When I'm using Firefox or internet explorer 7 I randomly receive pop ups with the addresses url.adtrgt.com and different ip address like 70.38.98.32 try to connect but fails. Couldnt not attach file so i put it on the bottom
DDS (Ver_09-01-07.01) - NTFSx86
Run by USER at 9:32:16.25 on Sat 01/10/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.456 [GMT -8:00]
AV: AVG Internet Security *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\USER\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: NoExplorer - No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {45427237-0a00-43ad-9ca1-f78689c0a380} - c:\windows\system32\ssqOEvtq.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {31b6ac47-46d9-bd7b-c9d4-115e933ff286}: {682ff339-e511-4d9c-b7db-9d6474ca6b13} - c:\windows\system32\vfcxnh.dll
BHO: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\pmnnKCrp.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: {A6575304-ECD0-4BD2-BCDD-F757AD1D5603} - No File
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Yahoo! Pager] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_01\bin\jusched.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Nitro PDF Printer Monitor] "c:\program files\nitro pdf\professional\NitroPDFPrinterMonitor.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\Ad-Watch.exe
mRun: [7c3410a6] rundll32.exe "c:\windows\system32\vyaayhph.dll",b
StartupFolder: c:\docume~1\user\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
Notify: pmnnKCrp - pmnnKCrp.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL,avgrsstx.dll vfcxnh.dll
SEH: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\pmnnKCrp.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll, digeste.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\ssqOEvtq
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\6vindh6z.default\
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-4 324872]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-10-4 27656]
R3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter;c:\windows\system32\drivers\NSDriver.sys [2008-4-29 15648]
R3 Ad-Watch Real-Time Scanner;AW Real-Time Scanner;c:\windows\system32\drivers\Awrtpd.sys [2008-4-29 12960]
R4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-6-2 611664]
R4 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2007-6-20 79168]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-10-4 298264]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-5-9 24652]
S1 mferkdk;VSCore mferkdk;\??\c:\program files\mcafee\virusscan enterprise\mferkdk.sys --> c:\program files\mcafee\virusscan enterprise\mferkdk.sys [?]
S3 Ad-Watch Registry Filter;Ad-Watch Registry Kernel Filter;c:\windows\system32\drivers\Awrtrd.sys [2008-4-29 15648]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-12-27 40264]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-12-27 57672]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-12-27 82248]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\svcntaux.exe --> c:\program files\spyware doctor\svcntaux.exe [?]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\swdsvc.exe --> c:\program files\spyware doctor\swdsvc.exe [?]
=============== Created Last 30 ================
2009-01-10 09:10 <DIR> --d----- c:\program files\Trend Micro
2009-01-10 09:01 129,024 a------- c:\windows\system32\vfcxnh.dll
2009-01-10 09:01 129,024 a------- c:\windows\system32\oyocpehm.dll
2009-01-10 09:01 120 ---sh--- c:\windows\system32\hphyaayv.ini
2009-01-10 09:01 72,704 a------- c:\windows\system32\vyaayhph.dll
2009-01-09 09:03 129,024 a------- c:\windows\system32\gkaydz.dll
2009-01-09 09:03 129,024 a------- c:\windows\system32\dkdaikmi.dll
2009-01-09 08:57 120 ---sh--- c:\windows\system32\ylmklbov.ini
2009-01-09 08:57 72,704 -------- c:\windows\system32\voblkmly.dll
2009-01-07 09:10 129,024 a------- c:\windows\system32\nsnrxn.dll
2009-01-07 09:10 129,024 a------- c:\windows\system32\xghjvqwp.dll
2009-01-07 09:05 120 ---sh--- c:\windows\system32\ovvcxnqi.ini
