Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bad Image Error


  • Please log in to reply
9 replies to this topic

#1 catybug1012

catybug1012

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:44 AM

Posted 27 May 2009 - 07:12 PM

Hello. I have windows xp professional. Whenever I start up my computer or open any application, I get a lot of error messages. It will say "(whatever application).exe-Bad Image" in the red area. In the gray box underneath, it always says "The application or DLL c:\windows\system32\bisomasu.dll is not a valid Windows image. Please check this againstfRoe your installation diskette."

Malwarebytes found and deleted : Adware.coupons, Backdoor.bot, and Trojan.vundo. I've also run McAfee, Spysweeper, Adaware, PandaOnline Scanner and Spybot. but I still keep getting the same error message.

Here is the dds.txt file :


DDS (Ver_09-05-14.01) - NTFSx86
Run by D R at 18:58:37.81 on Wed 05/27/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1535.983 [GMT -4:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: Webroot Internet Security Essentials *disabled* {2DB6657C-B970-44d3-AB42-6325A913CCC2}

============== Running Processes ===============

C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\sistray.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\D Rl\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://news.nationalgeographic.com/news/archaeology.html
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: {a17ed655-8961-49c4-a666-07f4df7a2ec4} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [P2kAutostart]
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe"
uRun: [ctfmon.exe] "c:\windows\system32\ctfmon.exe"
mRun: [C-Media Mixer] "c:\windows\Mixer.exe" /startup
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [NWEReboot]
mRun: [SiS Tray] "c:\windows\system32\sistray.EXE"
mRun: [SiS KHooker] "c:\windows\system32\khooker.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SpySweeper] "c:\program files\webroot\spy sweeper\SpySweeperUI.exe" /startintray
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: rqRIxuTN - rqRIxuTN.dll
Notify: xmjtnzpc - c:\documents and settings\d rl\application data\xmjtnzpc.dll
AppInit_DLLs: c:\windows\system32\bisomasu.dll
LSA: Notification Packages = scecli c:\windows\system32\bisomasu.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\donaro~1\applic~1\mozilla\firefox\profiles\zfim2gyn.default\
FF - prefs.js: browser.startup.homepage - hxxp://news.nationalgeographic.com/news/archaeology.html
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll

============= SERVICES / DRIVERS ===============

R0 Fasttrak;Fasttrak;c:\windows\system32\drivers\Fasttrak.sys [2001-11-23 70528]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-5-26 28544]
R0 SI3112r;Silicon Image SiI 3512 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [2008-7-25 102528]
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-8-9 29808]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2006-10-16 214024]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2007-8-1 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2006-10-16 144704]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2008-12-7 3671408]
R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\spy sweeper\WRConsumerService.exe [2009-1-27 1090936]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2006-10-16 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2006-10-16 79880]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-10-16 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-10-16 40552]
S2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2006-11-5 2944]
S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2006-11-5 61952]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [2006-11-5 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [2006-11-5 10368]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-10-16 34216]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]

=============== Created Last 30 ================

2009-05-27 08:27 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-05-27 08:27 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-05-27 08:08 194 a---h--- C:\aaw7boot.cmd
2009-05-26 12:12 28,544 a------- c:\windows\system32\drivers\pavboot.sys
2009-05-26 12:10 <DIR> --d----- c:\program files\Panda Security
2009-05-25 18:30 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-05-25 18:27 <DIR> --d----- c:\documents and settings\d r\.housecall6.6
2009-05-25 17:55 <DIR> --d----- c:\windows\SxsCaPendDel
2009-05-25 13:20 <DIR> --d----- c:\docume~1\donaro~1\applic~1\OpenOffice.org
2009-05-25 13:12 <DIR> --d----- c:\program files\OpenOffice.org 3
2009-05-25 13:11 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-25 13:11 73,728 a------- c:\windows\system32\javacpl.cpl
2009-05-25 12:31 <DIR> --d----- c:\docume~1\donaro~1\applic~1\NwDocx
2009-05-23 19:22 6,144 a--sh--- c:\windows\system32\access.ctl
2009-05-10 11:39 <DIR> --d----- c:\program files\Restore My Files Data Recovery v6.01
2009-04-29 07:02 <DIR> --d----- c:\docume~1\donaro~1\applic~1\Malwarebytes
2009-04-29 07:02 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-29 07:02 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-29 07:02 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-29 07:02 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware

==================== Find3M ====================

2009-05-26 12:06 1,744 a------- c:\windows\system32\d3d9caps.dat
2008-08-22 14:58 1,471,400 a------- c:\program files\LGUSBModemDriver_WHQL_Eng_Ver_4.8.1.exe
2007-05-02 07:10 774,144 a------- c:\program files\RngInterstitial.dll
2009-01-26 08:41 0 a--sh--- c:\windows\system32\bisomasu.dll
2009-01-26 08:41 0 a--sh--- c:\windows\system32\sajuyaya.dll

============= FINISH: 19:02:28.46 ===============

Thank you very much for your help!

BC AdBot (Login to Remove)

 


#2 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:10:44 AM

Posted 27 May 2009 - 07:32 PM

Hello catybug1012

Welcome to BleepingComputer :thumbup2:
========================
Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: Posted Image
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again
  • After the update, from the "File" menu, choose "Standard Scripts"
  • Put a check next to item 2: Advanced System Investigation
  • Click Execute selected scripts
  • At the next prompt, click the OK button
  • Let the scan run and click "OK" when the completion prompt pops up
  • Now Close out of the Standard Scripts window, and exit AVZ
  • Navigate to the avz4 folder and locate the folder LOG
  • Inside the LOG folder you will find virusinfo_syscheck.htm and virusinfo_syscheck.zip
  • Attach the Compressed file, virusinfo_syscheck.zip, to your next reply.

Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#3 catybug1012

catybug1012
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:44 AM

Posted 28 May 2009 - 07:11 AM

Good morning. I ran avz and attached the zip file results.

WHen I tried unzipping the avz.exe file to my desktop, I got an error message "data in zip file is damaged - CRC check failed" so I unzipped it to another location and had the same error message.

Thank you.

Attached Files



#4 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:10:44 AM

Posted 28 May 2009 - 07:24 AM

  • Close all windows then double click on AVZ.exe
  • Click File > Custom scripts
  • Copy & paste the contents of the following codebox in the box in the program

    begin
     DelBHO('{a17ed655-8961-49c4-a666-07f4df7a2ec4}');
     BC_DeleteFile('C:\Documents and Settings\Dona Roell\Application Data\xmjtnzpc.dll');
     DeleteFile('rqRIxuTN.dll');
     BC_DeleteFile('rqRIxuTN.dll');
     BC_ImportDeletedList;
     BC_LogFile(GetAVZDirectory + 'boot_clr.log');
     BC_Activate;
     ExecuteSysClean;
     SaveLog(GetAVZDirectory + 'avz_log.txt');
     RebootWindows(true);
    end.

  • Note: When you run the script, your PC will be restarted
  • Click Run
  • Restart your PC if it doesn't do it automatically, and post back with these 2 logs avz.log and boot_clr.log.
  • These can be found in the AVZ folder that you extracted on your desktop.
==================
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#5 catybug1012

catybug1012
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:44 AM

Posted 28 May 2009 - 06:23 PM

Hello, Kadah.

Here is the avs.log. I didn't have a boot_clr log. When I ran the custom script, toward the end of its run McAffee popped up and said it blocked trojan generic.dx. I tried twice and the same thing happened. I did have avz.cnt , but I think that was already part of the file.

I thought I would check with you first to see if I needed to do something else before running OTL.

Thank you.

