ntuser.dll calc.dll error messages

Page 1 of 2 1, 2  Next

View previous topic View next topic Go down

ntuser.dll calc.dll error messages

Post by joffreyj on Sun 18 Jul 2010, 6:46 am

You guys rock, what a community service. Log contents are below.

When I start up I get a rundll32.exe bad image for ntuser.dll

I also get an error that calc.dll cannot be loaded.

Thanks
========OTL.txt
OTL logfile created on: 7/17/2010 3:28:03 PM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Christina Lovvorn\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 609.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.48 Gb Total Space | 40.02 Gb Free Space | 57.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CLOVVORN
Current User Name: Christina Lovvorn
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/07/17 15:27:55 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Christina Lovvorn\Desktop\OTL1.exe
PRC - [2010/01/22 08:56:24 | 000,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2008/04/24 13:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
PRC - [2008/04/24 13:25:22 | 000,202,560 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
PRC - [2008/02/29 10:20:32 | 000,893,952 | ---- | M] () -- C:\Program Files\Bellsouth\HelpCenter\SSGet.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/12/28 13:04:56 | 000,262,217 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
PRC - [2005/12/28 12:56:16 | 000,602,182 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2005/12/28 12:55:40 | 000,667,718 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2005/12/28 12:52:32 | 000,397,381 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2005/12/28 12:47:10 | 000,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2005/12/28 12:45:02 | 000,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2005/12/28 12:44:24 | 000,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2005/11/16 22:35:16 | 000,397,312 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2005/11/11 16:43:04 | 000,548,864 | ---- | M] (McAfee Corporation) -- C:\Program Files\McAfee.com\Personal Firewall\MpfService.exe
PRC - [2005/10/24 08:33:04 | 000,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\lxcicoms.exe
PRC - [2005/10/13 19:56:16 | 000,126,976 | ---- | M] (McAfee, Inc) -- c:\Program Files\McAfee.com\Agent\Mcdetect.exe
PRC - [2005/09/30 10:47:22 | 000,200,704 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark 7300 Series\lxcimon.exe
PRC - [2005/08/31 14:14:52 | 001,277,952 | ---- | M] (BellSouth) -- C:\Program Files\Support.com\BellSouth\hcenter.exe
PRC - [2005/08/24 17:01:04 | 000,122,368 | ---- | M] (McAfee, Inc) -- c:\Program Files\McAfee.com\Agent\McTskshd.exe
PRC - [2005/08/01 08:05:04 | 000,094,208 | ---- | M] (Lexmark International Inc.) -- C:\Program Files\Lexmark 7300 Series\ezprint.exe
PRC - [2005/06/10 11:44:02 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2004/04/07 13:07:32 | 001,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
PRC - [2003/10/29 03:06:00 | 000,024,576 | ---- | M] (BVRP Software) -- C:\Program Files\Digital Line Detect\DLG.exe
PRC - [1999/02/01 19:53:24 | 000,405,560 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.EXE


========== Modules (SafeList) ==========

MOD - [2010/07/17 15:27:55 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Christina Lovvorn\Desktop\OTL1.exe
MOD - [2007/04/19 14:21:40 | 000,116,264 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprthook.dll
MOD - [2006/08/25 11:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 06:00:00 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll
MOD - [2004/08/04 06:00:00 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\WINDOWS\System32\PereSvc.exe -- (peresvc)
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\System32\BtwSvc.dll -- (BtwSvc)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\System32\6to4v32.dll -- (6to4)
SRV - [2010/07/12 04:55:38 | 001,352,832 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/03/15 11:50:36 | 001,142,224 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2010/03/11 11:09:22 | 000,366,840 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2010/01/22 08:56:24 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2008/04/24 13:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe -- (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2006/05/08 05:24:54 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV)
SRV - [2006/04/27 18:35:16 | 000,053,337 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - [2006/04/27 18:27:06 | 000,049,241 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2006/04/27 18:16:28 | 000,069,718 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
SRV - [2005/12/28 13:04:56 | 000,262,217 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER) Intel(R)
SRV - [2005/12/28 12:47:10 | 000,540,745 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel(R)
SRV - [2005/12/28 12:45:02 | 000,114,753 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2005/12/28 12:44:24 | 000,217,164 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2005/11/14 02:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005/11/11 16:43:04 | 000,548,864 | ---- | M] (McAfee Corporation) [Auto | Running] -- C:\Program Files\McAfee.com\Personal Firewall\MpfService.exe -- (MpfService)
SRV - [2005/10/24 08:33:04 | 000,491,520 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\System32\lxcicoms.exe -- (lxci_device)
SRV - [2005/10/13 19:56:16 | 000,126,976 | ---- | M] (McAfee, Inc) [Auto | Running] -- c:\Program Files\McAfee.com\Agent\Mcdetect.exe -- (McDetect.exe)
SRV - [2005/10/06 18:12:30 | 000,855,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Media Connect 2\wmccds.exe -- (WMConnectCDS)
SRV - [2005/08/24 17:01:04 | 000,122,368 | ---- | M] (McAfee, Inc) [Auto | Running] -- c:\Program Files\McAfee.com\Agent\McTskshd.exe -- (McTskshd.exe)
SRV - [2005/07/12 19:10:18 | 000,963,072 | ---- | M] (McAfee Inc.) [Auto | Stopped] -- C:\Program Files\McAfee\SpamKiller\MSKSrvr.exe -- (MskService)
SRV - [2005/07/01 20:22:50 | 000,245,760 | ---- | M] (McAfee, Inc) [On_Demand | Stopped] -- C:\Program Files\McAfee.com\Agent\mcupdmgr.exe -- (mcupdmgr.exe)
SRV - [2004/04/07 13:07:32 | 001,135,728 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -- (AOL ACS)


========== Driver Services (SafeList) ==========

DRV - [2010/07/12 04:55:39 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010/03/29 10:06:14 | 000,218,592 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/04/14 15:11:49 | 000,008,552 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2005/12/28 14:22:08 | 000,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2005/12/04 17:55:30 | 001,428,096 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel(R)
DRV - [2005/11/29 19:36:56 | 000,191,936 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2005/11/16 22:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2005/11/11 16:43:52 | 000,080,640 | ---- | M] (McAfee) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\MpFirewall.sys -- (MPFIREWL)
DRV - [2005/10/14 16:40:18 | 000,307,968 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/10/14 16:40:18 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/10/14 16:40:18 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/08/12 17:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/08/10 12:22:10 | 000,114,464 | ---- | M] (McAfee Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\naiavf5x.sys -- (NaiAvFilter1)
DRV - [2005/08/05 17:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 04:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 04:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 04:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004/12/06 02:05:00 | 000,100,603 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudfa.sys -- (tfsnudfa)
DRV - [2004/12/06 02:05:00 | 000,098,714 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudf.sys -- (tfsnudf)
DRV - [2004/12/06 02:05:00 | 000,086,586 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnifs.sys -- (tfsnifs)
DRV - [2004/12/06 02:05:00 | 000,034,843 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsncofs.sys -- (tfsncofs)
DRV - [2004/12/06 02:05:00 | 000,025,883 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnboio.sys -- (tfsnboio)
DRV - [2004/12/06 02:05:00 | 000,015,227 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnopio.sys -- (tfsnopio)
DRV - [2004/12/06 02:05:00 | 000,006,363 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnpool.sys -- (tfsnpool)
DRV - [2004/12/06 02:05:00 | 000,004,123 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndrct.sys -- (tfsndrct)
DRV - [2004/12/06 02:05:00 | 000,002,239 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndres.sys -- (tfsndres)
DRV - [2004/12/01 04:22:00 | 000,087,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)
DRV - [2004/11/23 03:56:00 | 000,040,480 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\drvnddm.sys -- (drvnddm)
DRV - [2004/11/22 18:36:39 | 000,018,003 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRENDIS5.sys -- (MRENDIS5)
DRV - [2004/08/12 18:45:54 | 000,137,728 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004/08/04 06:00:00 | 000,002,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\isapeep.sys -- (isapeep)
DRV - [2004/08/04 00:07:44 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2004/08/04 00:07:44 | 000,041,088 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2004/08/03 23:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/07/14 12:29:04 | 000,005,627 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\sscdbhk5.sys -- (sscdbhk5)
DRV - [2004/07/14 12:28:50 | 000,023,545 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\ssrtln.sys -- (ssrtln)
DRV - [2004/02/13 17:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
DRV - [2003/01/10 17:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 15:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 14:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = [You must be registered and logged in to see this link.]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = [You must be registered and logged in to see this link.]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2010/07/17 13:57:17 | 000,000,000 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (McAfee VirusScan) - {BA52B914-B692-46c4-B683-905236F6F655} - c:\Program Files\McAfee.com\VSO\mcvsshl.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [calc] C:\WINDOWS\System32\calc.DLL File not found
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 7300 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [lxcimon.exe] C:\Program Files\Lexmark 7300 Series\lxcimon.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAGE~1.EXE File not found
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShowLOMControl] Reg Error: Invalid data type. File not found
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [tgcmd] C:\Program Files\Support.com\BellSouth\hcenter.exe (BellSouth)
O4 - HKLM..\Run: [VSOCheckTask] C:\Program Files\McAfee.com\VSO\mcmnhdlr.exe (McAfee, Inc.)
O4 - HKCU..\Run: [calc] C:\Documents and Settings\NetworkService\ntuser.dll ()
O4 - HKCU..\Run: [Download] C:\Program Files\Bellsouth\HelpCenter\ssGet.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\Program Files\McAfee\SpamKiller\McApfBHO.dll (McAfee, Inc.)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} [You must be registered and logged in to see this link.] (SupportSoft External Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} [You must be registered and logged in to see this link.] (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [You must be registered and logged in to see this link.] (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.4.2_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} [You must be registered and logged in to see this link.] (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - AppInit_DLLs: (pabinula.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Christina Lovvorn\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Christina Lovvorn\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: BtwSvc - C:\WINDOWS\System32\BtwSvc.dll File not found
NetSvcs: BtwSrv - File not found
NetSvcs: 6to4 - C:\WINDOWS\System32\6to4v32.dll File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found


SafeBootMin: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe ()

SafeBootNet: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe ()

ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4b218e3e-bc98-4770-93d3-2731b9329278} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {8D1D0E9A-C799-4D28-9E29-0061D1E66E43} - Microsoft .NET Framework 1.1 Hotfix (KB928366)
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: Microsoft Base Smart Card Crypto Provider Package -

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.MP42 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (58560350072602624)