2009-01-07 09:04 665,050 a--sh--- c:\windows\system32\qtvEOqss.ini2
2009-01-07 09:04 665,050 a--sh--- c:\windows\system32\qtvEOqss.ini
2009-01-07 09:04 302,592 a------- c:\windows\system32\ssqOEvtq.dll
2009-01-05 09:06 120 ---sh--- c:\windows\system32\jpquaoah.ini
2009-01-05 09:03 129,024 a------- c:\windows\system32\dyahsd.dll
2009-01-05 09:03 129,024 a------- c:\windows\system32\nglctfdg.dll
2009-01-03 10:55 120 ---sh--- c:\windows\system32\qapmilox.ini
2009-01-03 10:52 129,024 a------- c:\windows\system32\ycxjpp.dll
2009-01-03 10:52 129,024 a------- c:\windows\system32\aesyugpn.dll
2009-01-03 10:33 12,552 a------- c:\windows\system32\drivers\avgrkx86.sys
2009-01-03 09:52 <DIR> --d----- c:\docume~1\user\applic~1\aAvgApi
2009-01-03 09:49 <DIR> --d----- c:\docume~1\user\applic~1\AVGTOOLBAR
2009-01-03 09:28 120 ---sh--- c:\windows\system32\xwdupoan.ini
2009-01-03 09:25 129,024 a------- c:\windows\system32\qedggc.dll
2009-01-03 09:25 129,024 a------- c:\windows\system32\olkgjsto.dll
2009-01-02 09:27 120 ---sh--- c:\windows\system32\gupgbnag.ini
2009-01-02 09:24 129,024 a------- c:\windows\system32\qqxess.dll
2009-01-02 09:24 129,024 a------- c:\windows\system32\bdlbpwds.dll
2008-12-31 11:27 0 a------- c:\windows\QuickInstall.INI
2008-12-31 10:07 53,248 a------- c:\windows\PalmDevC.dll
2008-12-31 10:07 <DIR> --d----- c:\program files\palmOne
2008-12-31 09:06 120 ---sh--- c:\windows\system32\vsbytsjx.ini
2008-12-31 09:03 129,024 a------- c:\windows\system32\szcwrg.dll
2008-12-31 09:03 129,024 a------- c:\windows\system32\frhwbnlh.dll
2008-12-29 17:28 <DIR> --d----- c:\program files\SpywareBlaster
2008-12-29 12:46 727,501 a--sh--- c:\windows\system32\SrsvDfhk.ini2
2008-12-29 09:17 120 ---sh--- c:\windows\system32\kgarfxkm.ini
2008-12-29 09:11 129,024 a------- c:\windows\system32\xcmtua.dll
2008-12-29 09:11 129,024 a------- c:\windows\system32\nlyqlhhy.dll
2008-12-27 15:32 <DIR> --d----- c:\program files\Microsoft Games
2008-12-27 12:56 82,248 a------- c:\windows\system32\drivers\iksyssec.sys
2008-12-27 12:56 40,264 a------- c:\windows\system32\drivers\ikfilesec.sys
2008-12-27 12:56 29,000 a------- c:\windows\system32\drivers\kcom.sys
2008-12-27 12:56 57,672 a------- c:\windows\system32\drivers\iksysflt.sys
2008-12-27 12:55 <DIR> --d----- c:\docume~1\user\applic~1\PC Tools
2008-12-27 12:55 626,688 a------- c:\windows\system32\msvcr80.dll
2008-12-27 09:37 129,024 a------- c:\windows\system32\rgrwzd.dll
2008-12-27 09:37 129,024 a------- c:\windows\system32\gbaqdmro.dll
2008-12-27 09:34 120 ---sh--- c:\windows\system32\abpsnxgs.ini
2008-12-27 09:31 727,501 a--sh--- c:\windows\system32\SrsvDfhk.ini
2008-12-27 09:25 34,816 a------- c:\windows\system32\pmnnKCrp.dll
2008-12-17 19:42 <DIR> --d----- C:\QUARANTINE
2008-12-17 16:40 1,495,552 a------- c:\windows\system32\epoPGPsdk.dll
2008-12-17 16:40 <DIR> --d----- c:\program files\common files\Cisco Systems
==================== Find3M ====================
2009-01-07 16:33 10,520 a------- c:\windows\system32\avgrsstx.dll
2009-01-07 16:33 324,872 a------- c:\windows\system32\drivers\avgldx86.sys
2008-12-31 10:06 16,694 a------- c:\windows\system32\drivers\PalmUSBD.sys
2008-11-22 14:11 286,720 -------- c:\windows\Setup1.exe
2008-11-22 14:11 73,216 a------- c:\windows\ST6UNST.EXE
2008-10-23 04:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-16 12:38 826,368 a------- c:\windows\system32\wininet.dll
2008-09-10 17:00 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091020080911\index.dat
============= FINISH: 9:32:43.53 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-01-07.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 5/8/2008 2:23:46 PM
System Uptime: 1/10/2009 8:59:58 AM (1 hours ago)
Motherboard: Dell Inc. | | 0KP561
Processor: Intel® Pentium® Dual CPU E2140 @ 1.60GHz | CPU | 1595/800mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 74 GiB total, 56.107 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP117: 12/29/2008 5:22:42 PM - Installed Google Earth Pro
RP118: 12/29/2008 5:22:43 PM - Installed Nitro PDF Professional.