Attached Files



#6 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:10:44 AM

Posted 29 May 2009 - 06:15 AM

That is fine go ahead with the OTL.
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#7 catybug1012

catybug1012
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:44 AM

Posted 29 May 2009 - 09:40 AM

Here is the extras.txt

OTL Extras logfile created on: 5/29/2009 10:30:41 AM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Dona Roell\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 73.78% Memory free
2.86 Gb Paging File | 2.52 Gb Available in Paging File | 88.14% Paging File free
Paging file location(s): C:\pagefile.sys 2 1000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 384.81 Gb Free Space | 82.62% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-ZGULHB9M0R
Current User Name: Dona Roell
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = MozillaHTML] -- C:\Program Files\Netscape\Netscape\Netscp.exe (Mozilla, Netscape)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (America Online, Inc.)
C:\Program Files\Common Files\AOL\1139789212\ee\aolsoftware.exe:*:Enabled:AOL Services File not found
C:\Program Files\Common Files\AOL\1139789212\ee\aim6.exe:*:Enabled:AIM File not found
C:\Program Files\Common Files\AOL\1141606746\ee\aolsoftware.exe:*:Enabled:AOL Services (America Online, Inc.)
C:\Program Files\Common Files\AOL\1141606746\ee\aim6.exe:*:Enabled:AIM (America Online, Inc.)
C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server File not found
C:\Program Files\Netscape\Netscape\Netscp.exe:*:Disabled:Netscape (Mozilla, Netscape)
C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer (LimeWire)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax (Intuit, Inc.)
C:\Program Files\TurboTax\Deluxe 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager (Intuit, Inc.)
C:\Program Files\Yahoo! Games\Bejeweled 2 Deluxe\WinBej2.exe:*:Enabled:Bejeweled2 File not found
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax (Intuit, Inc.)
C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager (Intuit, Inc.)
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server (Intuit Inc.)
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent (McAfee, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{069364A0-8F64-4691-8719-B3CC728BFD6C}" = ArcSoft PhotoImpression 5
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{553E56C3-7AA1-45FE-A2FC-2C43DC27F765}" = iTunes
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{76F8CB2B-6516-4E1E-B6F1-AED4ABDB4B0A}_is1" = Spy Sweeper
"{7C32C567-DC0F-4C80-B06C-7873850A2E06}" = The Sims Unleashed
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{8398B542-3CC4-44D9-83DF-696CCE70124B}" = Windows Support Tools
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AEF2D1F3-0696-11D5-8E6A-00C04F7FA234}" = PaperPort 8.0 SE
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{BBF7D230-8F25-4041-90A9-73FD03BE8640}" = DartViewer
"{C33DC9DF-0841-4B28-AD0B-68EF59FAC53C}" = Brother MFL-Pro Suite
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}" = WinZip 11.1
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FA02ACAC-9E14-4878-A257-92A22A647C2C}" = LG USB Modem Drivers
"3DForce S Series, SiS 315_315E" = 3DForce S Series, SiS 315_315E
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0
"BellsouthHelpCenter4_is1" = BellSouth® FastAccess® DSL Help Center 4.0
"Cindex for Windows 1.5" = Cindex for Windows 1.5
"DXTXTRA" = Microsoft DirectX Transform optional components
"InstallShield_{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"Java Web Start" = Java Web Start
"KeyRipper" = KeyRipper 2.00
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSC" = McAfee SecurityCenter
"Netscape (7.2)" = Netscape (7.2)
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"PCI Audio Applications" = PCI Audio Applications
"PCI Audio Driver" = PCI Audio Driver
"Plaxo" = Plaxo Toolbar for Outlook and Outlook Express
"SE Object Manager" = SE Object Manager
"SimEnhancer 3D" = SimEnhancer 3D
"TurboTax 2008" = TurboTax 2008
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"TurboTax Deluxe Deduction Maximizer 2006" = TurboTax Deluxe Deduction Maximizer 2006
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/21/2009 7:02:23 AM | Computer Name = HOME-ZGULHB9M0R | Source = | ID = 0
Description =

Error - 5/21/2009 5:33:36 PM | Computer Name = HOME-ZGULHB9M0R | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/21/2009 5:33:37 PM | Computer Name = HOME-ZGULHB9M0R | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/21/2009 5:33:37 PM | Computer Name = HOME-ZGULHB9M0R | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/21/2009 5:33:37 PM | Computer Name = HOME-ZGULHB9M0R | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/21/2009 8:33:20 PM | Computer Name = HOME-ZGULHB9M0R | Source = | ID = 0
Description =

Error - 5/21/2009 8:33:20 PM | Computer Name = HOME-ZGULHB9M0R | Source = | ID = 0
Description =

Error - 5/22/2009 8:54:39 AM | Computer Name = HOME-ZGULHB9M0R | Source = | ID = 0
Description =

Error - 5/22/2009 8:54:39 AM | Computer Name = HOME-ZGULHB9M0R | Source = | ID = 0
Description =

Error - 5/27/2009 5:01:23 AM | Computer Name = HOME-ZGULHB9M0R | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

[ System Events ]
Error - 5/27/2009 6:55:29 PM | Computer Name = HOME-ZGULHB9M0R | Source = Service Control Manager | ID = 7034
Description = The Intuit Update Service service terminated unexpectedly. It has
done this 1 time(s).

Error - 5/28/2009 6:37:00 AM | Computer Name = HOME-ZGULHB9M0R | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 5/28/2009 6:37:03 AM | Computer Name = HOME-ZGULHB9M0R | Source = Service Control Manager | ID = 7034
Description = The Intuit Update Service service terminated unexpectedly. It has
done this 1 time(s).

Error - 5/29/2009 8:22:07 AM | Computer Name = HOME-ZGULHB9M0R | Source = SideBySide | ID = 16842813
Description = Syntax error in manifest or policy file "C:\Program Files\Apple Software
Update\Plugins\EXEInstallPlugin.dll.Manifest" on line 2. The required attribute
version is missing from element assemblyIdentity.

Error - 5/29/2009 8:22:07 AM | Computer Name = HOME-ZGULHB9M0R | Source = SideBySide | ID = 16842810
Description = Syntax error in manifest or policy file "C:\Program Files\Apple Software
Update\Plugins\EXEInstallPlugin.dll.Manifest" on line 2.

Error - 5/29/2009 8:22:07 AM | Computer Name = HOME-ZGULHB9M0R | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Apple Software
Update\Plugins\EXEInstallPlugin.dll.Manifest. Reference error message: The operation
completed successfully. .

Error - 5/29/2009 8:22:07 AM | Computer Name = HOME-ZGULHB9M0R | Source = SideBySide | ID = 16842813
Description = Syntax error in manifest or policy file "C:\Program Files\Apple Software
Update\Plugins\MSIInstallPlugin.dll.Manifest" on line 2. The required attribute
version is missing from element assemblyIdentity.

Error - 5/29/2009 8:22:07 AM | Computer Name = HOME-ZGULHB9M0R | Source = SideBySide | ID = 16842810
Description = Syntax error in manifest or policy file "C:\Program Files\Apple Software
Update\Plugins\MSIInstallPlugin.dll.Manifest" on line 2.

Error - 5/29/2009 8:22:07 AM | Computer Name = HOME-ZGULHB9M0R | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Apple Software
Update\Plugins\MSIInstallPlugin.dll.Manifest. Reference error message: The operation
completed successfully. .

Error - 5/29/2009 8:32:53 AM | Computer Name = HOME-ZGULHB9M0R | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.


