] () โ C:\WINDOWS\BiMonitor.ini
[2011/06/17 16:21:14 | 000,030,846 | โ- | C] () โ C:\WINDOWS\maxlink.ini
[2011/06/17 16:14:38 | 000,013,334 | โ- | C] () โ C:\WINDOWS\setscan.ini
[2011/04/11 10:32:58 | 000,000,056 | โ- | C] () โ C:\WINDOWS\Addrfixr.ini
[2011/04/11 10:32:58 | 000,000,036 | โ- | C] () โ C:\WINDOWS\iltwain.ini
[2011/04/11 10:32:57 | 000,009,391 | โ- | C] () โ C:\WINDOWS\System32\dymourl.ini
[2011/04/11 10:32:34 | 000,061,440 | โ- | C] () โ C:\WINDOWS\System32\DYMOCFG.DLL
[2011/04/11 10:32:33 | 000,004,096 | โ- | C] () โ C:\WINDOWS\System32\lmmonres.dll
[2011/01/28 08:06:49 | 000,119,808 | โ- | C] () โ C:\WINDOWS\System32\cfgagmap.dll
[2011/01/11 17:05:18 | 000,008,592 | โ- | C] () โ C:\WINDOWS\System32\ractrlkeyhook.dll
[2010/08/24 09:40:34 | 000,123,135 | โ- | C] () โ C:\WINDOWS\HPHins12.dat.temp
[2010/08/24 09:40:34 | 000,014,916 | โ- | C] () โ C:\WINDOWS\hphmdl12.dat.temp
[2010/08/24 09:37:01 | 000,122,810 | โ- | C] () โ C:\WINDOWS\HPHins12.dat
[2010/08/24 09:37:01 | 000,014,916 | โ- | C] () โ C:\WINDOWS\hphmdl12.dat
[2010/08/24 09:36:57 | 000,077,824 | โ- | C] () โ C:\WINDOWS\System32\hpzids01.dll
[2010/02/26 21:25:56 | 001,604,482 | โ- | C] () โ C:\WINDOWS\System32\nvdata.bin
[2010/02/26 21:25:41 | 000,073,728 | โ- | C] () โ C:\WINDOWS\System32\RtNicProp32.dll
[2010/02/26 21:25:39 | 002,026,604 | โ- | C] () โ C:\WINDOWS\System32\igkrng500.bin
[2010/02/26 21:25:39 | 000,442,964 | โ- | C] () โ C:\WINDOWS\System32\igcompkrng500.bin
[2010/02/26 21:25:39 | 000,147,456 | โ- | C] () โ C:\WINDOWS\System32\igfxCoIn_v4977.dll
[2010/02/26 21:25:31 | 000,077,824 | โ- | C] () โ C:\WINDOWS\setpwr32.exe
[2010/02/26 21:19:19 | 000,001,152 | โ- | C] () โ C:\WINDOWS\System32\OEMINFO.INI
[2010/02/26 19:43:39 | 000,000,061 | โ- | C] () โ C:\WINDOWS\smscfg.ini
[2008/05/26 22:59:42 | 000,018,904 | โ- | C] () โ C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 22:59:40 | 000,106,605 | โ- | C] () โ C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/25 16:31:41 | 000,002,048 | โS- | C] () โ C:\WINDOWS\bootstat.dat
[2008/04/25 16:27:18 | 000,021,640 | โ- | C] () โ C:\WINDOWS\System32\emptyregdb.dat
[2008/04/25 16:26:32 | 000,001,793 | โ- | C] () โ C:\WINDOWS\System32\fxsperf.ini
[2008/04/25 11:16:24 | 000,004,569 | โ- | C] () โ C:\WINDOWS\System32\secupd.dat
[2008/04/25 11:16:22 | 000,466,796 | โ- | C] () โ C:\WINDOWS\System32\perfh009.dat
[2008/04/25 11:16:22 | 000,272,128 | โ- | C] () โ C:\WINDOWS\System32\perfi009.dat
[2008/04/25 11:16:22 | 000,079,886 | โ- | C] () โ C:\WINDOWS\System32\perfc009.dat
[2008/04/25 11:16:22 | 000,028,626 | โ- | C] () โ C:\WINDOWS\System32\perfd009.dat
[2008/04/25 11:16:22 | 000,004,627 | โ- | C] () โ C:\WINDOWS\System32\oembios.dat
[2008/04/25 11:16:21 | 013,107,200 | โ- | C] () โ C:\WINDOWS\System32\oembios.bin
[2008/04/25 11:16:20 | 000,000,741 | โ- | C] () โ C:\WINDOWS\System32\noise.dat
[2008/04/25 11:16:18 | 000,673,088 | โ- | C] () โ C:\WINDOWS\System32\mlang.dat
[2008/04/25 11:16:18 | 000,046,258 | โ- | C] () โ C:\WINDOWS\System32\mib.bin
[2008/04/25 11:16:13 | 000,218,003 | โ- | C] () โ C:\WINDOWS\System32\dssec.dat
[2008/04/25 11:16:11 | 000,001,804 | โ- | C] () โ C:\WINDOWS\System32\Dcache.bin
[2008/04/25 04:22:39 | 000,004,161 | โ- | C] () โ C:\WINDOWS\ODBCINST.INI
[2008/04/25 04:21:52 | 000,278,152 | โ- | C] () โ C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/13 19:06:36 | 000,187,776 | โ- | C] () โ C:\WINDOWS\System32\drivers\acpi.sys