RP119: 12/29/2008 5:22:43 PM - Printer Driver FAX4 Driver Installed
RP120: 12/29/2008 5:22:44 PM - Removed Google Earth Pro
RP121: 12/29/2008 5:22:46 PM - TrueCrypt installation
RP122: 12/29/2008 5:22:47 PM - System Checkpoint
RP123: 12/29/2008 5:22:49 PM - Installed Ad-Aware
RP124: 12/29/2008 5:22:49 PM - Removed Ad-Aware
RP125: 12/29/2008 5:22:50 PM - Software Distribution Service 3.0
RP126: 12/29/2008 5:22:52 PM - System Checkpoint
RP127: 12/29/2008 5:22:53 PM - Avg8 Update
RP128: 12/29/2008 5:22:53 PM - Avg8 Update
RP129: 12/29/2008 5:22:53 PM - Installed KODAK Gallery Upload Software.
RP130: 12/29/2008 5:22:54 PM - Software Distribution Service 3.0
RP131: 12/29/2008 5:22:55 PM - Avg8 Update
RP132: 12/29/2008 5:22:55 PM - Avg8 Update
RP133: 12/29/2008 5:22:56 PM - System Checkpoint
RP134: 12/29/2008 5:22:57 PM - System Checkpoint
RP135: 12/29/2008 5:22:58 PM - System Checkpoint
RP136: 12/29/2008 5:22:58 PM - Avg8 Update
RP137: 12/29/2008 5:22:59 PM - Avg8 Update
RP138: 12/29/2008 5:22:59 PM - System Checkpoint
RP139: 12/29/2008 5:23:00 PM - System Checkpoint
RP140: 12/29/2008 5:23:00 PM - Avg8 Update
RP141: 12/29/2008 5:23:00 PM - System Checkpoint
RP142: 12/29/2008 5:23:00 PM - Software Distribution Service 3.0
RP143: 12/29/2008 5:23:00 PM - System Checkpoint
RP144: 12/29/2008 5:23:01 PM - System Checkpoint
RP145: 12/29/2008 5:23:01 PM - Software Distribution Service 3.0
RP146: 12/29/2008 5:23:01 PM - System Checkpoint
RP147: 12/29/2008 5:23:01 PM - Installed Ad-Aware
RP148: 12/29/2008 5:23:02 PM - Removed Microsoft Silverlight
RP149: 12/29/2008 5:23:02 PM - TrueCrypt uninstallation
RP150: 12/29/2008 5:23:02 PM - System Checkpoint
RP151: 12/29/2008 5:23:02 PM - Avg8 Update
RP152: 12/29/2008 5:23:02 PM - System Checkpoint
RP153: 12/29/2008 5:23:02 PM - System Checkpoint
RP154: 12/29/2008 5:23:03 PM - System Checkpoint
RP155: 12/29/2008 5:23:03 PM - System Checkpoint
RP156: 12/29/2008 5:23:03 PM - System Checkpoint
RP157: 12/29/2008 5:23:04 PM - Configured Microsoft Office Professional Plus 2007
RP158: 12/29/2008 5:23:04 PM - Removed SweetIM for Messenger 2.5
RP159: 12/29/2008 5:23:04 PM - System Checkpoint
RP160: 12/29/2008 5:23:04 PM - Software Distribution Service 3.0
RP161: 12/29/2008 5:23:05 PM - Installed DirectX 9.0
RP162: 12/29/2008 5:23:05 PM - System Checkpoint
RP163: 12/29/2008 5:23:05 PM - Installed TBS WMP Plug-in
RP164: 12/29/2008 5:23:06 PM - Installed McAfee VirusScan Enterprise
RP165: 12/29/2008 5:23:06 PM - Removed McAfee VirusScan Enterprise
RP166: 12/29/2008 5:23:06 PM - Software Distribution Service 3.0
RP167: 12/29/2008 5:23:06 PM - System Checkpoint
RP168: 12/29/2008 5:23:06 PM - System Checkpoint
RP169: 12/29/2008 5:23:06 PM - System Checkpoint
RP170: 12/29/2008 5:23:06 PM - Last known good configuration
RP171: 12/29/2008 5:23:06 PM - Configured TBS WMP Plug-in