========== Files/Folders - Created Within 30 Days ==========

[2010/07/17 15:27:35 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Christina Lovvorn\Desktop\OTL1.exe
[2010/07/17 13:25:31 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2010/07/17 13:25:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2010/07/17 13:25:26 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/07/17 13:15:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Christina Lovvorn\Local Settings\Application Data\Sunbelt Software
[2010/07/17 13:14:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/07/17 13:13:40 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010/07/17 13:13:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/07/17 11:43:48 | 000,149,456 | ---- | C] (PC Tools) -- C:\WINDOWS\SGDetectionTool.dll
[2010/07/17 11:43:47 | 001,652,688 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll
[2010/07/17 11:43:47 | 000,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDRes.dll
[2010/07/17 11:38:33 | 000,233,136 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/07/17 11:38:28 | 000,218,592 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/07/17 11:38:28 | 000,088,040 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/07/17 11:38:16 | 000,063,360 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/07/17 11:38:03 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/07/17 11:38:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/07/17 11:38:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Christina Lovvorn\Application Data\PC Tools
[2010/07/17 11:38:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/07/17 11:37:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/17 05:34:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla Firefox
[2006/09/19 19:43:34 | 001,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\lxciserv.dll
[2006/09/19 19:43:34 | 001,122,304 | ---- | C] ( ) -- C:\WINDOWS\System32\lxciusb1.dll
[2006/09/19 19:43:33 | 000,630,784 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcipmui.dll
[2006/09/19 19:43:33 | 000,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\lxciprox.dll
[2006/09/19 19:43:33 | 000,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcipplc.dll
[2006/09/19 19:43:32 | 000,770,048 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcihbn3.dll
[2006/09/19 19:43:32 | 000,704,512 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcicomc.dll
[2006/09/19 19:43:32 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcicomm.dll
[2006/09/19 19:43:31 | 000,491,520 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcilmpm.dll
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Documents and Settings\Christina Lovvorn\My Documents\*.tmp files -> C:\Documents and Settings\Christina Lovvorn\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/17 15:27:55 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Christina Lovvorn\Desktop\OTL1.exe
[2010/07/17 15:25:18 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/17 15:25:16 | 000,144,480 | ---- | M] () -- C:\WINDOWS\System32\Status.MPF
[2010/07/17 15:24:47 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/17 15:24:35 | 1063,714,816 | -HS- | M] () -- C:\hiberfil.sys
[2010/07/17 15:24:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/17 15:23:34 | 003,145,728 | ---- | M] () -- C:\Documents and Settings\Christina Lovvorn\ntuser.dat
[2010/07/17 15:23:34 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Christina Lovvorn\ntuser.ini
[2010/07/17 15:00:01 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\mtualzhg.job
[2010/07/17 15:00:00 | 000,000,334 | ---- | M] () -- C:\WINDOWS\tasks\nhshziok.job
[2010/07/17 14:18:16 | 000,574,976 | ---- | M] () -- C:\Documents and Settings\Christina Lovvorn\Desktop\OTL.exe
[2010/07/17 13:53:12 | 000,006,456 | -H-- | M] () -- C:\WINDOWS\System32\febumigo
[2010/07/17 13:40:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/07/17 13:29:28 | 000,000,000 | ---- | M] () -- C:\WINDOWS\ohitacok.dll
[2010/07/17 13:25:26 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/07/17 13:14:16 | 000,000,885 | ---- | M] () -- C:\Documents and Settings\Christina Lovvorn\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/07/17 13:14:16 | 000,000,867 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/07/17 11:58:12 | 000,025,600 | ---- | M] () -- C:\WINDOWS\System32\reader_s.exe82
[2010/07/17 11:58:00 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Christina Lovvorn\reader_s.exe58
[2010/07/17 11:38:24 | 000,001,637 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/07/17 11:37:18 | 007,672,527 | ---- | M] (ATT Internet Services ) -- C:\Documents and Settings\Christina Lovvorn\HC43SInstaller.exe
[2010/07/17 11:35:26 | 000,000,000 | ---- | M] () -- C:\WINDOWS\agesaxovesebevax.dll
[2010/07/17 11:35:20 | 000,025,600 | ---- | M] () -- C:\WINDOWS\System32\reader_s.exe113
[2010/07/17 11:35:12 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Christina Lovvorn\reader_s.exe87
[2010/07/17 11:34:58 | 000,025,600 | ---- | M] () -- C:\WINDOWS\sysguard.exe85
[2010/07/17 11:22:39 | 000,025,600 | ---- | M] () -- C:\WINDOWS\System32\reader_s.exe616
[2010/07/17 11:22:22 | 000,025,600 | ---- | M] () -- C:\Documents and Settings\Christina Lovvorn\reader_s.exe595
[2010/07/17 11:22:20 | 000,025,600 | ---- | M] () -- C:\WINDOWS\sysguard.exe593
[2010/07/12 04:55:39 | 000,064,288 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Documents and Settings\Christina Lovvorn\My Documents\*.tmp files -> C:\Documents and Settings\Christina Lovvorn\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/17 14:18:14 | 000,574,976 | ---- | C] () -- C:\Documents and Settings\Christina Lovvorn\Desktop\OTL.exe
[2010/07/17 13:29:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ohitacok.dll
[2010/07/17 13:26:12 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/07/17 13:14:16 | 000,000,885 | ---- | C] () -- C:\Documents and Settings\Christina Lovvorn\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/07/17 13:14:16 | 000,000,867 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/07/17 12:00:17 | 000,000,296 | ---- | C] () -- C:\WINDOWS\tasks\mtualzhg.job
[2010/07/17 11:43:48 | 001,152,444 | ---- | C] () -- C:\WINDOWS\UDB.zip
[2010/07/17 11:43:48 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2010/07/17 11:43:48 | 000,000,882 | ---- | C] () -- C:\WINDOWS\RegSDImport.xml
[2010/07/17 11:43:48 | 000,000,879 | ---- | C] () -- C:\WINDOWS\RegISSImport.xml
[2010/07/17 11:43:48 | 000,000,131 | ---- | C] () -- C:\WINDOWS\IDB.zip
[2010/07/17 11:38:33 | 000,007,387 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctgntdi.cat
[2010/07/17 11:38:28 | 000,007,412 | ---- | C] () -- C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2010/07/17 11:38:28 | 000,007,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctcore.cat
[2010/07/17 11:38:24 | 000,001,637 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/07/17 11:38:16 | 000,007,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctplsg.cat
[2010/07/17 11:35:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\agesaxovesebevax.dll
[2010/04/17 12:00:12 | 000,096,768 | -HS- | C] () -- C:\WINDOWS\System32\bazoveza.dll
[2010/04/17 12:00:12 | 000,065,024 | -HS- | C] () -- C:\WINDOWS\System32\bewijeze.dll
[2010/04/17 12:00:12 | 000,057,344 | -HS- | C] () -- C:\WINDOWS\System32\limowuyu.dll
[2009/10/22 18:40:21 | 000,039,424 | -HS- | C] () -- C:\WINDOWS\System32\tubevare.dll
[2009/10/22 18:40:20 | 000,091,648 | -HS- | C] () -- C:\WINDOWS\System32\mujoviku.dll
[2009/10/22 18:25:23 | 000,015,000 | ---- | C] () -- C:\WINDOWS\System32\p50dk.dll
[2009/10/22 18:03:24 | 000,015,000 | ---- | C] () -- C:\WINDOWS\System32\p77jx.dll
[2009/09/08 00:01:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Ransom.INI
[2009/07/22 18:25:29 | 000,052,224 | -HS- | C] () -- C:\WINDOWS\System32\wosawamu.dll
[2009/07/09 13:30:57 | 000,097,484 | ---- | C] () -- C:\WINDOWS\System32\drivers\e602a061.sys
[2009/07/06 16:54:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PhantomOfVenice.INI
[2009/01/22 23:18:23 | 000,036,352 | ---- | C] () -- C:\WINDOWS\System32\efcCssPH.dll
[2008/12/31 12:13:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CastleMalloy.INI
[2008/12/18 10:43:22 | 000,034,816 | ---- | C] () -- C:\WINDOWS\System32\iifcYpqQ.dll
[2008/09/29 10:38:58 | 000,062,164 | -HS- | C] () -- C:\WINDOWS\System32\zelayira(2).dll
[2008/09/29 10:38:46 | 000,098,937 | -HS- | C] () -- C:\WINDOWS\System32\zotogogo(2).dll
[2008/06/11 15:12:25 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/02/24 23:07:30 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2006/09/19 19:47:55 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\IPPCPUID.DLL
[2006/09/19 19:47:24 | 000,028,672 | ---- | C] () -- C:\WINDOWS\hookdllX.dll
[2006/09/19 19:47:24 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmsbfn32.dll
[2006/09/19 19:44:10 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\lxcivs.dll
[2006/07/20 17:46:43 | 000,006,048 | ---- | C] () -- C:\WINDOWS\System32\MCC16.dll
[2006/05/21 06:04:47 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\575D6DB162.sys
[2006/05/21 06:04:46 | 000,003,766 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/05/14 16:18:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Game.INI
[2006/05/09 17:16:08 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/05/09 17:16:06 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\BJInstaller.dll
[2006/04/26 09:27:44 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/04/26 09:27:44 | 000,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2006/04/26 09:27:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2006/04/14 15:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/04/14 15:14:20 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/04/14 14:40:42 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/04/14 14:40:28 | 000,000,391 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/04/09 18:04:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 14:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 13:51:11 | 000,002,304 | ---- | C] () -- C:\WINDOWS\System32\isapeep.sys
[2004/08/10 13:51:06 | 000,061,952 | ---- | C] () -- C:\WINDOWS\System32\eventlog.dll
[2004/08/04 06:00:00 | 000,000,005 | ---- | C] () -- C:\WINDOWS\System32\FInstall.sys
[1999/01/22 14:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL

========== Custom Scans ==========


< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/04/29 00:31:46 | 000,357,888 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/04/29 00:31:46 | 000,205,312 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[8 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\*.exe /lockedfiles >
[8 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004/08/10 13:56:46 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004/08/10 13:56:46 | 000,872,448 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.sys >
[2006/05/21 06:05:36 | 000,000,088 | RHS- | M] () -- C:\WINDOWS\system32\575D6DB162.sys
[2004/08/04 06:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2004/08/04 06:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2005/02/07 19:07:08 | 000,004,608 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\DDMI64.sys
[2005/02/09 13:08:04 | 000,007,168 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\DLPT64.sys
[2004/08/04 06:00:00 | 000,000,005 | ---- | M] () -- C:\WINDOWS\system32\FInstall.sys
[2005/02/08 13:04:46 | 000,005,632 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GPCIEn64.sys
[2005/02/08 12:37:52 | 000,007,626 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GPCIEnum.sys
[2005/02/08 15:46:04 | 000,005,120 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GTKCMO64.sys
[2004/06/15 15:55:56 | 000,007,882 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GTKCMOS.sys
[2004/08/04 06:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2004/08/04 06:00:00 | 000,002,304 | ---- | M] () -- C:\WINDOWS\system32\isapeep.sys
[2004/08/04 06:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2004/08/04 06:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2006/05/21 06:05:37 | 000,003,766 | -HS- | M] () -- C:\WINDOWS\system32\KGyGaAvL.sys
[2004/08/04 06:00:00 | 000,032,768 | ---- | M] (woldvciqdbnxkufgorr) -- C:\WINDOWS\system32\lsm32.sys
[2004/08/04 06:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2004/08/04 06:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2004/08/04 06:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2004/08/04 06:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2004/08/04 06:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2004/08/04 06:00:00 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2004/08/04 06:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2004/08/04 06:00:00 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2004/08/04 06:00:00 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2004/08/04 06:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2004/08/04 06:00:00 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2008/09/15 07:57:41 | 001,846,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k(2).sys
[2009/04/17 05:58:57 | 001,846,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[8 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.dll >

< %systemroot%\system32\drivers\*.ini >

< %systemroot%\system32\drivers\*.exe >

< %SYSTEMDRIVE%\*.* >
[2009/07/09 13:30:32 | 000,000,002 | ---- | M] () -- C:\-1330480510
[2004/08/10 14:04:08 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2006/05/09 17:16:17 | 009,977,478 | ---- | M] () -- C:\BellSouthIW.re~
[2006/04/25 14:18:45 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2006/09/19 19:43:14 | 000,000,242 | ---- | M] () -- C:\CDFE.log
[2004/08/10 14:04:08 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2006/04/14 14:46:56 | 000,005,884 | RH-- | M] () -- C:\dell.sdr
[2009/10/22 18:25:31 | 000,250,368 | ---- | M] (Microsoft Corporation) -- C:\dtacmawh.exe
[2010/07/17 15:24:35 | 1063,714,816 | -HS- | M] () -- C:\hiberfil.sys
[2006/07/06 13:17:17 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2006/04/14 15:12:23 | 000,000,829 | -H-- | M] () -- C:\IPH.PH
[2009/10/22 18:25:24 | 000,052,224 | ---- | M] () -- C:\ldvx.exe
[2010/07/17 12:10:31 | 000,000,408 | ---- | M] () -- C:\lxci.log
[2006/09/19 19:43:07 | 000,000,000 | ---- | M] () -- C:\lxcifire.csv
[2006/09/19 19:43:48 | 000,000,867 | ---- | M] () -- C:\LXCIINST.csv
[2009/07/07 16:31:15 | 000,039,436 | ---- | M] () -- C:\lxciscan.log
[2004/08/10 14:04:08 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2006/04/14 15:00:09 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2009/02/09 06:01:52 | 000,341,504 | R--- | M] (Microsoft Corporation) -- C:\ntldrs
[2010/07/17 15:24:33 | 1598,029,824 | -HS- | M] () -- C:\pagefile.sys
[2009/10/22 18:25:38 | 000,050,176 | ---- | M] (user) -- C:\qsdhs.exe
[2006/09/19 19:49:52 | 000,000,172 | ---- | M] () -- C:\setupfax.log
[2006/04/14 15:12:34 | 000,000,071 | ---- | M] () -- C:\SystemInfo.ini
[2009/07/09 13:30:05 | 000,024,576 | ---- | M] () -- C:\vapa.exe
[2006/08/21 17:43:08 | 000,000,000 | ---- | M] () -- C:\wizard.txt
[2009/07/09 13:30:43 | 000,199,296 | ---- | M] () -- C:\xxqkc.exe
[2009/07/09 13:30:59 | 000,025,600 | ---- | M] () -- C:\yiuvab.exe
[4 C:\*.tmp files -> C:\*.tmp -> ]