< End of report >


and here is the otl.txt

OTL logfile created on: 5/29/2009 10:30:41 AM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Dona Roell\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 73.78% Memory free
2.86 Gb Paging File | 2.52 Gb Available in Paging File | 88.14% Paging File free
Paging file location(s): C:\pagefile.sys 2 1000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 384.81 Gb Free Space | 82.62% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-ZGULHB9M0R
Current User Name: Dona Roell
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\system32\brss01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\system32\Brmfrmps.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\program files\common files\mcafee\mna\mcnasvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\Mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\system32\sistray.EXE (Silicon Integrated Systems Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SSU.EXE (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Documents and Settings\Dona Roell\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (brmfrmps [Auto | Running]) -- C:\WINDOWS\system32\Brmfrmps.exe (Brother Industries, Ltd.)
SRV - (Brother XP spl Service [Auto | Running]) -- C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IntuitUpdateService [Auto | Running]) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (mcmscsvc [Auto | Running]) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) -- c:\program files\common files\mcafee\mna\mcnasvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (WebrootSpySweeperService [Auto | Running]) -- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (WRConsumerService [Auto | Running]) -- C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )

========== Driver Services (SafeList) ==========

DRV - (brfilt [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\Brfilt.sys (Brother Industries Ltd.)
DRV - (BrSerWDM [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbScn [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (cmpci [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\cmaudio.sys (C-Media Inc)
DRV - (Fasttrak [Boot | Running]) -- C:\WINDOWS\system32\drivers\Fasttrak.sys (Promise Technology, Inc.)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (mf [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\mf.sys (Microsoft Corporation)
DRV - (mfeavfk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MPFP [System | Running]) -- C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (ms_mpu401 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv4 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\nv4.sys (NVIDIA Corporation)
DRV - (pavboot [Boot | Running]) -- C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (rtl8029 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\RTL8029.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SI3112 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\SI3112.sys (Silicon Image, Inc.)
DRV - (SI3112r [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\SI3112r.sys (Silicon Image, Inc)
DRV - (SiFilter [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV - (SiS315 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SiSkp [System | Running]) -- C:\WINDOWS\system32\drivers\srvkp.sys ()
DRV - (ssfs0bbc [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (SSHRMD [Boot | Running]) -- C:\WINDOWS\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (SSIDRV [Boot | Running]) -- C:\WINDOWS\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (SSKBFD [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (tmcomm [Auto | Running]) -- C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (usbbus [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://news.nationalgeographic.com/news/archaeology.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://news.nationalgeographic.com/news/archaeology.html"
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: isreaditlater@ideashower.com:0.9945
FF - prefs.js..extensions.enabledItems: savefileto@mozdev.org:1.3
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/05/25 13:10:49 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/10 12:12:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/25 13:11:57 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape 7.2\Extensions\\Components: C:\PROGRAM FILES\NETSCAPE\NETSCAPE\COMPONENTS [2009/05/18 20:34:45 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape 7.2\Extensions\\Plugins: C:\PROGRAM FILES\NETSCAPE\NETSCAPE\PLUGINS [2009/05/25 13:11:57 | 00,000,000 | ---D | M]

[2008/12/12 10:19:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\mozilla\Extensions
[2008/12/12 10:19:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/28 19:38:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\mozilla\Firefox\Profiles\zfim2gyn.default\extensions
[2009/05/09 15:47:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\mozilla\Firefox\Profiles\zfim2gyn.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/05/09 15:46:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\mozilla\Firefox\Profiles\zfim2gyn.default\extensions\isreaditlater@ideashower.com
[2009/05/09 15:46:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\mozilla\Firefox\Profiles\zfim2gyn.default\extensions\savefileto@mozdev.org
[2009/05/27 18:36:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/04/28 15:01:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/05/25 13:12:14 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/28 15:01:02 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/28 15:01:03 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/06 18:51:10 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/06 18:51:10 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/06 18:51:10 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/06 18:51:10 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/06 18:51:10 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/06 18:51:10 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/06 18:51:10 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (2 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [C-Media Mixer] "C:\WINDOWS\Mixer.exe" /startup (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [IndexSearch] "C:\Program Files\Scansoft\PaperPort\IndexSearch.exe" ()
O4 - HKLM..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [NWEReboot] File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SiS KHooker] "C:\WINDOWS\system32\khooker.exe" (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SiS Tray] "C:\WINDOWS\system32\sistray.EXE" (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray (Webroot Software, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" (Adobe Systems Incorporated)
O4 - HKCU..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe" (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [P2kAutostart] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Reg Error: Key error. File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\windows\system32\bisomasu.dll) - c:\windows\system32\bisomasu.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\rqRIxuTN: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\xmjtnzpc: DllName - C:\Documents and Settings\Dona Roell\Application Data\xmjtnzpc.dll - C:\Documents and Settings\Dona Roell\Application Data\xmjtnzpc.dll File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\System32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (oft) - File not found
O30 - LSA: Authentication Packages - © - File not found
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (ecurity) - File not found
O30 - LSA: Security Packages - (Packages) - File not found
O30 - LSA: Security Packages - (settings...) - File not found
O30 - LSA: Security Packages - (gs) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/02/11 14:42:17 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2002/03/17 08:32:34 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.NU4 -- [ NTFS ]
O32 - AutoRun File - [2001/07/24 14:15:36 | 00,000,044 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{57023d58-d5be-11dd-9a0a-0050ba548a7c}\Shell - "" = AutoRun
O33 - MountPoints2\{57023d58-d5be-11dd-9a0a-0050ba548a7c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{57023d58-d5be-11dd-9a0a-0050ba548a7c}\Shell\AutoRun\command - "" = D:\USBAutoRun.exe -- File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/29 10:26:06 | 00,000,000 | ---D | M]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/05/29 10:26:05 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dona Roell\Desktop\OTL.exe
[2009/05/28 07:49:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dona Roell\Desktop\avz4
[2009/05/27 18:46:54 | 00,359,883 | ---- | C] () -- C:\Documents and Settings\Dona Roell\Desktop\dds.scr
[2009/05/27 09:42:30 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/05/27 08:27:29 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/05/27 08:27:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/05/27 08:08:33 | 00,000,194 | -H-- | C] () -- C:\aaw7boot.cmd
[2009/05/27 05:06:24 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/05/27 05:01:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2009/05/27 05:00:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/05/26 12:12:35 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys
[2009/05/26 12:10:56 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2009/05/25 18:30:21 | 00,102,664 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/05/25 17:55:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2009/05/25 13:20:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dona Roell\Application Data\OpenOffice.org
[2009/05/25 13:12:43 | 00,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2009/05/25 12:31:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dona Roell\Application Data\NwDocx
[2009/05/23 19:22:12 | 00,006,144 | -HS- | C] () -- C:\WINDOWS\System32\access.ctl
[2009/05/23 09:43:27 | 00,001,741 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2009/05/23 09:43:24 | 00,001,669 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2009/05/19 20:41:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dona Roell\Desktop\repair
[2009/05/15 07:52:20 | 00,186,368 | ---- | C] () -- C:\Documents and Settings\Dona Roell\Desktop\Z03_ORMR7497_04_SE_SIDX.doc
[2009/05/10 11:39:27 | 00,000,000 | ---D | C] -- C:\Program Files\Restore My Files Data Recovery v6.01
[2009/05/07 20:31:02 | 00,030,208 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\HIST_2110_Exam_4_Study_Guide_Spring_2009.doc
[2009/01/26 08:41:30 | 00,000,000 | -HS- | C] () -- C:\WINDOWS\System32\sajuyaya.dll
[2009/01/26 08:41:30 | 00,000,000 | -HS- | C] () -- C:\WINDOWS\System32\bisomasu.dll
[2008/12/07 22:25:56 | 00,031,088 | ---- | C] () -- C:\WINDOWS\System32\wrLZMA.dll
[2008/02/24 23:09:25 | 00,000,102 | ---- | C] () -- C:\WINDOWS\VSWizard.ini
[2008/02/24 19:58:48 | 00,000,000 | ---- | C] () -- C:\WINDOWS\khooker.INI
[2008/02/24 19:55:04 | 00,008,576 | R--- | C] () -- C:\WINDOWS\System32\drivers\srvkp.sys
[2008/02/24 19:51:30 | 00,039,632 | ---- | C] () -- C:\WINDOWS\System32\sunistlog.ini
[2008/02/24 19:51:29 | 00,148,250 | ---- | C] () -- C:\WINDOWS\System32\2_ssetup.ini
[2008/02/24 19:51:29 | 00,095,603 | ---- | C] () -- C:\WINDOWS\System32\1_ssetup.ini
[2007/03/03 16:20:46 | 00,000,021 | ---- | C] () -- C:\WINDOWS\PI5_SETUP.ini
[2006/11/05 18:09:10 | 00,000,051 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2006/11/05 18:03:40 | 00,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2006/11/05 18:03:09 | 00,002,239 | ---- | C] () -- C:\WINDOWS\BRMFBIDI.INI
[2006/11/05 18:02:50 | 00,000,419 | ---- | C] () -- C:\WINDOWS\brwmark.ini
[2006/11/05 18:02:50 | 00,000,267 | ---- | C] () -- C:\WINDOWS\Brpcfx.ini
[2006/11/05 18:02:50 | 00,000,079 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2006/11/05 17:58:20 | 00,000,767 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2006/11/02 09:25:30 | 00,684,032 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2006/11/02 09:25:30 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2006/08/22 18:10:11 | 00,000,039 | ---- | C] () -- C:\WINDOWS\pos.ini
[2006/02/16 15:14:37 | 00,010,492 | ---- | C] () -- C:\WINDOWS\cindex.ini
[2006/02/12 19:52:32 | 00,000,028 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/02/11 19:49:28 | 00,684,032 | ---- | C] () -- C:\WINDOWS\libeay32.dll
[2006/02/11 19:49:28 | 00,155,648 | ---- | C] () -- C:\WINDOWS\ssleay32.dll
[2006/02/11 19:34:42 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2006/02/11 19:34:34 | 00,004,331 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2006/02/11 19:33:53 | 00,000,284 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2006/02/11 19:33:53 | 00,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2006/02/11 17:04:29 | 00,040,448 | ---- | C] () -- C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/02/11 17:04:24 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\BJInstaller.dll
[2006/02/11 15:43:39 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/02/11 15:20:55 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2003/01/07 16:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/12 09:19:42 | 00,101,376 | ---- | C] () -- C:\WINDOWS\System32\Welsof32.dll
[2002/01/08 17:57:34 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
[2001/08/23 08:00:00 | 00,000,737 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/23 08:00:00 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\Dona Roell\My Documents\*.tmp files]
[2009/05/29 10:26:06 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dona Roell\Desktop\OTL.exe
[2009/05/29 08:22:07 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/05/29 07:33:14 | 00,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/29 07:32:36 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Dona Roell\Local Settings\desktop.ini
[2009/05/29 07:32:13 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/29 07:32:06 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/29 07:31:37 | 16,101,41696 | -HS- | M] () -- C:\hiberfil.sys
[2009/05/29 03:37:06 | 00,001,654 | ---- | M] () -- C:\WINDOWS\tasks\wrSpySweeper_L77CB2808029C47B3B6D9673FAD5014A9.job
[2009/05/29 03:37:03 | 00,001,490 | ---- | M] () -- C:\WINDOWS\tasks\wrSpySweeperFullSweep.job
[2009/05/27 18:58:07 | 00,359,883 | ---- | M] () -- C:\Documents and Settings\Dona Roell\Desktop\dds.scr
[2009/05/27 08:08:33 | 00,000,194 | -H-- | M] () -- C:\aaw7boot.cmd
[2009/05/27 05:06:25 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/05/26 12:06:58 | 00,001,744 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/26 06:39:46 | 00,300,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/25 18:27:43 | 00,102,664 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/05/24 09:16:00 | 00,122,548 | -HS- | M] () -- C:\Documents and Settings\Dona Roell\Application Data\xmjtnzpc.dlll
[2009/05/23 19:22:12 | 00,006,144 | -HS- | M] () -- C:\WINDOWS\System32\access.ctl
[2009/05/23 09:43:27 | 00,001,741 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2009/05/23 09:43:25 | 00,001,669 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2009/05/15 09:01:20 | 00,010,492 | ---- | M] () -- C:\WINDOWS\cindex.ini
[2009/05/15 07:52:21 | 00,186,368 | ---- | M] () -- C:\Documents and Settings\Dona Roell\Desktop\Z03_ORMR7497_04_SE_SIDX.doc
[2009/05/07 20:31:06 | 00,030,208 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\HIST_2110_Exam_4_Study_Guide_Spring_2009.doc