RP172: 12/29/2008 5:23:08 PM - Last known good configuration
RP173: 12/29/2008 5:23:08 PM - Removed FSC Rater Component
RP174: 12/29/2008 5:23:09 PM - Installed FSC Rater Component
RP175: 12/29/2008 5:23:15 PM - Last known good configuration
RP176: 12/31/2008 10:07:09 AM - Installed palmOne
RP177: 1/3/2009 9:49:09 AM - Configured AVG Free 8.0
RP178: 1/3/2009 10:31:27 AM - Avg8 Update
RP179: 1/3/2009 10:33:09 AM - Avg8 Update
RP180: 1/5/2009 11:17:18 AM - Removed KODAK Gallery Upload Software.
RP181: 1/7/2009 3:33:48 PM - System Checkpoint
RP182: 1/7/2009 4:31:20 PM - Avg8 Update
RP183: 1/7/2009 4:33:25 PM - Avg8 Update
RP184: 1/8/2009 9:17:16 AM - Removed Pocket Controller-Enterprise
RP185: 1/9/2009 2:44:17 PM - System Checkpoint
==== Installed Programs ======================
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.9
Apple Mobile Device Support
Apple Software Update
AVG Free 8.0
Bonjour
Broadcom ASF Management Applications
Broadcom Gigabit Integrated Controller
Broadcom Management Programs
Brother MFL-Pro Suite
CCleaner (remove only)
Comprise
Counter-Strike 1.6
Folder Lock
FSC Rater CA Workstation
FSC Rater Component
FSCToInfinityWeb
HawkSoft Components
HijackThis 2.0.2
Intel® Graphics Media Accelerator Driver
iTunes
Java SE Runtime Environment 6 Update 1
MetaFrame Presentation Server Web Client for Win32
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft ActiveSync
Microsoft Halo
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Mozilla Firefox (3.0.5)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB933579)
Nitro PDF Professional
North Coast Life
One Step Bridges CA
OneStep
palmOne
PaperPort
QuickTime
RealPlayer
ScrewDrivers Client v4
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923689)
Softech MVR Bridge - FSC Rater
SoundMAX
Spybot - Search & Destroy
SpywareBlaster 4.1
Viewpoint Media Player
WebEx
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows XP Service Pack 3
WinRAR archiver
Yahoo! Messenger
==== Event Viewer Messages From Past Week ========
1/3/2009 10:49:27 AM, error: Dhcp [1002] - The IP address lease 10.0.0.102 for the Network Card with network address 001D09102E90 has been denied by the DHCP server 10.0.0.100 (The DHCP Server sent a DHCPNACK message).
1/5/2009 11:16:18 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
1/13/2009 11:15:08 AM, error: W32Time [34] - The time service has detected that the system time needs to be changed by -518398 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time-a.nist.gov (ntp.m|0x1|10.0.0.102:123->129.6.15.28:123) is working properly.
1/7/2009 5:49:49 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
1/7/2009 5:50:05 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/10/2009 9:02:25 AM, error: EventLog [6004] - A driver packet received from the I/O subsystem was invalid. The data is the packet.