< %PROGRAMFILES%\*. >
[2008/11/14 10:29:38 | 000,000,000 | ---D | M] -- C:\Program Files\Abbyy FineReader 6.0 Sprint
[2009/10/22 20:15:03 | 000,000,000 | ---D | M] -- C:\Program Files\Active Security
[2006/04/14 15:07:58 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2006/05/21 06:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\America Online 9.0
[2006/04/14 15:12:21 | 000,000,000 | ---D | M] -- C:\Program Files\AOL Companion
[2006/04/14 15:22:38 | 000,000,000 | ---D | M] -- C:\Program Files\BAE
[2007/12/20 14:17:06 | 000,000,000 | ---D | M] -- C:\Program Files\Bellsouth
[2006/04/14 15:05:58 | 000,000,000 | ---D | M] -- C:\Program Files\Broadcom
[2008/03/10 09:28:23 | 000,000,000 | ---D | M] -- C:\Program Files\Comcast
[2010/07/17 11:38:03 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2004/08/10 14:02:08 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2006/04/14 15:03:41 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2006/04/14 15:18:52 | 000,000,000 | ---D | M] -- C:\Program Files\Corel
[2006/04/14 15:19:20 | 000,000,000 | ---D | M] -- C:\Program Files\Corel Corporation
[2006/04/14 15:07:17 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2006/04/14 15:20:00 | 000,000,000 | ---D | M] -- C:\Program Files\Dell
[2008/03/10 09:47:06 | 000,000,000 | ---D | M] -- C:\Program Files\DellSupport
[2006/04/14 15:07:08 | 000,000,000 | ---D | M] -- C:\Program Files\Digital Line Detect
[2006/05/09 19:13:04 | 000,000,000 | ---D | M] -- C:\Program Files\directx
[2006/04/14 15:12:30 | 000,000,000 | ---D | M] -- C:\Program Files\EarthLink Setup
[2008/06/01 20:20:37 | 000,000,000 | ---D | M] -- C:\Program Files\FastAccessDSL
[2006/06/23 10:40:00 | 000,000,000 | ---D | M] -- C:\Program Files\Funcom
[2010/07/17 05:03:47 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2009/01/02 16:24:40 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2006/04/14 15:01:58 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2006/04/14 15:02:36 | 000,000,000 | ---D | M] -- C:\Program Files\Intel, Inc
[2009/06/11 13:34:47 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2006/04/14 15:13:00 | 000,000,000 | ---D | M] -- C:\Program Files\Intuit
[2006/04/14 14:59:58 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/07/17 13:13:40 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2006/04/14 15:12:20 | 000,000,000 | ---D | M] -- C:\Program Files\Learn2.com
[2006/09/19 19:50:01 | 000,000,000 | ---D | M] -- C:\Program Files\Lexmark 7300 Series
[2006/09/19 19:48:03 | 000,000,000 | ---D | M] -- C:\Program Files\Lexmark Applications
[2010/07/17 14:41:55 | 000,000,000 | ---D | M] -- C:\Program Files\LIVEUPDATE
[2010/07/17 11:26:54 | 000,000,000 | ---D | M] -- C:\Program Files\Lx_cats
[2006/04/14 15:22:04 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee
[2006/04/14 15:21:56 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee.com
[2008/08/15 16:38:00 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2004/08/10 14:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2006/04/26 09:25:07 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2006/04/14 15:09:46 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Digital Media Edition
[2006/04/14 15:09:49 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Photo Story 2 LE
[2006/04/26 09:26:07 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio
[2006/04/14 15:06:53 | 000,000,000 | ---D | M] -- C:\Program Files\Modem Helper
[2004/08/10 14:02:30 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2008/08/21 17:04:22 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2004/08/10 14:01:24 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2006/11/20 21:19:55 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2008/08/21 17:05:31 | 000,000,000 | ---D | M] -- C:\Program Files\MUSICMATCH
[2009/09/07 23:42:01 | 000,000,000 | ---D | M] -- C:\Program Files\Nancy Drew
[2004/08/10 14:02:28 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2010/07/17 14:41:59 | 000,000,000 | ---D | M] -- C:\Program Files\NetWaiting
[2006/04/26 19:50:18 | 000,000,000 | ---D | M] -- C:\Program Files\NetZero
[2006/04/14 15:08:10 | 000,000,000 | ---D | M] -- C:\Program Files\NetZeroInstallers
[2006/04/26 19:37:02 | 000,000,000 | ---D | M] -- C:\Program Files\OfficeUpdate11
[2004/08/10 14:01:34 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2007/07/01 13:28:14 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2006/04/14 15:12:18 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2006/04/14 15:11:46 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2006/04/14 15:22:38 | 000,000,000 | ---D | M] -- C:\Program Files\SearchAssist
[2006/04/14 15:03:34 | 000,000,000 | ---D | M] -- C:\Program Files\Sigmatel
[2006/04/26 16:09:33 | 000,000,000 | ---D | M] -- C:\Program Files\Snapshot Viewer
[2006/04/14 15:14:20 | 000,000,000 | ---D | M] -- C:\Program Files\Sonic
[2007/02/24 23:08:38 | 000,000,000 | ---D | M] -- C:\Program Files\Sony
[2007/02/24 23:08:27 | 000,000,000 | ---D | M] -- C:\Program Files\Sony Corporation
[2010/07/17 15:06:45 | 000,000,000 | ---D | M] -- C:\Program Files\Spyware Doctor
[2008/06/03 17:59:08 | 000,000,000 | ---D | M] -- C:\Program Files\Support.com
[2006/04/14 15:05:32 | 000,000,000 | ---D | M] -- C:\Program Files\Synaptics
[2009/01/02 16:24:45 | 000,000,000 | ---D | M] -- C:\Program Files\The Adventure Company
[2004/08/10 14:08:30 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2006/04/14 15:12:19 | 000,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2006/05/09 19:07:00 | 000,000,000 | ---D | M] -- C:\Program Files\Viva Media
[2006/04/14 15:16:28 | 000,000,000 | ---D | M] -- C:\Program Files\WebCyberCoach
[2006/04/26 15:50:51 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2006/04/26 15:54:53 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2004/08/10 14:01:16 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2004/08/10 14:02:52 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2006/04/26 19:39:40 | 000,000,000 | ---D | M] -- C:\Program Files\WinZip
[2006/04/14 15:15:42 | 000,000,000 | ---D | M] -- C:\Program Files\WordPerfect Office 12
[2004/08/10 14:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\xerox

< %appdata%\*.* >
[2009/07/09 13:30:59 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Christina Lovvorn\Application Data\bcrypt.html
[2004/08/10 13:57:42 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Christina Lovvorn\Application Data\desktop.ini
[2009/07/09 13:46:13 | 000,000,012 | ---- | M] () -- C:\Documents and Settings\Christina Lovvorn\Application Data\wiaserva.log
[2009/07/09 13:31:23 | 000,000,008 | ---- | M] () -- C:\Documents and Settings\Christina Lovvorn\Application Data\wiaservg.log


< MD5 for: AGP440.SYS >
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\i386\AGP440.SYS
[2004/08/04 00:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\i386\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: DISK.SYS >
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:disk.sys
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2004/08/04 06:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\i386\disk.sys
[2004/08/04 06:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\system32\drivers\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\disk.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2004/08/04 06:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\i386\eventlog.dll
[2004/08/04 06:00:00 | 000,061,952 | ---- | M] () MD5=F1527490E15F6A1C0DCEB02DF943D74E -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: LOGEVENT.DLL >
[2004/08/04 06:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\logevent.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\sp2qfe\netlogon.dll
[2004/08/04 06:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\i386\netlogon.dll
[2004/08/04 06:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 06:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\i386\scecli.dll
[2004/08/04 06:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll

< MD5 for: USBSTOR.SYS >
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:usbstor.sys
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2004/08/03 23:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\system32\dllcache\usbstor.sys
[2004/08/03 23:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\system32\drivers\USBSTOR.SYS
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\usbstor.sys


joffreyj

Newbie Surfer
Newbie Surfer

Posts : 16
Joined : 2010-07-18
Operating System : windows xp home edition

View user profile

Back to top Go down

Re: ntuser.dll calc.dll error messages

Post by joffreyj on Sun 18 Jul 2010, 6:48 am

==== OTL.txt continued

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-07-26 03:12:56

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$hf_mig$\{29F8DDC1-9487-49b8-B27E-3E0C3C1298FF}] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB912812\KB912812] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB916281\KB916281] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB918899\KB918899] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB920213\KB920213] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB922760\KB922760] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB924496\KB924496] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB925454\KB925454] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB928090\KB928090] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB931768\KB931768] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB931784\KB931784] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB932168\KB932168] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB933566\KB933566] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB937143\KB937143] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB939653\KB939653] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB942615\KB942615] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB943460\KB943460] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB944533\KB944533] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB947864\KB947864] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB960859\KB960859] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB961371\KB961371] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB961371-v2\KB961371-v2] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB968389\KB968389] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB969059\KB969059] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB971557\KB971557] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB971633\KB971633] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB971657\KB971657] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB973346\KB973346] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB973507\KB973507] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB973815\KB973815] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB974112\KB974112] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB974455\KB974455] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB974571\KB974571] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB975025\KB975025] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP343.tmp\ZAP343.tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\temp\temp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\tmp\tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Config\Config] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Connection Wizard\Connection Wizard] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Debug\UserMode\UserMode] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Help\SBSI\Training\WXPPer\Cbz\Cbz] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Help\SBSI\Training\WXPPer\Lib\Lib] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Help\SBSI\Training\WXPPer\Wave\Wave] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\chsime\applets\applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\CHTIME\Applets\Applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imejp\applets\applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imejp98\imejp98] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imjp8_1\applets\applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imkr6_1\applets\applets] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\imkr6_1\dicts\dicts] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ime\shared\res\res] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\1F3B805BA42A0C233B0158879691FE82\2.1.21022\2.1.21022] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\java\classes\classes] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\java\trustlib\trustlib] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\msapps\msinfo\msinfo] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\mui\mui] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\pchealth\ERRORREP\UserDumps\UserDumps] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\pchealth\helpctr\BATCH\BATCH] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\pchealth\helpctr\System\DFS\DFS] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\pchealth\helpctr\Temp\Temp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PIF\PIF] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Registration\CRMLog\CRMLog] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\AuthCabs\AuthCabs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\40fc5c00ee89ac515590995374843d78\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\95b0eb6de61f9c4758f6dd82521ed694\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\10\policy\policy] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\51\msft\msft] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\51\policy\msft\msft] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\msft\msft] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\policy\msft\msft] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\60\msft\msft] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\70\70] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\fa2ebe7f385da369070f93700f340c57\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\5a0d771158cfd69be5ddd26d8f58c73b\5a0d771158cfd69be5ddd26d8f58c73b] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Sun\Java\Deployment\Deployment] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Temp\Google Toolbar\Google Toolbar] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Temp\IW53\IW53] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Temp\MCA37.tmp\MCA37.tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Temp\SaveReport\SaveReport] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Twain32\Twain32] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\WinSxS\InstallTemp\InstallTemp] -> \Device\__max++>\^ -> Mount Point

========== Alternate Data Streams ==========

@Alternate Data Stream - 197 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >

====Extras.txt
OTL Extras logfile created on: 7/17/2010 3:28:03 PM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Christina Lovvorn\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 609.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.48 Gb Total Space | 40.02 Gb Free Space | 57.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CLOVVORN
Current User Name: Christina Lovvorn
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- (America Online, Inc)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- (America Online, Inc.)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 -- (America Online, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- (America Online, Inc)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- (America Online, Inc.)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 -- (America Online, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player
"{06874C62-EC70-4275-9F30-BD81969993A8}" = Nancy Drew: Secret of Shadow Ranch
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{1088F929-91D9-4FD5-8AE8-E9593CD47CD7}" = Nancy Drew: Ransom of the Seven Ships
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{14374619-0900-4056-BA06-C87C900AF9E6}" = QuickBooks Simple Start Special Edition
"{1505D9B1-6037-4310-815A-4D8A212C5075}" = Nancy Drew: The Phantom of Venice
"{1F528948-0E80-4C96-B455-DE4167CB1DF7}" = Internal Network Card Power Management
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{24328842-A29C-4FEA-81D3-1929D3A7F1AE}" = Nancy Drew: Legend of the Crystal Skull
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01
"{3B304631-1355-4A32-BEA0-494DEFB3506D}" = Nancy Drew: The Final Scene
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4AFA5BCB-E113-4FD6-8C28-D8F3FD0100D3}" = Nancy Drew: Secret of the Scarlet Hand
"{5BF2B19D-9C79-492A-8969-F059F06A627F}" = Print to Fax
"{60D8CA34-642C-476F-AB4E-94DECCAEED69}" = The White Wolf of Icicle Creek
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7
"{6c651250-2eb2-11d5-8e33-0050dad72ac2}" = NetZero
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{70D1416D-C0FF-461C-8AF3-71B98C7F5CA4}" = Nancy Drew: Secret of the Old Clock
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{72CD4C5F-AB0B-4814-8780-9A4F26A2086B}" = Presto! PageManager 7.12.02
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{78B55A60-5E51-11D4-A766-00C00C02EDEF}" = Nancy Drew: Message in a Haunted Mansion
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8D107464-7C2D-44E0-8865-628EAD16FB47}" = Nancy Drew: The Haunting of Castle Malloy
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{92D34E42-4C6F-11D5-A76D-006008D256FF}" = Nancy Drew: Treasure in the Royal Tower
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 4.0
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B702CCCE-3176-4DBF-B932-D1B8F402F330}" = Digital Content Portal
"{B79920F8-AB6E-45B2-B257-900BBA969FF7}" = Presto! Forms 3.50.01
"{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters
"{C3D82C0B-3592-4B03-A970-F84C081A8152}" = Nancy Drew: Danger by Design
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D87149B3-7A1D-4548-9CBF-032B791E5908}" = Desktop Doctor
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Search Assist
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{EB7A3B64-1373-48AC-902E-F6643F074E3C}" = Nancy Drew: Last Train to Blue Moon Canyon
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4EC2FB1-4255-4040-8DE6-5D75FA9D039F}" = Nancy Drew: The Creature of Kapu Cave
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"America Online us" = America Online (Choose which version to remove)
"AOL Connectivity Services" = AOL Connectivity Services
"AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en)
"BellSouth" = BellSouth FastAccess DSL Help Center
"Browser Defender_is1" = Browser Defender 2.0.6.15
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Detective Barbie(R)" = Detective Barbie(R)
"InstallShield_{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00
"InstallShield_{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01
"InstallShield_{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters
"Lexmark 7300 Series" = Lexmark 7300 Series
"McAfee Uninstall Utility" = McAfee Uninstaller
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Nancy Drew: Stay Tuned For Danger" = Nancy Drew: Stay Tuned For Danger
"OpenMG HotFix4.5-06-05-10-01" = OpenMG Limited Patch 4.5-06-05-12-01
"ProInst" = Intel(R) PROSet/Wireless Software
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"Spyware Doctor" = Spyware Doctor 7.0
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WGA" = Windows Genuine Advantage Validation Tool
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"WinZip" = WinZip
"WMCSetup" = Windows Media Connect

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/3/2008 3:17:05 PM | Computer Name = CLOVVORN | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0000ec8d.