========== LOP Check ==========

[2009/05/27 09:44:53 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/08/26 18:31:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2008/08/26 18:31:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL
[2008/08/26 18:32:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2008/08/26 18:32:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/02/13 09:26:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intuit
[2009/05/27 05:02:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/04/29 07:02:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/09/25 19:16:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2008/08/26 18:35:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee.com
[2009/05/27 18:38:50 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/08/26 18:39:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive
[2008/08/26 18:39:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/05/27 18:24:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/08/26 18:39:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/08/26 18:39:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2009/05/01 09:00:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/01/27 07:15:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Webroot
[2008/08/26 18:39:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/05/23 09:43:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/05/25 13:20:06 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Dona Roell\Application Data
[2008/08/26 18:58:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Adobe
[2008/08/26 18:58:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\AdobeAUM
[2009/03/01 12:22:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\AdobeUM
[2008/08/26 18:58:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Apple Computer
[2008/08/26 18:58:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\ArcSoft
[2008/08/26 18:58:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Google
[2008/08/26 18:58:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Help
[2008/08/26 18:58:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Identities
[2008/08/26 18:58:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Intuit
[2008/08/26 18:58:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Leadertech
[2008/10/22 08:35:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\LimeWire
[2008/08/26 18:58:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Macromedia
[2009/04/29 07:02:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Malwarebytes
[2009/01/26 21:56:49 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Dona Roell\Application Data\Microsoft
[2008/08/26 18:59:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Mobile Master
[2008/12/12 10:19:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Mozilla
[2008/08/26 19:02:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Netscape
[2009/05/25 12:33:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\NwDocx
[2009/05/25 13:20:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\OpenOffice.org
[2008/08/26 19:02:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Pogo Games
[2008/08/26 19:02:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Snapfish
[2008/08/26 19:02:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Sun
[2009/04/13 08:51:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\U3
[2008/08/26 19:03:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dona Roell\Application Data\Webroot
[2009/05/27 05:06:25 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/05/29 08:22:07 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 08:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2008/03/15 02:32:07 | 00,000,274 | -H-- | M] () -- C:\WINDOWS\Tasks\McDefragTask.job
[2009/03/01 02:02:13 | 00,000,362 | -H-- | M] () -- C:\WINDOWS\Tasks\McQcTask.job
[2009/05/29 07:32:13 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/05/29 03:37:03 | 00,001,490 | ---- | M] () -- C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
[2009/05/29 03:37:06 | 00,001,654 | ---- | M] () -- C:\WINDOWS\Tasks\wrSpySweeper_L77CB2808029C47B3B6D9673FAD5014A9.job

========== Purity Check ==========

< End of report >

#8 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:10:44 AM

Posted 29 May 2009 - 11:07 AM

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O20 - AppInit_DLLs: (c:\windows\system32\bisomasu.dll) - c:\windows\system32\bisomasu.dll ()
    O20 - Winlogon\Notify\rqRIxuTN: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
    O20 - Winlogon\Notify\xmjtnzpc: DllName - C:\Documents and Settings\Dona Roell\Application Data\xmjtnzpc.dll - C:\Documents and Settings\Dona Roell\Application Data\xmjtnzpc.dll File not found
    O33 - MountPoints2\{57023d58-d5be-11dd-9a0a-0050ba548a7c}\Shell\AutoRun\command - "" = D:\USBAutoRun.exe -- File not found
    [2009/01/26 08:41:30 | 00,000,000 | -HS- | C] () -- C:\WINDOWS\System32\sajuyaya.dll
    
    :Commands
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.
================================Malwarebytes' Anti-Malware=================================
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley.
================================Follow up scan=================================
  • Double click on OTL to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTListIt.Txt a This is saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.

Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#9 catybug1012

catybug1012
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:44 AM

Posted 30 May 2009 - 11:53 AM

Yay! No more bad image errors!! I am so happy! Thank you very much!!