[2007/09/27 11:51:02 | 000,020,698 | โ- | C] () โ C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | โ- | C] () โ C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | โ- | C] () โ C:\WINDOWS\System32\gthrctr.ini
[2005/09/07 11:00:44 | 000,257,536 | โ- | C] () โ C:\WINDOWS\System32\BiImg.dll
[2005/09/07 11:00:44 | 000,110,592 | โ- | C] () โ C:\WINDOWS\System32\JPEG32.DLL
========== LOP Check ==========
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\aacosta\Application Data\Windows Desktop Search
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\administrator.BTE\Application Data\Windows Desktop Search
[2011/04/08 09:49:08 | 000,000,000 | โD | M] โ C:\Documents and Settings\administrator.BTE\Application Data\Windows Search
[2011/11/29 09:08:08 | 000,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/06/20 10:59:59 | 000,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/08/01 11:58:58 | 000,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\Winprint HylaFAX Reloaded
[2011/06/17 16:22:11 | 000,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\zeon
[2009/08/21 16:35:17 | 000,000,000 | โD | M] โ C:\Documents and Settings\cvasquez\Application Data\ICCO
[2010/04/09 08:04:18 | 000,000,000 | โD | M] โ C:\Documents and Settings\cvasquez\Application Data\Windows Desktop Search
[2010/04/08 15:50:49 | 000,000,000 | โD | M] โ C:\Documents and Settings\cvasquez\Application Data\Windows Search
[2010/09/17 13:39:42 | 000,000,000 | โD | M] โ C:\Documents and Settings\ddezmal\Application Data\Downloaded Installations
[2010/06/08 15:25:40 | 000,000,000 | โD | M] โ C:\Documents and Settings\ddezmal\Application Data\ICCO
[2011/04/06 14:27:50 | 000,000,000 | โD | M] โ C:\Documents and Settings\ddezmal\Application Data\Nitro PDF
[2010/03/26 00:11:17 | 000,000,000 | โD | M] โ C:\Documents and Settings\ddezmal\Application Data\Windows Desktop Search
[2010/08/10 11:25:16 | 000,000,000 | โD | M] โ C:\Documents and Settings\ddezmal\Application Data\Windows Search
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\Default User\Application Data\Windows Desktop Search
[2010/04/07 10:28:07 | 000,000,000 | โD | M] โ C:\Documents and Settings\jabreu\Application Data\ICCO
[2010/06/29 13:41:19 | 000,000,000 | โD | M] โ C:\Documents and Settings\jabreu\Application Data\Windows Desktop Search
[2010/06/30 10:41:46 | 000,000,000 | โD | M] โ C:\Documents and Settings\jabreu\Application Data\Windows Search
[2010/04/07 10:28:07 | 000,000,000 | โD | M] โ C:\Documents and Settings\jabreu_old\Application Data\ICCO
[2010/06/29 13:41:19 | 000,000,000 | โD | M] โ C:\Documents and Settings\jabreu_old\Application Data\Windows Desktop Search
[2010/06/30 10:41:46 | 000,000,000 | โD | M] โ C:\Documents and Settings\jabreu_old\Application Data\Windows Search
[2011/04/04 08:26:02 | 000,000,000 | โD | M] โ C:\Documents and Settings\jlattimore\Application Data\ICCO
[2011/04/04 12:20:08 | 000,000,000 | โD | M] โ C:\Documents and Settings\jlattimore\Application Data\ISIS Drivers
[2011/07/28 12:09:06 | 000,000,000 | โD | M] โ C:\Documents and Settings\jlattimore\Application Data\Nitro PDF
[2011/04/04 12:19:48 | 000,000,000 | โD | M] โ C:\Documents and Settings\jlattimore\Application Data\ScanSoft
[2011/07/21 07:44:35 | 000,000,000 | โD | M] โ C:\Documents and Settings\jlattimore\Application Data\Windows Search
[2010/12/14 16:21:38 | 000,000,000 | โD | M] โ C:\Documents and Settings\keithh\Application Data\ICCO