==== End Of File ===========================
DDS (Ver_09-01-07.01) - NTFSx86
Run by USER at 9:32:16.25 on Sat 01/10/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.456 [GMT -8:00]
AV: AVG Internet Security *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\USER\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: NoExplorer - No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {45427237-0a00-43ad-9ca1-f78689c0a380} - c:\windows\system32\ssqOEvtq.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {31b6ac47-46d9-bd7b-c9d4-115e933ff286}: {682ff339-e511-4d9c-b7db-9d6474ca6b13} - c:\windows\system32\vfcxnh.dll
BHO: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\pmnnKCrp.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: {A6575304-ECD0-4BD2-BCDD-F757AD1D5603} - No File
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Yahoo! Pager] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_01\bin\jusched.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Nitro PDF Printer Monitor] "c:\program files\nitro pdf\professional\NitroPDFPrinterMonitor.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\Ad-Watch.exe
mRun: [7c3410a6] rundll32.exe "c:\windows\system32\vyaayhph.dll",b
StartupFolder: c:\docume~1\user\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
Notify: pmnnKCrp - pmnnKCrp.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL,avgrsstx.dll vfcxnh.dll
SEH: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\pmnnKCrp.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll, digeste.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\ssqOEvtq
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\6vindh6z.default\
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-4 324872]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-10-4 27656]
R3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter;c:\windows\system32\drivers\NSDriver.sys [2008-4-29 15648]
R3 Ad-Watch Real-Time Scanner;AW Real-Time Scanner;c:\windows\system32\drivers\Awrtpd.sys [2008-4-29 12960]
R4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-6-2 611664]
R4 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2007-6-20 79168]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-10-4 298264]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-5-9 24652]
S1 mferkdk;VSCore mferkdk;\??\c:\program files\mcafee\virusscan enterprise\mferkdk.sys --> c:\program files\mcafee\virusscan enterprise\mferkdk.sys [?]
S3 Ad-Watch Registry Filter;Ad-Watch Registry Kernel Filter;c:\windows\system32\drivers\Awrtrd.sys [2008-4-29 15648]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-12-27 40264]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-12-27 57672]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-12-27 82248]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\svcntaux.exe --> c:\program files\spyware doctor\svcntaux.exe [?]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\swdsvc.exe --> c:\program files\spyware doctor\swdsvc.exe [?]
=============== Created Last 30 ================
2009-01-10 09:10 <DIR> --d----- c:\program files\Trend Micro
2009-01-10 09:01 129,024 a------- c:\windows\system32\vfcxnh.dll
2009-01-10 09:01 129,024 a------- c:\windows\system32\oyocpehm.dll
2009-01-10 09:01 120 ---sh--- c:\windows\system32\hphyaayv.ini
2009-01-10 09:01 72,704 a------- c:\windows\system32\vyaayhph.dll
2009-01-09 09:03 129,024 a------- c:\windows\system32\gkaydz.dll
2009-01-09 09:03 129,024 a------- c:\windows\system32\dkdaikmi.dll
2009-01-09 08:57 120 ---sh--- c:\windows\system32\ylmklbov.ini
2009-01-09 08:57 72,704 -------- c:\windows\system32\voblkmly.dll
2009-01-07 09:10 129,024 a------- c:\windows\system32\nsnrxn.dll
2009-01-07 09:10 129,024 a------- c:\windows\system32\xghjvqwp.dll
2009-01-07 09:05 120 ---sh--- c:\windows\system32\ovvcxnqi.ini
2009-01-07 09:04 665,050 a--sh--- c:\windows\system32\qtvEOqss.ini2
2009-01-07 09:04 665,050 a--sh--- c:\windows\system32\qtvEOqss.ini