Here's the Malwarebytes log :

Malwarebytes' Anti-Malware 1.37
Database version: 2197
Windows 5.1.2600 Service Pack 2

5/30/2009 12:48:07 PM
mbam-log-2009-05-30 (12-48-07).txt

Scan type: Full Scan (C:\|)
Objects scanned: 314980
Time elapsed: 1 hour(s), 56 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



And here is the OCL log:

========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\bisomasu.dll deleted successfully.
LoadLibrary failed for c:\windows\system32\bisomasu.dll
c:\windows\system32\bisomasu.dll NOT unregistered.
c:\windows\system32\bisomasu.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rqRIxuTN\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xmjtnzpc\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57023d58-d5be-11dd-9a0a-0050ba548a7c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57023d58-d5be-11dd-9a0a-0050ba548a7c}\ not found.
File D:\USBAutoRun.exe not found.
LoadLibrary failed for C:\WINDOWS\System32\sajuyaya.dll
C:\WINDOWS\System32\sajuyaya.dll NOT unregistered.
C:\WINDOWS\System32\sajuyaya.dll moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS00B109C8-9DF1-4C7D-B616-EAE373A64D5D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS04513183-2750-43D4-A18F-563B12E4348A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS04ABE543-3ACA-4C2D-A840-8349C92E6CD0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS05656815-98AA-463B-8FAA-D5544C7EEB4D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS065E85BD-29DC-4183-8FAD-341A063F872D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS07E62402-C807-4B5F-8007-D252A5FB851D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS07F08D4B-3331-41FA-88CB-292C56D87A94.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS08DB38B0-8F5A-473C-BE83-81C523E69647.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS09B5A623-EE93-4999-94E2-9A6629FE1709.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS09C145ED-5777-4293-9776-2BEFBAA9635C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS09CCE8F5-7C12-429F-9A5C-9AD9744D3E92.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0B0BE75B-B02D-46DB-A30D-4009D8A1DF4B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0B5072AE-682B-41A7-9353-CB035FE4DD6D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0E41696F-0EF7-47C9-86BD-1C8B036EDED5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0EFCCE63-6AC5-4A6D-94D9-754B96E5D7EF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0F2BC389-2EF8-4401-9094-676C32C2C411.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1053F68E-BB26-4B93-9B53-1725DED24B5D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS12BEB561-7EC5-44D1-A093-9D931EA6BCE9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS15EF7DCB-F5E3-4D90-A149-F2C390F45C5F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS16A9E5A1-FF97-4A47-BEC5-BE64C936F980.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1B3B4F93-8C16-4A81-A4F0-4BBE94B554B0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1BD6FAA5-9309-4A85-ABBD-765DAE4B88D6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1D5FB131-5376-4473-8161-111EDCF08127.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1DDE1E2C-5244-4222-A9C2-8D40CD79FA7A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1E2ACB9E-3AE4-4BAE-894D-FCB4E32F58FB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1E3F16B4-2810-4169-8006-AA06B28EB979.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2194EE6C-0B14-477F-85A7-AAAF9A59A15E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS21DACFD4-FB1B-4598-ADA5-57FE166F72DD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS22643F45-7504-4187-8704-E691D9948284.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS239E766E-4AFF-40A1-A2C8-2E05E275A664.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2423979F-9695-4563-B7A3-89390D3C312D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS24E5B344-2F8D-4F82-B32B-0B103670A88B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS256937AB-5ECF-4CAD-B19A-61B71047F074.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS25759582-A28F-4B69-BC74-E5ED9857EFAE.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS273125EB-AAAC-4D19-B9CE-BFE302D58CB7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS276B930D-5B33-4F78-9453-53414D943F93.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS28C92375-2C34-4DAB-9C04-3F8BCC34B64E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS29B8CDD7-1D15-4212-BB1D-F470E8A9F790.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2D8EC5DC-BCBF-4B16-83D8-97D9CA090E4C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2F2D0CC5-546D-4BC3-92F7-FDAD40108B10.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS30273F28-3BC9-429A-AD9D-515F1EEEDD14.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS307803B9-14DB-4EF8-89BC-5DD7848614DB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS320A1057-48BD-449C-9FA8-B4A1AB93196F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS320CFFAB-0BB2-41DC-B61D-7F78B1080BE0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS353F33B0-0A86-46F7-A265-1AA8935908E6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS37392EAA-3B5E-4063-A2FD-FC0596964EA3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS38B14E92-2044-4CDB-B1AF-738A14B3F3D7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3B4FE2C6-F144-4790-8A38-4DDC95B40539.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3CF69DE7-CD5D-4D30-9359-762D66B1505C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3D9FBC33-3C01-4363-B53C-1F6C282A3EEA.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3E84918F-4DA7-4A14-BE8B-F34BE860E654.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4055E4A4-F942-4CBB-A239-F88A86D34825.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS40BA9581-2CB9-4C4C-9776-9D56C87A2E96.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS42A4ED6F-3193-438D-A1D1-D7985B2F039E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS430E60C3-E68D-4ABC-81D1-758FD7B328B2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS451B7A2B-91EF-41FA-B52F-FAFA827AC4B1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS464FDEE7-85ED-4533-83E9-D742AE843C2E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS46E74945-965E-4E80-A937-FC6E0F4075C0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS490D5ED1-DDDF-43AB-AF38-2F863F68CD91.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4921B5BC-23A9-4219-8936-8F7EE6C48029.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4BFBC434-099D-49F0-8447-7D4DBC2E87D1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4C783EBD-DD8B-48B0-8130-DD1AA9C1C77C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4CE671CC-6413-4E3A-9074-26F7EC12E36C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4D5E2B8E-D1EC-499C-BC81-12E36CCEAAE8.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4E905C73-32ED-4953-A1DB-55753F67166A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4FFBECCD-B45A-4AF0-AFCD-950D105D987D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5025718C-A05C-44FF-8338-84F8CA0AC739.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS523160BC-3498-4697-B197-7AA44AB67D1E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS532BAB9C-2DCC-464C-BB29-4189A0F9D3F0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS541F9971-531D-476B-B43A-C530107248AC.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS54B3C7CA-3A75-4DBF-A381-26F1CCA1611C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS568234A2-0FFF-43BC-B718-71E5DB4DD569.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS56B6B82F-048D-4FA5-8B9F-0AE6B09CDA43.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS56D08FAD-BCFF-45A6-97AE-AF269A724561.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5884CC72-60F5-4513-A500-61D832AA78BB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5B5945EC-C575-471F-A1BE-21BDCEE3EE88.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS625E1016-8F57-4AE1-AA2F-FC68400C0DB1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6326CDFE-3F5B-4572-98E0-72031955C94E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS642B714A-DA79-4477-A66E-060CE3452BDA.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS67482D5C-4F10-4DBC-A321-AD472B271A00.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS67E55AFA-8A15-4E90-BD8F-227B9EF1EDC7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6846435E-32B4-4563-91CE-25DC47BAD76A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS68946CD7-B8DB-4359-9FB1-387A527FCBA5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6B5F4135-013F-4972-941A-155C9CA0BEEF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6C66B2DB-A1D4-419A-ACFA-7E85856DC547.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6C6E5BE0-DA14-43C7-95F8-B5797A73EFA0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6C7C1603-C829-4601-8817-E4D21BAE7FBE.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS709A29CF-7C14-4B89-A316-4F8D8F08996E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7181B861-9BCE-43AE-95AB-AC2DE09BEA9F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS77A821DD-606D-4A7E-A52C-B7508383EA54.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS79B71B76-8B3B-4DE1-AD24-4E85711587A6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7A574763-ACC0-49AC-A17A-8C8640663DF4.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7AF86DB8-2A38-4A64-9265-177BD52770FA.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7BC2E4BA-4DFF-4ABB-ACB7-75052D495F46.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7C4BE944-0CEC-4ADE-8B69-A287496172D9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7D513E3E-4D1E-4C92-9DB3-7B674919D2DB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7DCB9EA3-DF55-4EA3-BE1D-3D79F6399757.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS804A1B8D-5B41-4440-BA6A-E98A32806E67.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8091C2AD-DBA6-47D6-BF81-81616BCD7255.