Error - 6/3/2008 3:18:02 PM | Computer Name = CLOVVORN | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x00000000.

Error - 6/3/2008 3:18:06 PM | Computer Name = CLOVVORN | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0000ec8d.

Error - 6/3/2008 3:18:24 PM | Computer Name = CLOVVORN | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0000ec8d.

Error - 6/3/2008 3:42:09 PM | Computer Name = CLOVVORN | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0000ec8d.

Error - 6/3/2008 3:42:10 PM | Computer Name = CLOVVORN | Source = Application Error | ID = 1000
Description = Faulting application wgatray.exe, version 1.5.532.0, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x0000ec8d.

Error - 6/3/2008 3:42:49 PM | Computer Name = CLOVVORN | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x00000000.

Error - 6/3/2008 3:51:41 PM | Computer Name = CLOVVORN | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0000ec8d.

Error - 6/3/2008 3:51:50 PM | Computer Name = CLOVVORN | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 6/3/2008 5:28:26 PM | Computer Name = CLOVVORN | Source = MsiInstaller | ID = 11925
Description = Product: EarthLink Spyware Blocker -- Error 1925.You do not have sufficient
privileges to complete this installation for all users of the machine. Log on
as an administrator and then retry this installation.

[ System Events ]
Error - 7/17/2010 3:17:31 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7000
Description = The McAfee SpamKiller Server service failed to start due to the following
error: %%1053

Error - 7/17/2010 3:17:31 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7000
Description = The peresvc Service service failed to start due to the following
error: %%2

Error - 7/17/2010 3:22:29 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460

Error - 7/17/2010 3:25:07 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7000
Description = The Lavasoft Ad-Aware Service service failed to start due to the following
error: %%5

Error - 7/17/2010 3:25:07 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7023
Description = The Network Security service terminated with the following error:
%%126

Error - 7/17/2010 3:25:07 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7023
Description = The BtwSvc service terminated with the following error: %%126

Error - 7/17/2010 3:25:07 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the McAfee SpamKiller Server
service to connect.

Error - 7/17/2010 3:25:07 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7000
Description = The McAfee SpamKiller Server service failed to start due to the following
error: %%1053

Error - 7/17/2010 3:25:07 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7000
Description = The peresvc Service service failed to start due to the following
error: %%2

Error - 7/17/2010 3:30:03 PM | Computer Name = CLOVVORN | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460


< End of report >


joffreyj

Newbie Surfer
Newbie Surfer

Posts : 16
Joined : 2010-07-18
Operating System : windows xp home edition

View user profile

Back to top Go down

Re: ntuser.dll calc.dll error messages

Post by Sneakyone on Sun 18 Jul 2010, 2:27 pm

Hi, Welcome to GeekPolice.net!

Looks like quite a infection, it also looks like it has been there for quite a while.

You also have a nasty rootkit called Max++.


  1. Download Win32kDiag from any of the following locations and save it to your Desktop.

    • Download Win32kDiag (Win32kDiag.exe) - #1
    • Download Win32kDiag (Win32kDiag.exe) - #2
    • Download Win32kDiag (Win32kDiag.exe) - #3

  • Double-click Win32kDiag.exe to run Win32kDiag and let it finish.
  • When it states "Finished! Press any key to exit...", press any key on your keyboard to close the program.
  • Double-click on the Win32kDiag.txt file that is located on your Desktop and post the entire contents of that log as a reply to this topic.


  • I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Sun 18 Jul 2010, 8:09 pm

    Running from: C:\Documents and Settings\Christina Lovvorn\Desktop\Win32kDiag.exe

    Log file at : C:\Documents and Settings\Christina Lovvorn\Desktop\Win32kDiag.txt

    WARNING: Could not get backup privileges!

    Searching 'C:\WINDOWS'...



    Found mount point : C:\WINDOWS\$hf_mig$\KB912812\KB912812

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB916281\KB916281

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB918899\KB918899

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB920213\KB920213

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB922760\KB922760

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB924496\KB924496

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB925454\KB925454

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB928090\KB928090

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB931768\KB931768

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB931784\KB931784

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB932168\KB932168

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB933566\KB933566

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB937143\KB937143

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB939653\KB939653

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB942615\KB942615

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB943460\KB943460

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB944533\KB944533

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB947864\KB947864

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB960859\KB960859

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB961371\KB961371

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB961371-v2\KB961371-v2

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB968389\KB968389

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB969059\KB969059

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB971557\KB971557

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB971633\KB971633

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB971657\KB971657

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB973346\KB973346

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB973507\KB973507

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB973815\KB973815

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB974112\KB974112

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB974455\KB974455

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB974571\KB974571

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\KB975025\KB975025

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\$hf_mig$\{29F8DDC1-9487-49b8-B27E-3E0C3C1298FF}

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP343.tmp\ZAP343.tmp

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\assembly\temp\temp

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\assembly\tmp\tmp

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Config\Config

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Debug\UserMode\UserMode

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Cbz\Cbz

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Lib\Lib

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Wave\Wave

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\ime\chsime\applets\applets

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\ime\CHTIME\Applets\Applets

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\ime\imejp\applets\applets

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\ime\imejp98\imejp98

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\ime\imjp8_1\applets\applets

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\ime\imkr6_1\applets\applets

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\ime\imkr6_1\dicts\dicts

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\ime\shared\res\res

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\1F3B805BA42A0C233B0158879691FE82\2.1.21022\2.1.21022

    Mount point destination : \Device\__max++>\^

    Cannot access: C:\WINDOWS\Installer\e3ca7.msi

    [1] 2009-02-09 06:01:52 61440 C:\WINDOWS\Installer\e3ca7.msi ()



    Found mount point : C:\WINDOWS\java\classes\classes

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\java\trustlib\trustlib

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\msapps\msinfo\msinfo

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\mui\mui

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\pchealth\ERRORREP\UserDumps\UserDumps

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\pchealth\helpctr\BATCH\BATCH

    Mount point destination : \Device\__max++>\^

    Cannot access: C:\WINDOWS\pchealth\helpctr\binaries\HelpSvc.exe

    [1] 2004-08-04 06:00:00 743936 C:\WINDOWS\pchealth\helpctr\binaries\HelpSvc.exe ()

    [1] 2008-04-13 20:12:21 744448 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\helpsvc.exe (Microsoft Corporation)



    Found mount point : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\pchealth\helpctr\Temp\Temp

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\PIF\PIF

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\AuthCabs

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\40fc5c00ee89ac515590995374843d78\backup\backup

    Mount point destination : \Device\__max++>\^

    Cannot access: C:\WINDOWS\SoftwareDistribution\Download\40fc5c00ee89ac515590995374843d78\update\update.exe

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB873339\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 18:29:47 654848 C:\WINDOWS\$hf_mig$\KB885250\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB885835\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 11:34:54 654848 C:\WINDOWS\$hf_mig$\KB885836\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB886185\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB887472\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 10:34:54 654848 C:\WINDOWS\$hf_mig$\KB887742\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:48 654848 C:\WINDOWS\$hf_mig$\KB888113\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 14:46:40 654848 C:\WINDOWS\$hf_mig$\KB888302\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB890046\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 19:35:06 718048 C:\WINDOWS\$hf_mig$\KB890859\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB891781\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB893756\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB894391\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896358\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896422\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896423\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896424\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB896428\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB898461\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB899587\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899588\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899591\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB900485\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900725\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900930\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB901017\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB901214\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB902400\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB904706\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB904942\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB905414\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB905749\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB905915\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB908519\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB908531\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB910437\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB911280\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911562\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911567\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911927\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB912919\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB913446\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB913580\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914388\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914389\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB916595\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917159\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB917344\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917422\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917953\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918118\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918439\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB919007\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920214\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB920670\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920683\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920685\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920872\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921398\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921503\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB921883\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB922582\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB922616\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB922819\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923414\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB923561\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB923694\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923980\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924191\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924270\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB925486\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB925902\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB926255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB926436\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927779\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB927802\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927891\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB928255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB928843\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB929123\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB929969\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930178\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930916\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931261\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931836\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB933360\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB933729\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB935839\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB935840\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB936021\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB936357\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938127\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB938464\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938828\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB938829\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941202\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941568\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941644\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941693\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942763\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942840\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943055\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943485\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944338\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944653\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB945553\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB946026\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB946627\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB946648\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB948590\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB948881\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB950749\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950759\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950760\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950762\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB950974\update\update.exe (Microsoft Corporation)

    [1] 2007-12-03 11:25:31 755576 C:\WINDOWS\$hf_mig$\KB951066\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951698\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB951748\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB952004\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB952287\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB952954\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB953838\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB953839\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB954211\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB954600\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB955069\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB955839\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB956391\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956572\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956802\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956841\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB957095\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\$hf_mig$\KB957097\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB958215\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958644\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958687\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB958690\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB959426\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960225\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB960714\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB960715\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB961373\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB961501\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB963027\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB967715\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB968537\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB969897\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB969898\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB970238\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\1d5cae1db1c525dbb30a9177294f0dcc\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\40fc5c00ee89ac515590995374843d78\update\update.exe ()

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\483f9239792ab1dfd6edf3fc484d2eb3\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\4f16665ac0e64727d0b09512c7b6d40c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\58b417d4f9467dc5c1babe51c3278018\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\678162639e69c808c1768ab6340eae25\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\95b0eb6de61f9c4758f6dd82521ed694\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\97f18c7ac91916468f96bb79c87bff6c\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\update\update.exe (Microsoft Corporation)

    [1] 2006-04-03 11:40:12 716000 C:\WINDOWS\SoftwareDistribution\Download\c268348752498f57ff1128ae6a23c4f1\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\cb3326d47d62f5b5e5d5cc4dc6e316c2\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\update\update.exe (Microsoft Corporation)

    [1] 2007-08-10 20:46:20 755576 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\e9ba84652946a0f1afd3e49f8e447c26\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\fa2ebe7f385da369070f93700f340c57\update\update.exe (Microsoft Corporation)



    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\95b0eb6de61f9c4758f6dd82521ed694\backup\backup

    Mount point destination : \Device\__max++>\^

    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Sun 18 Jul 2010, 8:10 pm



    Cannot access: C:\WINDOWS\SoftwareDistribution\Download\97f18c7ac91916468f96bb79c87bff6c\update\update.exe

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB873339\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 18:29:47 654848 C:\WINDOWS\$hf_mig$\KB885250\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB885835\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 11:34:54 654848 C:\WINDOWS\$hf_mig$\KB885836\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB886185\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB887472\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 10:34:54 654848 C:\WINDOWS\$hf_mig$\KB887742\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:48 654848 C:\WINDOWS\$hf_mig$\KB888113\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 14:46:40 654848 C:\WINDOWS\$hf_mig$\KB888302\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB890046\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 19:35:06 718048 C:\WINDOWS\$hf_mig$\KB890859\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB891781\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB893756\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB894391\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896358\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896422\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896423\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896424\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB896428\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB898461\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB899587\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899588\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899591\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB900485\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900725\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900930\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB901017\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB901214\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB902400\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB904706\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB904942\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB905414\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB905749\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB905915\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB908519\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB908531\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB910437\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB911280\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911562\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911567\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911927\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB912919\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB913446\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB913580\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914388\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914389\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB916595\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917159\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB917344\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917422\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917953\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918118\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918439\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB919007\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920214\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB920670\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920683\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920685\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920872\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921398\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921503\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB921883\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB922582\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB922616\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB922819\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923414\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB923561\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB923694\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923980\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924191\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924270\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB925486\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB925902\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB926255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB926436\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927779\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB927802\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927891\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB928255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB928843\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB929123\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB929969\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930178\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930916\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931261\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931836\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB933360\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB933729\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB935839\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB935840\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB936021\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB936357\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938127\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB938464\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938828\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB938829\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941202\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941568\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941644\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941693\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942763\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942840\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943055\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943485\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944338\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944653\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB945553\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB946026\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB946627\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB946648\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB948590\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB948881\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB950749\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950759\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950760\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950762\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB950974\update\update.exe (Microsoft Corporation)

    [1] 2007-12-03 11:25:31 755576 C:\WINDOWS\$hf_mig$\KB951066\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951698\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB951748\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB952004\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB952287\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB952954\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB953838\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB953839\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB954211\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB954600\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB955069\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB955839\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB956391\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956572\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956802\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956841\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB957095\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\$hf_mig$\KB957097\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB958215\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958644\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958687\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB958690\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB959426\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960225\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB960714\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB960715\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB961373\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB961501\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB963027\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB967715\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB968537\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB969897\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB969898\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB970238\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\1d5cae1db1c525dbb30a9177294f0dcc\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\40fc5c00ee89ac515590995374843d78\update\update.exe ()

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\483f9239792ab1dfd6edf3fc484d2eb3\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\4f16665ac0e64727d0b09512c7b6d40c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\58b417d4f9467dc5c1babe51c3278018\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\678162639e69c808c1768ab6340eae25\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\95b0eb6de61f9c4758f6dd82521ed694\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\97f18c7ac91916468f96bb79c87bff6c\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\update\update.exe (Microsoft Corporation)

    [1] 2006-04-03 11:40:12 716000 C:\WINDOWS\SoftwareDistribution\Download\c268348752498f57ff1128ae6a23c4f1\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\cb3326d47d62f5b5e5d5cc4dc6e316c2\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\update\update.exe (Microsoft Corporation)