2009-01-07 09:04 302,592 a------- c:\windows\system32\ssqOEvtq.dll
2009-01-05 09:06 120 ---sh--- c:\windows\system32\jpquaoah.ini
2009-01-05 09:03 129,024 a------- c:\windows\system32\dyahsd.dll
2009-01-05 09:03 129,024 a------- c:\windows\system32\nglctfdg.dll
2009-01-03 10:55 120 ---sh--- c:\windows\system32\qapmilox.ini
2009-01-03 10:52 129,024 a------- c:\windows\system32\ycxjpp.dll
2009-01-03 10:52 129,024 a------- c:\windows\system32\aesyugpn.dll
2009-01-03 10:33 12,552 a------- c:\windows\system32\drivers\avgrkx86.sys
2009-01-03 09:52 <DIR> --d----- c:\docume~1\user\applic~1\aAvgApi
2009-01-03 09:49 <DIR> --d----- c:\docume~1\user\applic~1\AVGTOOLBAR
2009-01-03 09:28 120 ---sh--- c:\windows\system32\xwdupoan.ini
2009-01-03 09:25 129,024 a------- c:\windows\system32\qedggc.dll
2009-01-03 09:25 129,024 a------- c:\windows\system32\olkgjsto.dll
2009-01-02 09:27 120 ---sh--- c:\windows\system32\gupgbnag.ini
2009-01-02 09:24 129,024 a------- c:\windows\system32\qqxess.dll
2009-01-02 09:24 129,024 a------- c:\windows\system32\bdlbpwds.dll
2008-12-31 11:27 0 a------- c:\windows\QuickInstall.INI
2008-12-31 10:07 53,248 a------- c:\windows\PalmDevC.dll
2008-12-31 10:07 <DIR> --d----- c:\program files\palmOne
2008-12-31 09:06 120 ---sh--- c:\windows\system32\vsbytsjx.ini
2008-12-31 09:03 129,024 a------- c:\windows\system32\szcwrg.dll
2008-12-31 09:03 129,024 a------- c:\windows\system32\frhwbnlh.dll
2008-12-29 17:28 <DIR> --d----- c:\program files\SpywareBlaster
2008-12-29 12:46 727,501 a--sh--- c:\windows\system32\SrsvDfhk.ini2
2008-12-29 09:17 120 ---sh--- c:\windows\system32\kgarfxkm.ini
2008-12-29 09:11 129,024 a------- c:\windows\system32\xcmtua.dll
2008-12-29 09:11 129,024 a------- c:\windows\system32\nlyqlhhy.dll
2008-12-27 15:32 <DIR> --d----- c:\program files\Microsoft Games
2008-12-27 12:56 82,248 a------- c:\windows\system32\drivers\iksyssec.sys
2008-12-27 12:56 40,264 a------- c:\windows\system32\drivers\ikfilesec.sys
2008-12-27 12:56 29,000 a------- c:\windows\system32\drivers\kcom.sys
2008-12-27 12:56 57,672 a------- c:\windows\system32\drivers\iksysflt.sys
2008-12-27 12:55 <DIR> --d----- c:\docume~1\user\applic~1\PC Tools
2008-12-27 12:55 626,688 a------- c:\windows\system32\msvcr80.dll
2008-12-27 09:37 129,024 a------- c:\windows\system32\rgrwzd.dll
2008-12-27 09:37 129,024 a------- c:\windows\system32\gbaqdmro.dll
2008-12-27 09:34 120 ---sh--- c:\windows\system32\abpsnxgs.ini
2008-12-27 09:31 727,501 a--sh--- c:\windows\system32\SrsvDfhk.ini
2008-12-27 09:25 34,816 a------- c:\windows\system32\pmnnKCrp.dll
2008-12-17 19:42 <DIR> --d----- C:\QUARANTINE
2008-12-17 16:40 1,495,552 a------- c:\windows\system32\epoPGPsdk.dll
2008-12-17 16:40 <DIR> --d----- c:\program files\common files\Cisco Systems
==================== Find3M ====================
2009-01-07 16:33 10,520 a------- c:\windows\system32\avgrsstx.dll
2009-01-07 16:33 324,872 a------- c:\windows\system32\drivers\avgldx86.sys
2008-12-31 10:06 16,694 a------- c:\windows\system32\drivers\PalmUSBD.sys
2008-11-22 14:11 286,720 -------- c:\windows\Setup1.exe
2008-11-22 14:11 73,216 a------- c:\windows\ST6UNST.EXE
2008-10-23 04:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-16 12:38 826,368 a------- c:\windows\system32\wininet.dll
2008-09-10 17:00 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091020080911\index.dat
============= FINISH: 9:32:43.53 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-01-07.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 5/8/2008 2:23:46 PM
System Uptime: 1/10/2009 8:59:58 AM (1 hours ago)
Motherboard: Dell Inc. | | 0KP561
Processor: Intel® Pentium® Dual CPU E2140 @ 1.60GHz | CPU | 1595/800mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 74 GiB total, 56.107 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP117: 12/29/2008 5:22:42 PM - Installed Google Earth Pro
RP118: 12/29/2008 5:22:43 PM - Installed Nitro PDF Professional.