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS80E835F8-514A-4305-AF14-6DA980A9C1B2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS83096CBA-A655-4215-9DAF-B6580995A3B1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8323E583-D631-4434-92FC-F14039EF3517.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS83893B57-6E42-4FF8-92C7-400108871A6F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS83C46248-6181-46FE-8512-CEA13E2FF8A4.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS845AD009-BDC4-428C-9BEF-352A9733325B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8469A83B-94B4-45E5-8395-A5EE85CB15AC.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8543BB62-ABF5-4199-A041-8FD30F87C1BD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS86F6CDE6-9550-40B3-9F40-B2C7CC274F11.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8828BA6F-E4BE-4BB0-AC77-C26E1A89DA14.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS88E3DE7B-6056-4C85-B6E5-38926D49DCF9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8989155D-9241-47C9-A953-85B55E691D4A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8A62559F-49FD-4704-8454-790942DFDC88.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8C25B08A-161D-49CE-83DC-DA53C4892897.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8D03A0C6-A445-4DC2-9B51-F3C4CA0BF4D9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8D3699B6-864B-4EC6-926B-0FE9AC669E08.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8D6FF60F-2088-4E53-8AD4-D30FEC2848D0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8D8EC5F5-C739-4136-98B8-B28659E55055.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8D8F1C70-B8B7-4D80-B901-8C8615AF7214.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8D9F4783-7982-449C-9354-440C12423B83.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS90F89F00-F75A-42EE-9C88-945987DA66C4.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS913A43AB-AA93-4A61-B88A-9B1A192F6823.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS92AD9891-224E-4560-95AE-C04BDF5E4B29.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS92DE7E27-CD18-4B62-9F5F-6DA4EAC6BE5A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9432DDF4-9725-4BBD-B213-B435A25A2FD4.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9450695D-A989-4ECE-BC04-1EAD2FEEF72F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9484112A-A881-4694-A761-9E4AB14E081D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS94B72EF8-5AEF-49AA-AF38-4C82CEDE5CF0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS96187DE2-099C-4AB6-9E7E-43240871786C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS96A99CCE-156D-4BDA-9366-763C9DD5DA7F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS987D36A1-0750-42ED-BAD8-FF4F63359F2A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS992BA5C5-A35C-4DD3-A307-2DFB10622487.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9BAC03C5-645F-4D58-9A90-ABDD85773C64.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9BB1419F-85D2-4FBB-8C1E-0F8CB65C2B2A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9C845EB3-C7B7-481E-9AC4-8A549F806EC3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9CAF8510-47F7-46AD-B7EE-C20B5630F609.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9CDCD6AC-441E-43E8-9BD8-07F537C075FA.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9E08CAB0-2329-4C22-954F-C19B3E3D1FC2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9F78D267-7AE8-4661-95CA-CADC69F7BCDD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA12063B4-8AF9-4B32-8AD9-3E50817A1A01.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA219C2C5-ED16-483B-A1C7-5DEE845124D0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA24FEFAD-235F-44AF-A130-8FB864764298.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA3DEDF10-DB1B-49EF-B604-755FB0A483F1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA3F45CFC-C64C-4EED-B2DC-FFB72E752D1F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA4AA3F7A-4310-408C-96BD-58221E997235.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA4E9C830-AD0E-4242-B6C8-02A5BB1A4F15.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA53D15F0-6CB6-4FA7-A351-338D31B219A0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA563A792-091C-4CA6-84E8-8093595C623E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA64422BA-3F44-4B33-9D59-AB8E53BE4FC5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA92715C0-8505-48F7-8D0D-DA40991C3139.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAAFC26D2-F1A2-4540-B0A9-980BE70B9418.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAB8EFE26-8766-4516-8C97-93CF596198D3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSABA7F76A-64C9-4F58-8CB0-01F88E6BAA50.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAE4C507D-2D8E-4341-8012-16865542AE98.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAF17EE34-7ADE-4B66-8FE0-559048AFFA22.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB081BB2E-41E0-4635-BECC-E8C6D3E87B5C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB1DF916C-E276-40EF-9D43-1E03D89A7CA1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB2286C27-BDB7-42DD-9F83-D89DC733C5AF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB297C70D-9123-4D3B-B76E-DCB5EFA0A0A6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB29815E5-394E-4F0C-9262-37A27378BFA0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB4BE5955-5279-4E67-8EEC-D39D34B2EFF0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB5BA211C-F367-49F7-8102-BC6373F6161B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB5E6BE7E-C77C-44CE-8F8B-146282EDE4EB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB6681E31-3508-4038-8F9F-B4CD94885985.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB8E8D023-6369-44AC-A2D6-CE9DB173E7A8.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBA57118E-89DF-4D80-A23D-263F537D2F90.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBA9E2669-AB6C-4A3E-9826-109057A2C537.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBEC19717-43D9-4F83-BC54-B4D2A7686AD7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBF9D2C55-622E-496C-9C45-FB798598B8A9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBFB74837-D5B8-4390-B753-AFAEC7120B28.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC43FA534-3B4C-4196-BB19-3C1FC8BFA671.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC51DC9BA-D3C0-4971-AF42-52F195A4F40E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC560FE76-DA39-4327-9FE7-BED5178FAA77.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC7170AF9-F4EA-44ED-88E3-C6692D75FB87.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC83D4BA3-3074-4377-8D87-33F9165109CB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSCD63E938-283E-48FC-AB59-ACE135E3B274.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSCE52C8C5-2A65-43DB-BE27-614AAEB37E78.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD31D8FE7-19B1-4761-ACA9-FBEFBA649DAA.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD4D0D35B-F153-48AE-9DF3-BB4FF3DA29F5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD6BA6237-6391-4D3F-A085-F582A0C353F0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD850FC01-8E05-4212-8743-0E4539347FA7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD96A7F26-7BFB-462A-9991-771409BDD4A9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDA17F5B0-A426-47EA-B12D-32AAE4818867.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDAB1A246-EB63-47F7-BB4B-FCCC71BBA696.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDBC07265-8F9F-4EB1-AFDE-2ECDE454312F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDC969902-3125-49B2-A94B-30E0C4050F73.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDE26B063-89A0-4FAB-BB25-8E89750E2DD1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDF40F1C8-4686-4A68-92B2-FB360BC2D08A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE15065DB-5FE1-412F-BF34-2F8C2582F1AD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE17AE3C0-74BF-4B91-A21B-7FD0795ED07D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE1CA1C4E-06BD-4879-8E5F-3133F0D67BD4.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE1D517EA-D5F5-4F0C-9AC7-5D7ECE4B227E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE3D0999B-0CB4-4E70-94E2-A92D396665F8.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE607E082-BD5E-4B13-B481-0E0C163267DF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE6240C70-2754-48B3-B69B-7311A60D0CF9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE9B42883-9957-41DE-BC62-638B304AB8D3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEA1FC96C-545D-47D6-9E9E-D801E04DC8CA.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEA65D85C-9044-4E6C-A765-6DB4599C2685.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEAF04D60-008C-4273-A2C9-A9D475FBD6D6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEEB27376-3DE4-4E38-986A-5FB27E4F44A9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEF4A855F-E05D-43EF-8E5F-D1A253EEC621.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF012B532-EC74-40FF-9312-243F99B9E576.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF15AA5F7-3894-4EE7-AC07-4DF2A879A215.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF5BD3B3A-4EB4-4C04-B549-7A540C10C28E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF7DD5428-8FC3-4758-A11B-9F66BF86F09F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF8291311-2F39-432A-9EB9-EB14C7AA7090.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF9C0A909-F372-4044-B93F-DD4FAF2B6E16.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFA5AEF9A-519F-47A5-B99F-410A5BE94B2A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFD2D8EDE-331A-428F-866E-0DBA4B989A1F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_7mTOe7zb4FYqq3C scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_ZWdEpfBianwFU6c scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_704.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.