    [1] 2007-08-10 20:46:20 755576 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\e9ba84652946a0f1afd3e49f8e447c26\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\fa2ebe7f385da369070f93700f340c57\update\update.exe (Microsoft Corporation)



    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\backup\backup

    Mount point destination : \Device\__max++>\^

    Cannot access: C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\update\update.exe

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB873339\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 18:29:47 654848 C:\WINDOWS\$hf_mig$\KB885250\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB885835\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 11:34:54 654848 C:\WINDOWS\$hf_mig$\KB885836\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB886185\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB887472\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 10:34:54 654848 C:\WINDOWS\$hf_mig$\KB887742\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:48 654848 C:\WINDOWS\$hf_mig$\KB888113\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 14:46:40 654848 C:\WINDOWS\$hf_mig$\KB888302\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB890046\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 19:35:06 718048 C:\WINDOWS\$hf_mig$\KB890859\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB891781\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB893756\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB894391\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896358\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896422\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896423\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896424\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB896428\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB898461\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB899587\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899588\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899591\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB900485\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900725\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900930\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB901017\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB901214\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB902400\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB904706\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB904942\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB905414\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB905749\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB905915\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB908519\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB908531\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB910437\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB911280\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911562\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911567\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911927\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB912919\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB913446\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB913580\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914388\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914389\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB916595\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917159\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB917344\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917422\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917953\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918118\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918439\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB919007\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920214\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB920670\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920683\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920685\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920872\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921398\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921503\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB921883\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB922582\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB922616\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB922819\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923414\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB923561\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB923694\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923980\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924191\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924270\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB925486\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB925902\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB926255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB926436\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927779\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB927802\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927891\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB928255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB928843\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB929123\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB929969\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930178\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930916\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931261\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931836\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB933360\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB933729\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB935839\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB935840\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB936021\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB936357\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938127\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB938464\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938828\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB938829\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941202\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941568\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941644\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941693\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942763\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942840\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943055\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943485\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944338\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944653\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB945553\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB946026\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB946627\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB946648\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB948590\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB948881\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB950749\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950759\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950760\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950762\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB950974\update\update.exe (Microsoft Corporation)

    [1] 2007-12-03 11:25:31 755576 C:\WINDOWS\$hf_mig$\KB951066\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951698\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB951748\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB952004\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB952287\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB952954\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB953838\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB953839\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB954211\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB954600\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB955069\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB955839\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB956391\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956572\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956802\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956841\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB957095\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\$hf_mig$\KB957097\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB958215\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958644\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958687\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB958690\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB959426\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960225\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB960714\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB960715\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB961373\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB961501\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB963027\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB967715\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB968537\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB969897\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB969898\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB970238\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\1d5cae1db1c525dbb30a9177294f0dcc\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\40fc5c00ee89ac515590995374843d78\update\update.exe ()

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\483f9239792ab1dfd6edf3fc484d2eb3\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\4f16665ac0e64727d0b09512c7b6d40c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\58b417d4f9467dc5c1babe51c3278018\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\678162639e69c808c1768ab6340eae25\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\95b0eb6de61f9c4758f6dd82521ed694\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\97f18c7ac91916468f96bb79c87bff6c\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\update\update.exe (Microsoft Corporation)

    [1] 2006-04-03 11:40:12 716000 C:\WINDOWS\SoftwareDistribution\Download\c268348752498f57ff1128ae6a23c4f1\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\cb3326d47d62f5b5e5d5cc4dc6e316c2\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\update\update.exe (Microsoft Corporation)

    [1] 2007-08-10 20:46:20 755576 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\e9ba84652946a0f1afd3e49f8e447c26\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\fa2ebe7f385da369070f93700f340c57\update\update.exe (Microsoft Corporation)



    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\10\policy\policy

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\51\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\51\policy\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\policy\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\60\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\70\70

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\fa2ebe7f385da369070f93700f340c57\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\5a0d771158cfd69be5ddd26d8f58c73b\5a0d771158cfd69be5ddd26d8f58c73b

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Temp\Google Toolbar\Google Toolbar

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Temp\IW53\IW53

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Temp\MCA37.tmp\MCA37.tmp

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Temp\SaveReport\SaveReport

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Twain32\Twain32

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp

    Mount point destination : \Device\__max++>\^



    Finished!


    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sneakyone on Mon 19 Jul 2010, 3:33 am

    Hi,

    We need to run the tool with the following command to fix some malware related changes.

    Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK:

    "%userprofile%\desktop\win32kdiag.exe" -f -r

    When it's finished, there will be a log called Win32kDiag.txt on your
    desktop. Please open it with notepad and post the contents here.


    I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Mon 19 Jul 2010, 4:50 am



    Cannot access: C:\WINDOWS\SoftwareDistribution\Download\97f18c7ac91916468f96bb79c87bff6c\update\update.exe

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB873339\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 18:29:47 654848 C:\WINDOWS\$hf_mig$\KB885250\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB885835\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 11:34:54 654848 C:\WINDOWS\$hf_mig$\KB885836\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB886185\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB887472\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 10:34:54 654848 C:\WINDOWS\$hf_mig$\KB887742\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:48 654848 C:\WINDOWS\$hf_mig$\KB888113\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 14:46:40 654848 C:\WINDOWS\$hf_mig$\KB888302\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB890046\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 19:35:06 718048 C:\WINDOWS\$hf_mig$\KB890859\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB891781\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB893756\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB894391\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896358\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896422\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896423\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896424\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB896428\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB898461\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB899587\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899588\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899591\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB900485\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900725\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900930\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB901017\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB901214\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB902400\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB904706\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB904942\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB905414\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB905749\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB905915\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB908519\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB908531\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB910437\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB911280\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911562\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911567\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911927\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB912919\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB913446\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB913580\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914388\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914389\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB916595\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917159\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB917344\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917422\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917953\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918118\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918439\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB919007\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920214\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB920670\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920683\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920685\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920872\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921398\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921503\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB921883\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB922582\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB922616\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB922819\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923414\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB923561\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB923694\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923980\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924191\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924270\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB925486\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB925902\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB926255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB926436\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927779\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB927802\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927891\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB928255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB928843\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB929123\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB929969\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930178\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930916\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931261\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931836\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB933360\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB933729\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB935839\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB935840\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB936021\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB936357\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938127\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB938464\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938828\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB938829\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941202\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941568\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941644\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941693\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942763\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942840\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943055\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943485\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944338\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944653\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB945553\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB946026\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB946627\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB946648\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB948590\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB948881\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB950749\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950759\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950760\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950762\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB950974\update\update.exe (Microsoft Corporation)

    [1] 2007-12-03 11:25:31 755576 C:\WINDOWS\$hf_mig$\KB951066\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951698\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB951748\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB952004\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB952287\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB952954\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB953838\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB953839\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB954211\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB954600\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB955069\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB955839\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB956391\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956572\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956802\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956841\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB957095\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\$hf_mig$\KB957097\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB958215\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958644\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958687\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB958690\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB959426\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960225\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB960714\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB960715\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB961373\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB961501\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB963027\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB967715\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB968537\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB969897\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB969898\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB970238\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\1d5cae1db1c525dbb30a9177294f0dcc\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\40fc5c00ee89ac515590995374843d78\update\update.exe ()

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\483f9239792ab1dfd6edf3fc484d2eb3\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\4f16665ac0e64727d0b09512c7b6d40c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\58b417d4f9467dc5c1babe51c3278018\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\678162639e69c808c1768ab6340eae25\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\95b0eb6de61f9c4758f6dd82521ed694\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\97f18c7ac91916468f96bb79c87bff6c\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\update\update.exe (Microsoft Corporation)

    [1] 2006-04-03 11:40:12 716000 C:\WINDOWS\SoftwareDistribution\Download\c268348752498f57ff1128ae6a23c4f1\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\cb3326d47d62f5b5e5d5cc4dc6e316c2\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\update\update.exe (Microsoft Corporation)

    [1] 2007-08-10 20:46:20 755576 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\e9ba84652946a0f1afd3e49f8e447c26\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\fa2ebe7f385da369070f93700f340c57\update\update.exe (Microsoft Corporation)



    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\backup\backup

    Mount point destination : \Device\__max++>\^

    Cannot access: C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\update\update.exe

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB873339\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 18:29:47 654848 C:\WINDOWS\$hf_mig$\KB885250\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB885835\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 11:34:54 654848 C:\WINDOWS\$hf_mig$\KB885836\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB886185\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:52 654848 C:\WINDOWS\$hf_mig$\KB887472\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 10:34:54 654848 C:\WINDOWS\$hf_mig$\KB887742\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:34:48 654848 C:\WINDOWS\$hf_mig$\KB888113\update\update.exe (Microsoft Corporation)

    [1] 2004-11-30 14:46:40 654848 C:\WINDOWS\$hf_mig$\KB888302\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB890046\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 19:35:06 718048 C:\WINDOWS\$hf_mig$\KB890859\update\update.exe (Microsoft Corporation)

    [1] 2004-10-14 14:21:58 654848 C:\WINDOWS\$hf_mig$\KB891781\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB893756\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB894391\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896358\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896422\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896423\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB896424\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB896428\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB898461\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB899587\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899588\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB899591\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB900485\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900725\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB900930\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB901017\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB901214\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB902400\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB904706\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB904942\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 23:35:05 718048 C:\WINDOWS\$hf_mig$\KB905414\update\update.exe (Microsoft Corporation)

    [1] 2005-02-24 20:35:06 718048 C:\WINDOWS\$hf_mig$\KB905749\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB905915\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB908519\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB908531\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB910437\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB911280\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911562\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911567\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB911927\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB912919\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB913446\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB913580\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914388\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB914389\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB916595\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917159\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB917344\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917422\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB917953\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918118\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB918439\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB919007\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920214\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB920670\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920683\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920685\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB920872\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921398\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB921503\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB921883\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB922582\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB922616\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB922819\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923414\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB923561\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB923694\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB923980\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924191\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB924270\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB925486\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB925902\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB926255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:16:51 716000 C:\WINDOWS\$hf_mig$\KB926436\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927779\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB927802\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB927891\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB928255\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB928843\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB929123\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB929969\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930178\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB930916\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931261\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB931836\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB933360\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:28 716000 C:\WINDOWS\$hf_mig$\KB933729\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB935839\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB935840\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB936021\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB936357\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938127\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB938464\update\update.exe (Microsoft Corporation)

    [1] 2005-10-12 19:12:29 716000 C:\WINDOWS\$hf_mig$\KB938828\update\update.exe (Microsoft Corporation)

    [1] 2006-01-19 15:29:19 716000 C:\WINDOWS\$hf_mig$\KB938829\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941202\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941568\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941644\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB941693\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942763\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB942840\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943055\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB943485\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944338\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB944653\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB945553\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB946026\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB946627\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:20:44 755576 C:\WINDOWS\$hf_mig$\KB946648\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB948590\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:56 716000 C:\WINDOWS\$hf_mig$\KB948881\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\$hf_mig$\KB950749\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950759\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950760\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB950762\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB950974\update\update.exe (Microsoft Corporation)

    [1] 2007-12-03 11:25:31 755576 C:\WINDOWS\$hf_mig$\KB951066\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB951698\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB951748\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB952004\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB952287\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB952954\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB953838\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB953839\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB954211\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB954600\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB955069\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB955839\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB956391\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956572\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB956802\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB956841\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB957095\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\$hf_mig$\KB957097\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB958215\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958644\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 07:18:51 755576 C:\WINDOWS\$hf_mig$\KB958687\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB958690\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB959426\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960225\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB960714\update\update.exe (Microsoft Corporation)

    [1] 2008-11-15 13:18:04 755576 C:\WINDOWS\$hf_mig$\KB960715\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB960803\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB961373\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB961501\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB963027\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB967715\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\$hf_mig$\KB968537\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB969897\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:22 755576 C:\WINDOWS\$hf_mig$\KB969898\update\update.exe (Microsoft Corporation)

    [1] 2007-11-30 08:39:18 755576 C:\WINDOWS\$hf_mig$\KB970238\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\1d5cae1db1c525dbb30a9177294f0dcc\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\40fc5c00ee89ac515590995374843d78\update\update.exe ()

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\483f9239792ab1dfd6edf3fc484d2eb3\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\4f16665ac0e64727d0b09512c7b6d40c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\update\update.exe (Microsoft Corporation)

    [1] 2007-03-05 21:22:59 716000 C:\WINDOWS\SoftwareDistribution\Download\58b417d4f9467dc5c1babe51c3278018\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\678162639e69c808c1768ab6340eae25\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\95b0eb6de61f9c4758f6dd82521ed694\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\97f18c7ac91916468f96bb79c87bff6c\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\update\update.exe (Microsoft Corporation)

    [1] 2008-07-08 09:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\update\update.exe (Microsoft Corporation)

    [1] 2006-04-03 11:40:12 716000 C:\WINDOWS\SoftwareDistribution\Download\c268348752498f57ff1128ae6a23c4f1\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\cb3326d47d62f5b5e5d5cc4dc6e316c2\update\update.exe (Microsoft Corporation)

    [1] 2008-07-09 03:38:29 755576 C:\WINDOWS\SoftwareDistribution\Download\cfb5c33fcc73ed7dcd60250b085691a5\update\update.exe ()

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\update\update.exe (Microsoft Corporation)

    [1] 2007-08-10 20:46:20 755576 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\update\update.exe (Microsoft Corporation)

    [1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\e9ba84652946a0f1afd3e49f8e447c26\update\update.exe (Microsoft Corporation)

    [1] 2009-05-26 07:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\fa2ebe7f385da369070f93700f340c57\update\update.exe (Microsoft Corporation)



    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\10\policy\policy

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\51\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\51\policy\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\policy\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\60\msft\msft

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\70\70

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\fa2ebe7f385da369070f93700f340c57\backup\backup

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\5a0d771158cfd69be5ddd26d8f58c73b\5a0d771158cfd69be5ddd26d8f58c73b

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Temp\Google Toolbar\Google Toolbar

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Temp\IW53\IW53

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Temp\MCA37.tmp\MCA37.tmp

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Temp\SaveReport\SaveReport

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\Twain32\Twain32

    Mount point destination : \Device\__max++>\^

    Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp

    Mount point destination : \Device\__max++>\^



    Finished!