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\keithh\Application Data\Windows Desktop Search
[2010/12/16 09:14:37 | 000,000,000 | โD | M] โ C:\Documents and Settings\keithh\Application Data\Windows Search
[2010/04/07 11:19:31 | 000,000,000 | โD | M] โ C:\Documents and Settings\khughes\Application Data\ICCO
[2010/04/07 11:27:06 | 000,000,000 | โD | M] โ C:\Documents and Settings\khughes\Application Data\Windows Search
[2010/04/13 08:41:41 | 000,000,000 | โD | M] โ C:\Documents and Settings\mlehrer\Application Data\ICCO
[2010/04/14 08:03:10 | 000,000,000 | โD | M] โ C:\Documents and Settings\mlehrer\Application Data\Windows Desktop Search
[2010/04/13 09:43:25 | 000,000,000 | โD | M] โ C:\Documents and Settings\mlehrer\Application Data\Windows Search
[2010/06/07 14:50:11 | 000,000,000 | โD | M] โ C:\Documents and Settings\rschwartz\Application Data\ICCO
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\rschwartz\Application Data\Windows Desktop Search
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\rundreiner\Application Data\Windows Desktop Search
[2011/04/08 16:54:03 | 000,000,000 | โD | M] โ C:\Documents and Settings\sphanor\Application Data\ICCO
[2011/06/20 08:36:32 | 000,000,000 | โD | M] โ C:\Documents and Settings\sphanor\Application Data\ScanSoft
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\sphanor\Application Data\Windows Desktop Search
[2011/04/11 11:20:55 | 000,000,000 | โD | M] โ C:\Documents and Settings\sphanor\Application Data\Windows Search
[2011/08/01 11:58:35 | 000,000,000 | โD | M] โ C:\Documents and Settings\sphanor\Application Data\Winprint HylaFAX Reloaded
[2011/06/17 16:22:48 | 000,000,000 | โD | M] โ C:\Documents and Settings\sphanor\Application Data\Zeon
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\Square One\Application Data\Windows Desktop Search
[2010/03/25 09:41:27 | 000,000,000 | โD | M] โ C:\Documents and Settings\Square One\Application Data\Windows Search
[2010/03/25 10:20:26 | 000,000,000 | โD | M] โ C:\Documents and Settings\vpiscitelli\Application Data\ICCO
[2010/02/26 19:37:23 | 000,000,000 | โD | M] โ C:\Documents and Settings\vpiscitelli\Application Data\Windows Desktop Search
[2010/03/31 16:19:43 | 000,000,000 | โD | M] โ C:\Documents and Settings\vpiscitelli\Application Data\Windows Search
[2011/11/29 14:51:29 | 000,000,424 | -Hโ | M] () โ C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
< End of report >
OTL Extras logfile created on: 11/29/2011 3:02:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\administrator.BTE\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.20 Gb Available Physical Memory | 73.38% Memory free
4.84 Gb Paging File | 4.11 Gb Available in Paging File | 84.94% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.78 Gb Total Space | 193.71 Gb Free Space | 83.22% Space Free | Partition Type: NTFS
Computer Name: SQ1-PC-053 | User Name: administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ rundll32.exe shell32.dll,Control_RunDLL "%1",%*
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ "%1" %*
cmdfile [open] โ "%1" %*
comfile [open] โ "%1" %*
cplfile [cplopen] โ rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] โ "%1" %*
piffile [open] โ "%1" %*
regfile [merge] โ Reg Error: Key error.
scrfile [config] โ "%1"
scrfile [install] โ rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] โ "%1" /S
txtfile โ Reg Error: Key error.