OTL by OldTimer - Version 2.1.1.0 log created on 05302009_102807

Files moved on Reboot...
File C:\WINDOWS\temp\wrstemp\SSMS00B109C8-9DF1-4C7D-B616-EAE373A64D5D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS04513183-2750-43D4-A18F-563B12E4348A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS04ABE543-3ACA-4C2D-A840-8349C92E6CD0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS05656815-98AA-463B-8FAA-D5544C7EEB4D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS065E85BD-29DC-4183-8FAD-341A063F872D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS07E62402-C807-4B5F-8007-D252A5FB851D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS07F08D4B-3331-41FA-88CB-292C56D87A94.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS08DB38B0-8F5A-473C-BE83-81C523E69647.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS09B5A623-EE93-4999-94E2-9A6629FE1709.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS09C145ED-5777-4293-9776-2BEFBAA9635C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS09CCE8F5-7C12-429F-9A5C-9AD9744D3E92.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0B0BE75B-B02D-46DB-A30D-4009D8A1DF4B.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0B5072AE-682B-41A7-9353-CB035FE4DD6D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0E41696F-0EF7-47C9-86BD-1C8B036EDED5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0EFCCE63-6AC5-4A6D-94D9-754B96E5D7EF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0F2BC389-2EF8-4401-9094-676C32C2C411.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1053F68E-BB26-4B93-9B53-1725DED24B5D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS12BEB561-7EC5-44D1-A093-9D931EA6BCE9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS15EF7DCB-F5E3-4D90-A149-F2C390F45C5F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS16A9E5A1-FF97-4A47-BEC5-BE64C936F980.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1B3B4F93-8C16-4A81-A4F0-4BBE94B554B0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1BD6FAA5-9309-4A85-ABBD-765DAE4B88D6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1D5FB131-5376-4473-8161-111EDCF08127.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1DDE1E2C-5244-4222-A9C2-8D40CD79FA7A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1E2ACB9E-3AE4-4BAE-894D-FCB4E32F58FB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1E3F16B4-2810-4169-8006-AA06B28EB979.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2194EE6C-0B14-477F-85A7-AAAF9A59A15E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS21DACFD4-FB1B-4598-ADA5-57FE166F72DD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS22643F45-7504-4187-8704-E691D9948284.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS239E766E-4AFF-40A1-A2C8-2E05E275A664.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2423979F-9695-4563-B7A3-89390D3C312D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS24E5B344-2F8D-4F82-B32B-0B103670A88B.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS256937AB-5ECF-4CAD-B19A-61B71047F074.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS25759582-A28F-4B69-BC74-E5ED9857EFAE.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS273125EB-AAAC-4D19-B9CE-BFE302D58CB7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS276B930D-5B33-4F78-9453-53414D943F93.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS28C92375-2C34-4DAB-9C04-3F8BCC34B64E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS29B8CDD7-1D15-4212-BB1D-F470E8A9F790.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2D8EC5DC-BCBF-4B16-83D8-97D9CA090E4C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2F2D0CC5-546D-4BC3-92F7-FDAD40108B10.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS30273F28-3BC9-429A-AD9D-515F1EEEDD14.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS307803B9-14DB-4EF8-89BC-5DD7848614DB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS320A1057-48BD-449C-9FA8-B4A1AB93196F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS320CFFAB-0BB2-41DC-B61D-7F78B1080BE0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS353F33B0-0A86-46F7-A265-1AA8935908E6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS37392EAA-3B5E-4063-A2FD-FC0596964EA3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS38B14E92-2044-4CDB-B1AF-738A14B3F3D7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS3B4FE2C6-F144-4790-8A38-4DDC95B40539.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS3CF69DE7-CD5D-4D30-9359-762D66B1505C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS3D9FBC33-3C01-4363-B53C-1F6C282A3EEA.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS3E84918F-4DA7-4A14-BE8B-F34BE860E654.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4055E4A4-F942-4CBB-A239-F88A86D34825.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS40BA9581-2CB9-4C4C-9776-9D56C87A2E96.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS42A4ED6F-3193-438D-A1D1-D7985B2F039E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS430E60C3-E68D-4ABC-81D1-758FD7B328B2.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS451B7A2B-91EF-41FA-B52F-FAFA827AC4B1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS464FDEE7-85ED-4533-83E9-D742AE843C2E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS46E74945-965E-4E80-A937-FC6E0F4075C0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS490D5ED1-DDDF-43AB-AF38-2F863F68CD91.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4921B5BC-23A9-4219-8936-8F7EE6C48029.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4BFBC434-099D-49F0-8447-7D4DBC2E87D1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4C783EBD-DD8B-48B0-8130-DD1AA9C1C77C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4CE671CC-6413-4E3A-9074-26F7EC12E36C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4D5E2B8E-D1EC-499C-BC81-12E36CCEAAE8.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4E905C73-32ED-4953-A1DB-55753F67166A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4FFBECCD-B45A-4AF0-AFCD-950D105D987D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5025718C-A05C-44FF-8338-84F8CA0AC739.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS523160BC-3498-4697-B197-7AA44AB67D1E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS532BAB9C-2DCC-464C-BB29-4189A0F9D3F0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS541F9971-531D-476B-B43A-C530107248AC.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS54B3C7CA-3A75-4DBF-A381-26F1CCA1611C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS568234A2-0FFF-43BC-B718-71E5DB4DD569.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS56B6B82F-048D-4FA5-8B9F-0AE6B09CDA43.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS56D08FAD-BCFF-45A6-97AE-AF269A724561.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5884CC72-60F5-4513-A500-61D832AA78BB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5B5945EC-C575-471F-A1BE-21BDCEE3EE88.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS625E1016-8F57-4AE1-AA2F-FC68400C0DB1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6326CDFE-3F5B-4572-98E0-72031955C94E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS642B714A-DA79-4477-A66E-060CE3452BDA.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS67482D5C-4F10-4DBC-A321-AD472B271A00.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS67E55AFA-8A15-4E90-BD8F-227B9EF1EDC7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6846435E-32B4-4563-91CE-25DC47BAD76A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS68946CD7-B8DB-4359-9FB1-387A527FCBA5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6B5F4135-013F-4972-941A-155C9CA0BEEF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6C66B2DB-A1D4-419A-ACFA-7E85856DC547.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6C6E5BE0-DA14-43C7-95F8-B5797A73EFA0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6C7C1603-C829-4601-8817-E4D21BAE7FBE.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS709A29CF-7C14-4B89-A316-4F8D8F08996E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7181B861-9BCE-43AE-95AB-AC2DE09BEA9F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS77A821DD-606D-4A7E-A52C-B7508383EA54.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS79B71B76-8B3B-4DE1-AD24-4E85711587A6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7A574763-ACC0-49AC-A17A-8C8640663DF4.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7AF86DB8-2A38-4A64-9265-177BD52770FA.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7BC2E4BA-4DFF-4ABB-ACB7-75052D495F46.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7C4BE944-0CEC-4ADE-8B69-A287496172D9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7D513E3E-4D1E-4C92-9DB3-7B674919D2DB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7DCB9EA3-DF55-4EA3-BE1D-3D79F6399757.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS804A1B8D-5B41-4440-BA6A-E98A32806E67.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8091C2AD-DBA6-47D6-BF81-81616BCD7255.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS80E835F8-514A-4305-AF14-6DA980A9C1B2.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS83096CBA-A655-4215-9DAF-B6580995A3B1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8323E583-D631-4434-92FC-F14039EF3517.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS83893B57-6E42-4FF8-92C7-400108871A6F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS83C46248-6181-46FE-8512-CEA13E2FF8A4.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS845AD009-BDC4-428C-9BEF-352A9733325B.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8469A83B-94B4-45E5-8395-A5EE85CB15AC.