RP119: 12/29/2008 5:22:43 PM - Printer Driver FAX4 Driver Installed
RP120: 12/29/2008 5:22:44 PM - Removed Google Earth Pro
RP121: 12/29/2008 5:22:46 PM - TrueCrypt installation
RP122: 12/29/2008 5:22:47 PM - System Checkpoint
RP123: 12/29/2008 5:22:49 PM - Installed Ad-Aware
RP124: 12/29/2008 5:22:49 PM - Removed Ad-Aware
RP125: 12/29/2008 5:22:50 PM - Software Distribution Service 3.0
RP126: 12/29/2008 5:22:52 PM - System Checkpoint
RP127: 12/29/2008 5:22:53 PM - Avg8 Update
RP128: 12/29/2008 5:22:53 PM - Avg8 Update
RP129: 12/29/2008 5:22:53 PM - Installed KODAK Gallery Upload Software.
RP130: 12/29/2008 5:22:54 PM - Software Distribution Service 3.0
RP131: 12/29/2008 5:22:55 PM - Avg8 Update
RP132: 12/29/2008 5:22:55 PM - Avg8 Update
RP133: 12/29/2008 5:22:56 PM - System Checkpoint
RP134: 12/29/2008 5:22:57 PM - System Checkpoint
RP135: 12/29/2008 5:22:58 PM - System Checkpoint
RP136: 12/29/2008 5:22:58 PM - Avg8 Update
RP137: 12/29/2008 5:22:59 PM - Avg8 Update
RP138: 12/29/2008 5:22:59 PM - System Checkpoint
RP139: 12/29/2008 5:23:00 PM - System Checkpoint
RP140: 12/29/2008 5:23:00 PM - Avg8 Update
RP141: 12/29/2008 5:23:00 PM - System Checkpoint
RP142: 12/29/2008 5:23:00 PM - Software Distribution Service 3.0
RP143: 12/29/2008 5:23:00 PM - System Checkpoint
RP144: 12/29/2008 5:23:01 PM - System Checkpoint
RP145: 12/29/2008 5:23:01 PM - Software Distribution Service 3.0
RP146: 12/29/2008 5:23:01 PM - System Checkpoint
RP147: 12/29/2008 5:23:01 PM - Installed Ad-Aware
RP148: 12/29/2008 5:23:02 PM - Removed Microsoft Silverlight
RP149: 12/29/2008 5:23:02 PM - TrueCrypt uninstallation
RP150: 12/29/2008 5:23:02 PM - System Checkpoint
RP151: 12/29/2008 5:23:02 PM - Avg8 Update
RP152: 12/29/2008 5:23:02 PM - System Checkpoint
RP153: 12/29/2008 5:23:02 PM - System Checkpoint
RP154: 12/29/2008 5:23:03 PM - System Checkpoint
RP155: 12/29/2008 5:23:03 PM - System Checkpoint
RP156: 12/29/2008 5:23:03 PM - System Checkpoint
RP157: 12/29/2008 5:23:04 PM - Configured Microsoft Office Professional Plus 2007
RP158: 12/29/2008 5:23:04 PM - Removed SweetIM for Messenger 2.5
RP159: 12/29/2008 5:23:04 PM - System Checkpoint
RP160: 12/29/2008 5:23:04 PM - Software Distribution Service 3.0
RP161: 12/29/2008 5:23:05 PM - Installed DirectX 9.0
RP162: 12/29/2008 5:23:05 PM - System Checkpoint
RP163: 12/29/2008 5:23:05 PM - Installed TBS WMP Plug-in
RP164: 12/29/2008 5:23:06 PM - Installed McAfee VirusScan Enterprise
RP165: 12/29/2008 5:23:06 PM - Removed McAfee VirusScan Enterprise
RP166: 12/29/2008 5:23:06 PM - Software Distribution Service 3.0
RP167: 12/29/2008 5:23:06 PM - System Checkpoint
RP168: 12/29/2008 5:23:06 PM - System Checkpoint
RP169: 12/29/2008 5:23:06 PM - System Checkpoint
RP170: 12/29/2008 5:23:06 PM - Last known good configuration
RP171: 12/29/2008 5:23:06 PM - Configured TBS WMP Plug-in
RP172: 12/29/2008 5:23:08 PM - Last known good configuration