Unknown [openas] โ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] โ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"Enabled" = 1
"AllowUserPrefMerge" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"Enabled" = 1
"AllowUserPrefMerge" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"135:TCP:*:Enabled:Offer Remote Assistance - Port" = 135:TCP:*:Enabled:Offer Remote Assistance - Port
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 1
"RemoteAddresses" = LocalSubnet
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 1
"RemoteAddresses" = *
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\AuthorizedApplications]
"AllowUserPrefMerge" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console โ (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02E73E50-6513-4802-8600-B5A5BA185BE3}" = ScanSoft PaperPort 11
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Javaโข 6 Update 17
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57E936AA-62B9-41F6-BFEB-CC53D45A0E07}" = CreditSoft 8
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7236672F-6430-439E-9B27-27EDEAF1D676}" = Realtek Ethernet Diagnostic Utility
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{803259ED-7A67-4CB5-B6D7-281ED371091B}" = LogMeIn
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intelยฎ Matrix Storage Manager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9D59AC32-B0FA-4CD7-A2EC-4B57C06CD9D9}" = Dell Backup and Recovery Manager
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4065943-D898-4BE6-BFA4-6A5299675F93}" = Canon DR-4010C Driver
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}" = Trend Micro Internet Security
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Franรงais, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}_946" = Adobe Acrobat 9.4.6 - CPSID_83708
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Franรงais, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AD1D8B40-F83C-41CA-BA08-9DB8D1653316}" = ScanSoft PDF Create! 3.0
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{B34F6EB6-46EF-461A-981A-A19A22897BFF}" = DR-4010C UserManual
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1AE6D4D-C37A-487d-83D8-C333125B2459}" = HP Photosmart and Deskjet 7.0 Software
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F64330DD-1138-4CB4-BF45-87F9168933F6}_is1" = Winprint HylaFAX Reloaded 0.3.1
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DYMO Label Software" = DYMO Label Software
"HDMI" = Intelยฎ Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{57E936AA-62B9-41F6-BFEB-CC53D45A0E07}" = CreditSoft 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"NVIDIA Drivers" = NVIDIA Drivers
"PROPLUS" = Microsoft Office Professional Plus 2007
"Spark 2.5.8" = Spark 2.5.8
"WinLiveSuite_Wave3" = Windows Live Essentials
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 11/29/2011 11:26:22 AM | Computer Name = SQ1-PC-053 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established
Error - 11/29/2011 11:31:12 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 11/29/2011 11:31:13 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry
MUSIC.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)
Error - 11/29/2011 11:31:13 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 11/29/2011 11:31:13 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry
PICTURES.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)
Error - 11/29/2011 11:31:13 AM | Computer Name = SQ1-PC-053 | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 11/29/2011 11:36:36 AM | Computer Name = SQ1-PC-053 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established
Error - 11/29/2011 12:09:45 PM | Computer Name = SQ1-PC-053 | Source = MsiInstaller | ID = 10005
Description = Product: 32 Bit HP BiDi Channel Components Installer โ The installer
has encountered an unexpected error installing this package. This may indicate
a problem with this package. The error code is 2753. The arguments are: ipm12.CF34E983_546C_421F_A494_3C30281E4CF3,
,
Error - 11/29/2011 1:41:45 PM | Computer Name = SQ1-PC-053 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile,
P4 3.0.8402.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 11/29/2011 2:24:46 PM | Computer Name = SQ1-PC-053 | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 1.1.7801.0, P3 1.115.2798.0, P4 1.115.2798.0, P5 exploit_win32_cpllnk.a, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
[ OSession Events ]
Error - 7/22/2010 1:33:37 PM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 365
seconds with 0 seconds of active time. This session ended with a crash.
Error - 4/27/2011 2:21:48 PM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6548.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 20457
seconds with 2100 seconds of active time. This session ended with a crash.
Error - 6/9/2011 2:45:37 PM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6548.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8087
seconds with 720 seconds of active time. This session ended with a crash.
Error - 8/1/2011 4:51:56 PM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.
Error - 8/31/2011 9:37:53 AM | Computer Name = SQ1-PC-053 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 580
seconds with 60 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 10/4/2011 6:57:52 PM | Computer Name = SQ1-PC-053 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 10/6/2011 6:57:22 PM | Computer Name = SQ1-PC-053 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 11/22/2011 12:01:26 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10010
Description = The server {000209FF-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 11/22/2011 12:04:19 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10010
Description = The server {000209FF-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 11/22/2011 12:04:49 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10010
Description = The server {000209FF-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 11/25/2011 6:49:28 PM | Computer Name = SQ1-PC-053 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.
Error - 11/28/2011 4:55:03 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 11/28/2011 4:56:01 PM | Computer Name = SQ1-PC-053 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm MpFilter tmtdi
Error - 11/28/2011 5:00:16 PM | Computer Name = SQ1-PC-053 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 11/29/2011 11:30:18 AM | Computer Name = SQ1-PC-053 | Source = System Error | ID = 1003
Description = Error code 000000ca, parameter1 00000004, parameter2 876391b8, parameter3
00000000, parameter4 00000000.
< End of report >