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8543BB62-ABF5-4199-A041-8FD30F87C1BD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS86F6CDE6-9550-40B3-9F40-B2C7CC274F11.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8828BA6F-E4BE-4BB0-AC77-C26E1A89DA14.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS88E3DE7B-6056-4C85-B6E5-38926D49DCF9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8989155D-9241-47C9-A953-85B55E691D4A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8A62559F-49FD-4704-8454-790942DFDC88.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8C25B08A-161D-49CE-83DC-DA53C4892897.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8D03A0C6-A445-4DC2-9B51-F3C4CA0BF4D9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8D3699B6-864B-4EC6-926B-0FE9AC669E08.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8D6FF60F-2088-4E53-8AD4-D30FEC2848D0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8D8EC5F5-C739-4136-98B8-B28659E55055.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8D8F1C70-B8B7-4D80-B901-8C8615AF7214.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8D9F4783-7982-449C-9354-440C12423B83.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS90F89F00-F75A-42EE-9C88-945987DA66C4.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS913A43AB-AA93-4A61-B88A-9B1A192F6823.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS92AD9891-224E-4560-95AE-C04BDF5E4B29.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS92DE7E27-CD18-4B62-9F5F-6DA4EAC6BE5A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9432DDF4-9725-4BBD-B213-B435A25A2FD4.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9450695D-A989-4ECE-BC04-1EAD2FEEF72F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9484112A-A881-4694-A761-9E4AB14E081D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS94B72EF8-5AEF-49AA-AF38-4C82CEDE5CF0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS96187DE2-099C-4AB6-9E7E-43240871786C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS96A99CCE-156D-4BDA-9366-763C9DD5DA7F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS987D36A1-0750-42ED-BAD8-FF4F63359F2A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS992BA5C5-A35C-4DD3-A307-2DFB10622487.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9BAC03C5-645F-4D58-9A90-ABDD85773C64.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9BB1419F-85D2-4FBB-8C1E-0F8CB65C2B2A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9C845EB3-C7B7-481E-9AC4-8A549F806EC3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9CAF8510-47F7-46AD-B7EE-C20B5630F609.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9CDCD6AC-441E-43E8-9BD8-07F537C075FA.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9E08CAB0-2329-4C22-954F-C19B3E3D1FC2.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9F78D267-7AE8-4661-95CA-CADC69F7BCDD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA12063B4-8AF9-4B32-8AD9-3E50817A1A01.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA219C2C5-ED16-483B-A1C7-5DEE845124D0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA24FEFAD-235F-44AF-A130-8FB864764298.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA3DEDF10-DB1B-49EF-B604-755FB0A483F1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA3F45CFC-C64C-4EED-B2DC-FFB72E752D1F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA4AA3F7A-4310-408C-96BD-58221E997235.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA4E9C830-AD0E-4242-B6C8-02A5BB1A4F15.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA53D15F0-6CB6-4FA7-A351-338D31B219A0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA563A792-091C-4CA6-84E8-8093595C623E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA64422BA-3F44-4B33-9D59-AB8E53BE4FC5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA92715C0-8505-48F7-8D0D-DA40991C3139.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSAAFC26D2-F1A2-4540-B0A9-980BE70B9418.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSAB8EFE26-8766-4516-8C97-93CF596198D3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSABA7F76A-64C9-4F58-8CB0-01F88E6BAA50.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSAE4C507D-2D8E-4341-8012-16865542AE98.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSAF17EE34-7ADE-4B66-8FE0-559048AFFA22.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB081BB2E-41E0-4635-BECC-E8C6D3E87B5C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB1DF916C-E276-40EF-9D43-1E03D89A7CA1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB2286C27-BDB7-42DD-9F83-D89DC733C5AF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB297C70D-9123-4D3B-B76E-DCB5EFA0A0A6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB29815E5-394E-4F0C-9262-37A27378BFA0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB4BE5955-5279-4E67-8EEC-D39D34B2EFF0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB5BA211C-F367-49F7-8102-BC6373F6161B.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB5E6BE7E-C77C-44CE-8F8B-146282EDE4EB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB6681E31-3508-4038-8F9F-B4CD94885985.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB8E8D023-6369-44AC-A2D6-CE9DB173E7A8.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBA57118E-89DF-4D80-A23D-263F537D2F90.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBA9E2669-AB6C-4A3E-9826-109057A2C537.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBEC19717-43D9-4F83-BC54-B4D2A7686AD7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBF9D2C55-622E-496C-9C45-FB798598B8A9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBFB74837-D5B8-4390-B753-AFAEC7120B28.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSC43FA534-3B4C-4196-BB19-3C1FC8BFA671.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSC51DC9BA-D3C0-4971-AF42-52F195A4F40E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSC560FE76-DA39-4327-9FE7-BED5178FAA77.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSC7170AF9-F4EA-44ED-88E3-C6692D75FB87.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSC83D4BA3-3074-4377-8D87-33F9165109CB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSCD63E938-283E-48FC-AB59-ACE135E3B274.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSCE52C8C5-2A65-43DB-BE27-614AAEB37E78.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD31D8FE7-19B1-4761-ACA9-FBEFBA649DAA.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD4D0D35B-F153-48AE-9DF3-BB4FF3DA29F5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD6BA6237-6391-4D3F-A085-F582A0C353F0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD850FC01-8E05-4212-8743-0E4539347FA7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD96A7F26-7BFB-462A-9991-771409BDD4A9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDA17F5B0-A426-47EA-B12D-32AAE4818867.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDAB1A246-EB63-47F7-BB4B-FCCC71BBA696.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDBC07265-8F9F-4EB1-AFDE-2ECDE454312F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDC969902-3125-49B2-A94B-30E0C4050F73.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDE26B063-89A0-4FAB-BB25-8E89750E2DD1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDF40F1C8-4686-4A68-92B2-FB360BC2D08A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE15065DB-5FE1-412F-BF34-2F8C2582F1AD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE17AE3C0-74BF-4B91-A21B-7FD0795ED07D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE1CA1C4E-06BD-4879-8E5F-3133F0D67BD4.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE1D517EA-D5F5-4F0C-9AC7-5D7ECE4B227E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE3D0999B-0CB4-4E70-94E2-A92D396665F8.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE607E082-BD5E-4B13-B481-0E0C163267DF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE6240C70-2754-48B3-B69B-7311A60D0CF9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE9B42883-9957-41DE-BC62-638B304AB8D3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEA1FC96C-545D-47D6-9E9E-D801E04DC8CA.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEA65D85C-9044-4E6C-A765-6DB4599C2685.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEAF04D60-008C-4273-A2C9-A9D475FBD6D6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEEB27376-3DE4-4E38-986A-5FB27E4F44A9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEF4A855F-E05D-43EF-8E5F-D1A253EEC621.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF012B532-EC74-40FF-9312-243F99B9E576.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF15AA5F7-3894-4EE7-AC07-4DF2A879A215.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF5BD3B3A-4EB4-4C04-B549-7A540C10C28E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF7DD5428-8FC3-4758-A11B-9F66BF86F09F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF8291311-2F39-432A-9EB9-EB14C7AA7090.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF9C0A909-F372-4044-B93F-DD4FAF2B6E16.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSFA5AEF9A-519F-47A5-B99F-410A5BE94B2A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSFD2D8EDE-331A-428F-866E-0DBA4B989A1F.tmp not found!
File C:\WINDOWS\temp\mcmsc_7mTOe7zb4FYqq3C not found!
File C:\WINDOWS\temp\mcmsc_ZWdEpfBianwFU6c not found!
File C:\WINDOWS\temp\Perflib_Perfdata_704.dat not found!

Registry entries deleted on Reboot...

*****

#10 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:10:44 AM

Posted 30 May 2009 - 12:00 PM

You are welcome :thumbup2:
  • Double click on OTL to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTListIt.Txt a This is saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
Also let me know of any other issues you may be having.
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users