    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sneakyone on Mon 19 Jul 2010, 5:55 am

    Hi,

    Did you do the instructions in post 6?


    I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Mon 19 Jul 2010, 9:29 am

    Sorry think I sent the wrong one.....

    Running from: C:\Documents and Settings\Christina Lovvorn\desktop\win32kdiag.exe

    Log file at : C:\Documents and Settings\Christina Lovvorn\Desktop\Win32kDiag.txt

    Removing all found mount points.

    Attempting to reset file permissions.

    WARNING: Could not get backup privileges!

    Searching 'C:\WINDOWS'...



    Cannot access: C:\WINDOWS\Installer\e3ca7.msi

    Attempting to restore permissions of : C:\WINDOWS\Installer\e3ca7.msi

    [1] 2009-02-09 06:01:52 61440 C:\WINDOWS\Installer\e3ca7.msi ()





    Finished!


    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sneakyone on Mon 19 Jul 2010, 9:33 am

    Hi,

    Please download ComboFix from BleepingComputer.com

    Alternate link: GeeksToGo.com

    Alternate link: Forospyware.com

    Rename ComboFix.exe to commy.exe before you save it to your Desktop
    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
    • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console


    Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.


    I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Mon 19 Jul 2010, 10:25 am

    ComboFix 10-07-16.02 - Christina Lovvorn 07/18/2010 19:07:28.1.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.735 [GMT -4:00]
    Running from: c:\documents and settings\Christina Lovvorn\desktop\commy.exe
    Command switches used :: /stepdel
    AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
    FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    c:\program files\Active Security
    c:\temp\vtmp2
    C:\-1330480510
    c:\docume~1\CHRIST~1\LOCALS~1\Temp\csrss.exe
    c:\documents and settings\All Users\Application Data\98584366.ini
    c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\c.cgm
    c:\documents and settings\Christina Lovvorn\Application Data\bcrypt.html
    c:\documents and settings\Christina Lovvorn\Application Data\wiaserva.log
    c:\documents and settings\Christina Lovvorn\Application Data\wiaservg.log
    c:\documents and settings\Christina Lovvorn\Local Settings\Temporary Internet Files\fbk.sts
    c:\documents and settings\Christina Lovvorn\ntuser.dll
    c:\documents and settings\Christina Lovvorn\reader_s .exe
    c:\documents and settings\Christina Lovvorn\reader_s.exe121
    c:\documents and settings\Christina Lovvorn\reader_s.exe225
    c:\documents and settings\Christina Lovvorn\reader_s.exe595
    c:\documents and settings\Christina Lovvorn\reader_s.exe63
    c:\documents and settings\Christina Lovvorn\reader_s.exe99
    c:\documents and settings\Klovvorn\ntuser.dll
    c:\documents and settings\Klovvorn\reader_s .exe
    c:\documents and settings\Klovvorn\reader_s.exe
    c:\documents and settings\Klovvorn\Start Menu\Programs\Startup\scandisk.dll
    c:\documents and settings\Klovvorn\Start Menu\Programs\Startup\scandisk.lnk
    c:\documents and settings\LocalService\ntuser.dll
    c:\documents and settings\NetworkService\ntuser.dll
    c:\documents and settings\Shu Lovvorn\reader_s .exe
    c:\documents and settings\Shu Lovvorn\reader_s.exe
    C:\dtacmawh.exe
    C:\ldvx.exe
    C:\ntldrs
    c:\program files\Active Security\asecurity.exe
    c:\program files\Active Security\core.cga
    c:\program files\Active Security\help.ico
    c:\program files\Active Security\uninstall.exe
    C:\qsdhs.exe
    c:\windows\444.471
    c:\windows\agesaxovesebevax.dll
    c:\windows\ohitacok.dll
    c:\windows\system32\~.exe
    c:\windows\system32\1119.exe
    c:\windows\system32\bazoveza.dll
    c:\windows\system32\bewijeze.dll
    c:\windows\system32\bszip.dll
    c:\windows\system32\certstore.dat
    c:\windows\system32\config\systemprofile\ntuser.dll
    c:\windows\system32\efcCssPH.dll
    c:\windows\system32\FInstall.sys
    c:\windows\system32\iifcYpqQ.dll
    c:\windows\system32\Install.txt
    c:\windows\system32\isapeep.sys
    c:\windows\system32\limowuyu.dll
    c:\windows\system32\lsm32.sys
    c:\windows\system32\mujoviku.dll
    c:\windows\system32\opear.exe
    c:\windows\system32\opeia.exe
    c:\windows\system32\p50dk.dll
    c:\windows\system32\p77jx.dll
    c:\windows\system32\PowerDes.exe
    c:\windows\system32\spywarewarning2.mht
    c:\windows\system32\tubevare.dll
    c:\windows\system32\wmdtc.exe
    c:\windows\system32\wosawamu.dll
    c:\windows\system32\zelayira(2).dll
    c:\windows\system32\zotogogo(2).dll
    c:\windows\Tasks\mtualzhg.job
    c:\windows\Temp\lsass.exe
    c:\windows\wiaserviv.log
    c:\windows\xpsp1hfm.log

    ----- BITS: Possible infected sites -----

    [You must be registered and logged in to see this link.]
    Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
    Restored copy from - c:\i386\eventlog.dll

    Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected
    Restored copy from - c:\i386\ndis.sys
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_6TO4
    -------\Legacy_BTWSVC
    -------\Legacy_PERESVC
    -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
    -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
    -------\Service_6to4
    -------\Service_BtwSvc
    -------\Service_peresvc
    -------\Legacy_isapeep
    -------\Service_isapeep


    ((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
    .

    2010-07-18 22:56 . 2010-07-18 22:56 0 ----a-r- c:\windows\win32k.sys
    2010-07-17 17:25 . 2010-07-17 17:25 -------- dc----w- c:\windows\system32\DRVSTORE
    2010-07-17 17:25 . 2010-07-12 08:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-07-17 17:25 . 2010-07-17 17:25 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-07-17 17:15 . 2010-07-17 17:15 -------- d-----w- c:\documents and settings\Christina Lovvorn\Local Settings\Application Data\Sunbelt Software
    2010-07-17 17:14 . 2010-07-17 17:14 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
    2010-07-17 17:14 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
    2010-07-17 17:13 . 2010-07-17 17:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-07-17 17:13 . 2010-07-17 17:13 -------- d-----w- c:\program files\Lavasoft
    2010-07-17 15:43 . 2010-01-27 17:51 767952 ----a-w- c:\windows\BDTSupport.dll
    2010-07-17 15:43 . 2010-01-22 12:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
    2010-07-17 15:43 . 2009-10-28 04:36 1152444 ----a-w- c:\windows\UDB.zip
    2010-07-17 15:43 . 2008-11-26 15:08 131 ----a-w- c:\windows\IDB.zip
    2010-07-17 15:43 . 2010-01-22 12:56 165840 ----a-w- c:\windows\PCTBDRes.dll
    2010-07-17 15:43 . 2010-01-22 12:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
    2010-07-17 15:38 . 2010-02-05 13:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2010-07-17 15:38 . 2010-03-29 14:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2010-07-17 15:38 . 2009-11-23 17:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2010-07-17 15:38 . 2010-04-08 18:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2010-07-17 15:38 . 2010-07-17 19:06 -------- d-----w- c:\program files\Spyware Doctor
    2010-07-17 15:38 . 2010-07-17 15:44 -------- d-----w- c:\program files\Common Files\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\Christina Lovvorn\Application Data\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2010-07-17 15:37 . 2010-07-18 23:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-07-17 09:38 . 2010-07-17 09:38 53304 ----a-w- c:\documents and settings\Klovvorn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-07-17 09:38 . 2010-07-17 09:38 -------- d-----w- c:\documents and settings\Klovvorn\Local Settings\Application Data\Nancy Drew

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-17 18:41 . 2006-04-14 19:07 -------- d-----w- c:\program files\NetWaiting
    2010-07-17 18:41 . 2006-07-07 21:44 -------- d-----w- c:\program files\LIVEUPDATE
    2010-07-17 18:40 . 2009-11-17 15:41 -------- d-----w- c:\documents and settings\All Users\Application Data\08466529
    2010-07-17 18:40 . 2009-10-24 03:46 -------- d-----w- c:\documents and settings\All Users\Application Data\58030723
    2010-07-17 18:40 . 2009-10-22 22:40 -------- d-----w- c:\documents and settings\All Users\Application Data\21481218
    2010-07-17 15:37 . 2009-08-12 21:32 7672527 ----a-w- c:\documents and settings\Christina Lovvorn\HC43SInstaller.exe
    2010-07-17 15:26 . 2006-09-19 23:45 -------- d-----w- c:\program files\Lx_cats
    2006-05-21 10:05 . 2006-05-21 10:04 88 --sh--r- c:\windows\system32\575D6DB162.sys
    2008-09-23 22:08 . 2008-09-23 22:08 62186 --sha-w- c:\windows\system32\gazanudu.dll.tmp
    2008-09-23 21:03 . 2008-09-23 21:03 63585 --sha-w- c:\windows\system32\jifipanu.dll.tmp
    2006-05-21 10:05 . 2006-05-21 10:04 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
    2008-09-23 22:08 . 2008-09-23 22:08 62186 --sha-w- c:\windows\system32\legidonu.dll.tmp
    2008-09-23 22:08 . 2008-09-23 22:08 62186 --sha-w- c:\windows\system32\lukumeyo.dll.tmp
    2008-09-23 21:03 . 2008-09-23 21:03 63585 --sha-w- c:\windows\system32\sadeyoli.dll.tmp
    2008-09-23 21:03 . 2008-09-23 21:03 63585 --sha-w- c:\windows\system32\tisuleto.dll.tmp
    2009-03-21 14:18 . 2004-08-10 17:51 23552 --sha-w- c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\scandisk.dll
    .
    Code:
    <pre>
    c:\program files\Corel\Corel Photo Album 6\mediadetect .exe
    c:\program files\Dell\QuickSet\quickset .exe
    c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
    c:\program files\Java\j2re1.4.2_03\bin\jusched .exe
    c:\program files\LIVEUPDATE\liveupdate .exe
    c:\program files\McAfee.com\Agent\mcagent .exe
    c:\program files\McAfee.com\Agent\mcupdate .exe
    c:\program files\McAfee.com\Agent\mcupda~1 .exe
    c:\program files\McAfee.com\Personal Firewall\mpftray .exe
    c:\program files\McAfee.com\VSO\mcvsshld .exe
    c:\program files\McAfee.com\VSO\oasclnt .exe
    c:\program files\MUSICMATCH\Musicmatch Jukebox\mimboot .exe
    c:\program files\NetWaiting\netwaiting                      .exe
    c:\program files\NetWaiting\netwaiting                    .exe
    c:\program files\NetWaiting\netwaiting                  .exe
    c:\program files\NetWaiting\netwaiting                  .exe
    c:\program files\NetWaiting\netwaiting                .exe
    c:\program files\NetWaiting\netwaiting                .exe
    c:\program files\NetWaiting\netwaiting              .exe
    c:\program files\NetWaiting\netwaiting              .exe
    c:\program files\NetWaiting\netwaiting            .exe
    c:\program files\NetWaiting\netwaiting            .exe
    c:\program files\NetWaiting\netwaiting          .exe
    c:\program files\NetWaiting\netwaiting          .exe
    c:\program files\NetWaiting\netwaiting        .exe
    c:\program files\NetWaiting\netwaiting        .exe
    c:\program files\NetWaiting\netwaiting      .exe
    c:\program files\NetWaiting\netwaiting      .exe
    c:\program files\NetWaiting\netwaiting    .exe
    c:\program files\NetWaiting\netwaiting    .exe
    c:\program files\NetWaiting\netwaiting  .exe
    c:\program files\NetWaiting\netwaiting  .exe
    c:\program files\NetWaiting\netwaiting .exe
    c:\program files\Real\RealPlayer\realplay .exe
    c:\program files\Synaptics\SynTP\syntpenh .exe
    c:\windows\sysguard .exe
    c:\windows\system32\hkcmd .exe
    c:\windows\system32\igfxpers .exe
    c:\windows\system32\igfxtray .exe
    c:\windows\system32\reader_s .exe
    c:\windows\system32\dla\tfswctrl .exe
    </pre>