RP173: 12/29/2008 5:23:08 PM - Removed FSC Rater Component
RP174: 12/29/2008 5:23:09 PM - Installed FSC Rater Component
RP175: 12/29/2008 5:23:15 PM - Last known good configuration
RP176: 12/31/2008 10:07:09 AM - Installed palmOne
RP177: 1/3/2009 9:49:09 AM - Configured AVG Free 8.0
RP178: 1/3/2009 10:31:27 AM - Avg8 Update
RP179: 1/3/2009 10:33:09 AM - Avg8 Update
RP180: 1/5/2009 11:17:18 AM - Removed KODAK Gallery Upload Software.
RP181: 1/7/2009 3:33:48 PM - System Checkpoint
RP182: 1/7/2009 4:31:20 PM - Avg8 Update
RP183: 1/7/2009 4:33:25 PM - Avg8 Update
RP184: 1/8/2009 9:17:16 AM - Removed Pocket Controller-Enterprise
RP185: 1/9/2009 2:44:17 PM - System Checkpoint
==== Installed Programs ======================
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.9
Apple Mobile Device Support
Apple Software Update
AVG Free 8.0
Bonjour
Broadcom ASF Management Applications
Broadcom Gigabit Integrated Controller
Broadcom Management Programs
Brother MFL-Pro Suite
CCleaner (remove only)
Comprise
Counter-Strike 1.6
Folder Lock
FSC Rater CA Workstation
FSC Rater Component
FSCToInfinityWeb
HawkSoft Components
HijackThis 2.0.2
Intel® Graphics Media Accelerator Driver
iTunes
Java SE Runtime Environment 6 Update 1
MetaFrame Presentation Server Web Client for Win32
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft ActiveSync
Microsoft Halo
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Mozilla Firefox (3.0.5)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB933579)
Nitro PDF Professional
North Coast Life
One Step Bridges CA
OneStep
palmOne
PaperPort
QuickTime
RealPlayer
ScrewDrivers Client v4
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923689)
Softech MVR Bridge - FSC Rater
SoundMAX
Spybot - Search & Destroy
SpywareBlaster 4.1
Viewpoint Media Player
WebEx
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows XP Service Pack 3
WinRAR archiver
Yahoo! Messenger
==== Event Viewer Messages From Past Week ========
1/3/2009 10:49:27 AM, error: Dhcp [1002] - The IP address lease 10.0.0.102 for the Network Card with network address 001D09102E90 has been denied by the DHCP server 10.0.0.100 (The DHCP Server sent a DHCPNACK message).
1/5/2009 11:16:18 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
1/13/2009 11:15:08 AM, error: W32Time [34] - The time service has detected that the system time needs to be changed by -518398 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time-a.nist.gov (ntp.m|0x1|10.0.0.102:123->129.6.15.28:123) is working properly.
1/7/2009 5:49:49 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
1/7/2009 5:50:05 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/10/2009 9:02:25 AM, error: EventLog [6004] - A driver packet received from the I/O subsystem was invalid. The data is the packet.
==== End Of File ===========================

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top