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Download"="c:\program files\Bellsouth\HelpCenter\ssGet.exe" [2008-02-29 893952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ShowLOMControl"="1 (0x1)" [X]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
    "SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
    "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-14 98304]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
    "VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
    "MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-12 1121792]
    "MSKAGENTEXE"="c:\progra~1\McAfee\SPAMKI~1\MSKAGE~1.EXE" [N/A]
    "tgcmd"="c:\program files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
    "lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2005-09-30 200704]
    "EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2005-08-01 94208]
    "ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
    "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-4-14 156784]
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-14 24576]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/17/2010 1:25 PM 64288]
    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/17/2010 11:38 AM 218592]
    R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [7/17/2010 11:43 AM 112592]
    R3 lxci_device;lxci_device;c:\windows\system32\lxcicoms.exe -service --> c:\windows\system32\lxcicoms.exe -service [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/12/2010 4:55 AM 1352832]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/17/2010 11:38 AM 366840]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]

    2009-10-13 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (CLOVVORN-Shu Lovvorn).job
    - c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-04-14 22:18]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = [You must be registered and logged in to see this link.]
    mStart Page = [You must be registered and logged in to see this link.]
    mWindow Title = Windows Internet Explorer provided by Comcast
    uInternet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
    uSearchAssistant = [You must be registered and logged in to see this link.]
    uSearchURL,(Default) = [You must be registered and logged in to see this link.]
    Trusted Zone: musicmatch.com\online
    DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - [You must be registered and logged in to see this link.]
    .
    - - - - ORPHANS REMOVED - - - -

    AddRemove-Detective Barbie(R) - c:\program files\Mattel Media\Detective Barbie(R)\Uninst.isu
    AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
    AddRemove-{60D8CA34-642C-476F-AB4E-94DECCAEED69} - c:\program files\InstallShield Installation Information\{60D8CA34-642C-476F-AB4E-94DECCAEED69}\setup.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
    Rootkit scan 2010-07-18 19:16
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Intel\Wireless\Bin\WLKeeper.exe
    c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\progra~1\mcafee.com\agent\mctskshd.exe
    c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
    c:\program files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    c:\windows\system32\wdfmgr.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\stsystra.exe
    c:\windows\system32\lxcicoms.exe
    c:\program files\Microsoft Office\Office\1033\msoffice.exe
    c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
    c:\program files\Common Files\InstallShield\UpdateService\agent.exe
    .
    **************************************************************************
    .
    Completion time: 2010-07-18 19:23:11 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-07-18 23:23

    Pre-Run: 42,808,532,992 bytes free
    Post-Run: 43,178,344,448 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    - - End Of File - - 93DC8273CB4D27D6CE4C9FA443D515E3

    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sneakyone on Mon 19 Jul 2010, 10:58 am

    Hi,

    Re-running ComboFix to remove infections:

    1. Close any open browsers.
    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    3. Open notepad and copy/paste the text in the codebox below into it:
      Code:

      KillAll::

      File::
      c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\scandisk.dll
      c:\windows\system32\gazanudu.dll.tmp
      c:\windows\system32\jifipanu.dll.tmp
      c:\windows\system32\legidonu.dll.tmp
      c:\windows\system32\lukumeyo.dll.tmp
      c:\windows\system32\sadeyoli.dll.tmp
      c:\windows\system32\tisuleto.dll.tmp

      Folder::
      c:\documents and settings\All Users\Application Data\08466529
      c:\documents and settings\All Users\Application Data\58030723
      c:\documents and settings\All Users\Application Data\21481218

      RenV::
      c:\program files\Corel\Corel Photo Album 6\mediadetect .exe
      c:\program files\Dell\QuickSet\quickset .exe
      c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
      c:\program files\Java\j2re1.4.2_03\bin\jusched .exe
      c:\program files\LIVEUPDATE\liveupdate .exe
      c:\program files\McAfee.com\Agent\mcagent .exe
      c:\program files\McAfee.com\Agent\mcupdate .exe
      c:\program files\McAfee.com\Agent\mcupda~1 .exe
      c:\program files\McAfee.com\Personal Firewall\mpftray .exe
      c:\program files\McAfee.com\VSO\mcvsshld .exe
      c:\program files\McAfee.com\VSO\oasclnt .exe
      c:\program files\MUSICMATCH\Musicmatch Jukebox\mimboot .exe
      c:\program files\NetWaiting\netwaiting                      .exe
      c:\program files\NetWaiting\netwaiting                    .exe
      c:\program files\NetWaiting\netwaiting                  .exe
      c:\program files\NetWaiting\netwaiting                  .exe
      c:\program files\NetWaiting\netwaiting                .exe
      c:\program files\NetWaiting\netwaiting                .exe
      c:\program files\NetWaiting\netwaiting              .exe
      c:\program files\NetWaiting\netwaiting              .exe
      c:\program files\NetWaiting\netwaiting            .exe
      c:\program files\NetWaiting\netwaiting            .exe
      c:\program files\NetWaiting\netwaiting          .exe
      c:\program files\NetWaiting\netwaiting          .exe
      c:\program files\NetWaiting\netwaiting        .exe
      c:\program files\NetWaiting\netwaiting        .exe
      c:\program files\NetWaiting\netwaiting      .exe
      c:\program files\NetWaiting\netwaiting      .exe
      c:\program files\NetWaiting\netwaiting    .exe
      c:\program files\NetWaiting\netwaiting    .exe
      c:\program files\NetWaiting\netwaiting  .exe
      c:\program files\NetWaiting\netwaiting  .exe
      c:\program files\NetWaiting\netwaiting .exe
      c:\program files\Real\RealPlayer\realplay .exe
      c:\program files\Synaptics\SynTP\syntpenh .exe
      c:\windows\sysguard .exe
      c:\windows\system32\hkcmd .exe
      c:\windows\system32\igfxpers .exe
      c:\windows\system32\igfxtray .exe
      c:\windows\system32\reader_s .exe
      c:\windows\system32\dla\tfswctrl .exe

      Rootkit::
      c:\windows\win32k.sys

      Reboot::


    4. Save this as CFScript.txt, in the same location as ComboFix.exe



    5. Referring to the picture above, drag CFScript into ComboFix.exe
    6. When finished, it shall produce a log for you at C:\ComboFix.txt
    7. Please post the contents of the log in your next reply.


    ========

    Please visit Virustotal


    • Click the Browse.. button
    • Navigate to the file c:\windows\system32\575D6DB162.sys
    • Click the Open button
    • Click the Send button
    • Copy and paste the results into a new reply in this thread please.

    If VirusTotal is busy please use Jotti


    I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Mon 19 Jul 2010, 4:14 pm

    File 575D6DB162.sys received on 2010.07.19 05:10:33 (UTC)
    Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


    Result: 0/42 (0%)
    Loading server information...
    Your file is queued in position: 1.
    Estimated start time is between 46 and 66 seconds.
    Do not close the window until scan is complete.
    The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
    If you are waiting for more than five minutes you have to resend your file.
    Your file is being scanned by VirusTotal in this moment,
    results will be shown as they're generated.
    Compact Print results
    Your file has expired or does not exists.
    Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

    You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
    Email:


    Antivirus Version Last Update Result
    a-squared 5.0.0.31 2010.07.19 -
    AhnLab-V3 2010.07.18.00 2010.07.18 -
    AntiVir 8.2.4.12 2010.07.18 -
    Antiy-AVL 2.0.3.7 2010.07.15 -
    Authentium 5.2.0.5 2010.07.19 -
    Avast 4.8.1351.0 2010.07.19 -
    Avast5 5.0.332.0 2010.07.19 -
    AVG 9.0.0.836 2010.07.18 -
    BitDefender 7.2 2010.07.19 -
    CAT-QuickHeal 11.00 2010.07.19 -
    ClamAV 0.96.0.3-git 2010.07.19 -
    Comodo 5473 2010.07.19 -
    DrWeb 5.0.2.03300 2010.07.19 -
    eSafe 7.0.17.0 2010.07.18 -
    eTrust-Vet None 2010.07.16 -
    F-Prot 4.6.1.107 2010.07.19 -
    F-Secure 9.0.15370.0 2010.07.19 -
    Fortinet 4.1.143.0 2010.07.18 -
    GData 21 2010.07.19 -
    Ikarus T3.1.1.84.0 2010.07.19 -
    Jiangmin 13.0.900 2010.07.18 -
    Kaspersky 7.0.0.125 2010.07.19 -
    McAfee 5.400.0.1158 2010.07.19 -
    McAfee-GW-Edition 2010.1 2010.07.19 -
    Microsoft 1.6004 2010.07.18 -
    NOD32 5290 2010.07.19 -
    Norman 6.05.11 2010.07.18 -
    nProtect 2010-07-18.02 2010.07.18 -
    Panda 10.0.2.7 2010.07.18 -
    PCTools 7.0.3.5 2010.07.19 -
    Prevx 3.0 2010.07.19 -
    Rising 22.57.00.00 2010.07.19 -
    Sophos 4.55.0 2010.07.19 -
    Sunbelt 6601 2010.07.19 -
    SUPERAntiSpyware 4.40.0.1006 2010.07.19 -
    Symantec 20101.1.1.7 2010.07.19 -
    TheHacker 6.5.2.1.319 2010.07.19 -
    TrendMicro 9.120.0.1004 2010.07.19 -
    TrendMicro-HouseCall 9.120.0.1004 2010.07.19 -
    VBA32 3.12.12.6 2010.07.16 -
    ViRobot 2010.7.12.3932 2010.07.19 -
    VirusBuster 5.0.27.0 2010.07.18 -
    Additional information
    File size: 88 bytes
    MD5...: 14e84f38386284ab7e49487b91246420
    SHA1..: 731d26be58a017ebab5674fc7aa9cefeee18b2ba
    SHA256: db75e78ace2bf1d9a5ed32086aa501663881451b70086f3ec42455862fea936f
    ssdeep: 3:hl/L/7LjHVn:fzXt

    PEiD..: -
    PEInfo: -
    RDS...: NSRL Reference Data Set
    -
    pdfid.: -
    trid..: MS Flight Simulator Aircraft Performance Info (100.0%)
    sigcheck:
    publisher....: n/a
    copyright....: n/a
    product......: n/a
    description..: n/a
    original name: n/a
    internal name: n/a
    file version.: n/a
    comments.....: n/a
    signers......: -
    signing date.: -
    verified.....: Unsigned


    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sneakyone on Mon 19 Jul 2010, 5:23 pm

    Hi,

    Do you also have the ComboFix log?


    I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Mon 19 Jul 2010, 9:39 pm

    Oops here it is.

    ComboFix 10-07-16.02 - Christina Lovvorn 07/19/2010 6:22.4.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.620 [GMT -4:00]
    Running from: c:\documents and settings\Christina Lovvorn\Desktop\commy.exe
    Command switches used :: c:\documents and settings\Christina Lovvorn\Desktop\CFscript.txt
    AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
    FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

    FILE ::
    "c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\scandisk.dll"
    "c:\windows\system32\gazanudu.dll.tmp"
    "c:\windows\system32\jifipanu.dll.tmp"
    "c:\windows\system32\legidonu.dll.tmp"
    "c:\windows\system32\lukumeyo.dll.tmp"
    "c:\windows\system32\sadeyoli.dll.tmp"
    "c:\windows\system32\tisuleto.dll.tmp"
    .

    ((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
    .

    2010-07-17 17:25 . 2010-07-17 17:25 -------- dc----w- c:\windows\system32\DRVSTORE
    2010-07-17 17:25 . 2010-07-12 08:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-07-17 17:25 . 2010-07-17 17:25 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-07-17 17:15 . 2010-07-17 17:15 -------- d-----w- c:\documents and settings\Christina Lovvorn\Local Settings\Application Data\Sunbelt Software
    2010-07-17 17:14 . 2010-07-17 17:14 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
    2010-07-17 17:14 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
    2010-07-17 17:13 . 2010-07-17 17:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-07-17 17:13 . 2010-07-17 17:13 -------- d-----w- c:\program files\Lavasoft
    2010-07-17 15:43 . 2010-01-27 17:51 767952 ----a-w- c:\windows\BDTSupport.dll
    2010-07-17 15:43 . 2010-01-22 12:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
    2010-07-17 15:43 . 2009-10-28 04:36 1152444 ----a-w- c:\windows\UDB.zip
    2010-07-17 15:43 . 2008-11-26 15:08 131 ----a-w- c:\windows\IDB.zip
    2010-07-17 15:43 . 2010-01-22 12:56 165840 ----a-w- c:\windows\PCTBDRes.dll
    2010-07-17 15:43 . 2010-01-22 12:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
    2010-07-17 15:38 . 2010-02-05 13:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2010-07-17 15:38 . 2010-03-29 14:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2010-07-17 15:38 . 2009-11-23 17:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2010-07-17 15:38 . 2010-04-08 18:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2010-07-17 15:38 . 2010-07-17 19:06 -------- d-----w- c:\program files\Spyware Doctor
    2010-07-17 15:38 . 2010-07-17 15:44 -------- d-----w- c:\program files\Common Files\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\Christina Lovvorn\Application Data\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2010-07-17 15:37 . 2010-07-19 10:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-07-17 09:38 . 2010-07-17 09:38 53304 ----a-w- c:\documents and settings\Klovvorn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-07-17 09:38 . 2010-07-17 09:38 -------- d-----w- c:\documents and settings\Klovvorn\Local Settings\Application Data\Nancy Drew

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-19 00:57 . 2006-04-14 19:07 -------- d-----w- c:\program files\NetWaiting
    2010-07-19 00:57 . 2006-07-07 21:44 -------- d-----w- c:\program files\LIVEUPDATE
    2010-07-17 15:37 . 2009-08-12 21:32 7672527 ----a-w- c:\documents and settings\Christina Lovvorn\HC43SInstaller.exe
    2010-07-17 15:26 . 2006-09-19 23:45 -------- d-----w- c:\program files\Lx_cats
    2006-05-21 10:05 . 2006-05-21 10:04 88 --sh--r- c:\windows\system32\575D6DB162.sys
    2006-05-21 10:05 . 2006-05-21 10:04 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
    .
    Code:
    <pre>
    c:\program files\NetWaiting\netwaiting                  .exe
    c:\program files\NetWaiting\netwaiting                .exe
    c:\program files\NetWaiting\netwaiting              .exe
    c:\program files\NetWaiting\netwaiting            .exe
    c:\program files\NetWaiting\netwaiting          .exe
    c:\program files\NetWaiting\netwaiting        .exe
    c:\program files\NetWaiting\netwaiting      .exe
    c:\program files\NetWaiting\netwaiting    .exe
    c:\program files\NetWaiting\netwaiting  .exe
    </pre>

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Download"="c:\program files\Bellsouth\HelpCenter\ssGet.exe" [2008-02-29 893952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ShowLOMControl"="1 (0x1)" [X]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
    "SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
    "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-14 98304]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
    "VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
    "MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-12 1121792]
    "MSKAGENTEXE"="c:\progra~1\McAfee\SPAMKI~1\MSKAGE~1.EXE" [2010-07-19 25600]
    "tgcmd"="c:\program files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
    "lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2005-09-30 200704]
    "EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2005-08-01 94208]
    "ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
    "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-4-14 156784]
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-14 24576]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/17/2010 1:25 PM 64288]
    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/17/2010 11:38 AM 218592]
    R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [7/17/2010 11:43 AM 112592]
    R3 lxci_device;lxci_device;c:\windows\system32\lxcicoms.exe -service --> c:\windows\system32\lxcicoms.exe -service [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/12/2010 4:55 AM 1352832]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/17/2010 11:38 AM 366840]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]

    2009-10-13 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (CLOVVORN-Shu Lovvorn).job
    - c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-04-14 22:18]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = [You must be registered and logged in to see this link.]
    mStart Page = [You must be registered and logged in to see this link.]
    mWindow Title = Windows Internet Explorer provided by Comcast
    uInternet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
    uSearchAssistant = [You must be registered and logged in to see this link.]
    uSearchURL,(Default) = [You must be registered and logged in to see this link.]
    Trusted Zone: musicmatch.com\online
    DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - [You must be registered and logged in to see this link.]
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
    Rootkit scan 2010-07-19 06:30
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Intel\Wireless\Bin\WLKeeper.exe
    c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\progra~1\mcafee.com\agent\mctskshd.exe
    c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
    c:\program files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    c:\windows\system32\wdfmgr.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\stsystra.exe
    c:\windows\system32\lxcicoms.exe
    c:\program files\Microsoft Office\Office\1033\msoffice.exe
    c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
    c:\program files\Internet Explorer\iexplore.exe
    .
    **************************************************************************
    .
    Completion time: 2010-07-19 06:35:33 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-07-19 10:35
    ComboFix2.txt 2010-07-19 01:12
    ComboFix3.txt 2010-07-18 23:23

    Pre-Run: 42,946,375,680 bytes free
    Post-Run: 42,935,582,720 bytes free

    - - End Of File - - 586D1C6C12CC72DF120F6E378D861E50

    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sneakyone on Tue 20 Jul 2010, 6:17 am

    Hi,

    Re-running ComboFix to remove infections:

    1. Close any open browsers.
    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    3. Open notepad and copy/paste the text in the quotebox below into it:
      Code:

      RenV::
      c:\program files\NetWaiting\netwaiting                  .exe
      c:\program files\NetWaiting\netwaiting                .exe
      c:\program files\NetWaiting\netwaiting              .exe
      c:\program files\NetWaiting\netwaiting            .exe
      c:\program files\NetWaiting\netwaiting          .exe
      c:\program files\NetWaiting\netwaiting        .exe
      c:\program files\NetWaiting\netwaiting      .exe
      c:\program files\NetWaiting\netwaiting    .exe
      c:\program files\NetWaiting\netwaiting  .exe

    4. Save this as CFScript.txt, in the same location as ComboFix.exe



    5. Referring to the picture above, drag CFScript into ComboFix.exe
    6. When finished, it shall produce a log for you at C:\ComboFix.txt
    7. Please post the contents of the log in your next reply.


    I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Tue 20 Jul 2010, 6:43 am

    Contents below. I have a question, this computer belongs to my girlfriends daughter. How do I stop this from happening again? Is there some software or guidlines? Thanks.

    ComboFix 10-07-16.02 - Christina Lovvorn 07/19/2010 15:30:48.5.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.608 [GMT -4:00]
    Running from: c:\documents and settings\Christina Lovvorn\Desktop\commy.exe
    Command switches used :: c:\documents and settings\Christina Lovvorn\Desktop\CFscript.txt
    AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
    FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .

    ((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
    .

    2010-07-19 16:52 . 2010-07-19 16:52 -------- d-----w- c:\windows\ServicePackFiles
    2010-07-18 23:27 . 2009-11-21 16:36 470528 ------w- c:\windows\system32\dllcache\aclayers.dll
    2010-07-18 23:27 . 2010-06-14 14:30 743936 ------w- c:\windows\system32\dllcache\helpsvc.exe
    2010-07-18 23:27 . 2009-10-15 17:21 82432 ------w- c:\windows\system32\dllcache\fontsub.dll
    2010-07-18 23:27 . 2009-10-23 14:27 3555328 ------w- c:\windows\system32\dllcache\moviemk.exe
    2010-07-17 17:25 . 2010-07-17 17:25 -------- dc----w- c:\windows\system32\DRVSTORE
    2010-07-17 17:25 . 2010-07-12 08:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-07-17 17:25 . 2010-07-17 17:25 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-07-17 17:15 . 2010-07-17 17:15 -------- d-----w- c:\documents and settings\Christina Lovvorn\Local Settings\Application Data\Sunbelt Software
    2010-07-17 17:14 . 2010-07-17 17:14 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
    2010-07-17 17:14 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
    2010-07-17 17:13 . 2010-07-17 17:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-07-17 17:13 . 2010-07-17 17:13 -------- d-----w- c:\program files\Lavasoft
    2010-07-17 15:43 . 2010-01-27 17:51 767952 ----a-w- c:\windows\BDTSupport.dll
    2010-07-17 15:43 . 2010-01-22 12:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
    2010-07-17 15:43 . 2009-10-28 04:36 1152444 ----a-w- c:\windows\UDB.zip
    2010-07-17 15:43 . 2008-11-26 15:08 131 ----a-w- c:\windows\IDB.zip
    2010-07-17 15:43 . 2010-01-22 12:56 165840 ----a-w- c:\windows\PCTBDRes.dll
    2010-07-17 15:43 . 2010-01-22 12:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
    2010-07-17 15:38 . 2010-02-05 13:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2010-07-17 15:38 . 2010-03-29 14:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2010-07-17 15:38 . 2009-11-23 17:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2010-07-17 15:38 . 2010-04-08 18:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2010-07-17 15:38 . 2010-07-17 19:06 -------- d-----w- c:\program files\Spyware Doctor
    2010-07-17 15:38 . 2010-07-17 15:44 -------- d-----w- c:\program files\Common Files\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\Christina Lovvorn\Application Data\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2010-07-17 15:37 . 2010-07-19 17:07 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-07-17 09:38 . 2010-07-17 09:38 53304 ----a-w- c:\documents and settings\Klovvorn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-07-17 09:38 . 2010-07-17 09:38 -------- d-----w- c:\documents and settings\Klovvorn\Local Settings\Application Data\Nancy Drew

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-19 17:12 . 2009-08-12 21:32 7639760 ----a-w- c:\documents and settings\Christina Lovvorn\HC43SInstaller.exe
    2010-07-19 00:57 . 2006-04-14 19:07 -------- d-----w- c:\program files\NetWaiting
    2010-07-19 00:57 . 2006-07-07 21:44 -------- d-----w- c:\program files\LIVEUPDATE
    2010-07-17 15:26 . 2006-09-19 23:45 -------- d-----w- c:\program files\Lx_cats
    2010-06-14 14:30 . 2004-08-10 18:02 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    2010-05-02 05:56 . 2004-08-10 17:51 1850880 ----a-w- c:\windows\system32\win32k.sys
    2006-05-21 10:05 . 2006-05-21 10:04 88 --sh--r- c:\windows\system32\575D6DB162.sys
    2006-05-21 10:05 . 2006-05-21 10:04 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
    .
    Code:
    <pre>
    c:\program files\NetWaiting\netwaiting                  .exe
    c:\program files\NetWaiting\netwaiting                .exe
    c:\program files\NetWaiting\netwaiting              .exe
    c:\program files\NetWaiting\netwaiting            .exe
    c:\program files\NetWaiting\netwaiting          .exe
    c:\program files\NetWaiting\netwaiting        .exe
    c:\program files\NetWaiting\netwaiting      .exe
    c:\program files\NetWaiting\netwaiting    .exe
    c:\program files\NetWaiting\netwaiting  .exe
    </pre>

    ((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
    .
    + 2004-08-10 17:51 . 2009-06-25 08:17 59392 c:\windows\system32\wdigest.dll
    + 2007-01-29 08:58 . 2010-04-21 13:28 46080 c:\windows\system32\tzchange.exe
    + 2004-08-10 17:51 . 2009-06-12 11:50 76288 c:\windows\system32\telnet.exe
    + 2006-04-26 19:36 . 2007-07-27 14:41 26488 c:\windows\system32\spupdsvc.exe
    - 2006-04-26 19:36 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
    - 2006-04-26 19:36 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
    + 2006-04-26 19:36 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll
    + 2004-08-10 17:51 . 2009-06-25 08:17 56320 c:\windows\system32\secur32.dll
    + 2004-08-10 17:51 . 2009-10-12 13:54 69632 c:\windows\system32\raschap.dll
    - 2004-08-10 17:51 . 2004-08-04 10:00 69632 c:\windows\system32\raschap.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 39424 c:\windows\system32\pngfilt.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 39424 c:\windows\system32\pngfilt.dll
    + 2004-08-10 17:51 . 2010-07-19 16:57 65120 c:\windows\system32\perfc009.dat
    - 2004-08-10 17:51 . 2010-07-18 23:20 65120 c:\windows\system32\perfc009.dat
    + 2004-08-04 05:56 . 2009-11-27 17:33 17920 c:\windows\system32\msyuv.dll
    + 2004-08-10 17:51 . 2009-11-27 16:37 28672 c:\windows\system32\msvidc32.dll
    - 2004-08-10 17:51 . 2004-08-04 10:00 11264 c:\windows\system32\msrle32.dll
    + 2004-08-10 17:51 . 2009-11-27 16:37 11264 c:\windows\system32\msrle32.dll
    + 2004-08-10 17:51 . 2009-09-04 20:45 58880 c:\windows\system32\msasn1.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 16384 c:\windows\system32\jsproxy.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 16384 c:\windows\system32\jsproxy.dll
    + 2004-08-04 05:56 . 2009-11-27 16:37 48128 c:\windows\system32\iyuv_32.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 96256 c:\windows\system32\inseng.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 96256 c:\windows\system32\inseng.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 81920 c:\windows\system32\ieencode.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 81920 c:\windows\system32\ieencode.dll
    + 2004-08-10 17:51 . 2009-10-15 17:21 82432 c:\windows\system32\fontsub.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 55808 c:\windows\system32\extmgr.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 55808 c:\windows\system32\extmgr.dll
    + 2004-08-10 17:51 . 2009-06-22 11:35 92544 c:\windows\system32\drivers\ksecdd.sys
    + 2009-06-25 08:17 . 2009-06-25 08:17 59392 c:\windows\system32\dllcache\wdigest.dll
    + 2009-06-12 11:50 . 2009-06-12 11:50 76288 c:\windows\system32\dllcache\telnet.exe
    + 2009-02-03 20:08 . 2009-06-25 08:17 56320 c:\windows\system32\dllcache\secur32.dll
    + 2009-10-12 13:54 . 2009-10-12 13:54 69632 c:\windows\system32\dllcache\raschap.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 39424 c:\windows\system32\dllcache\pngfilt.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 39424 c:\windows\system32\dllcache\pngfilt.dll
    + 2009-11-27 17:33 . 2009-11-27 17:33 17920 c:\windows\system32\dllcache\msyuv.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 28672 c:\windows\system32\dllcache\msvidc32.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 11264 c:\windows\system32\dllcache\msrle32.dll
    + 2009-09-04 20:45 . 2009-09-04 20:45 58880 c:\windows\system32\dllcache\msasn1.dll
    + 2009-06-22 11:35 . 2009-06-22 11:35 92544 c:\windows\system32\dllcache\ksecdd.sys
    - 2006-05-10 05:25 . 2009-04-29 04:31 16384 c:\windows\system32\dllcache\jsproxy.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 16384 c:\windows\system32\dllcache\jsproxy.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 48128 c:\windows\system32\dllcache\iyuv_32.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 96256 c:\windows\system32\dllcache\inseng.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 96256 c:\windows\system32\dllcache\inseng.dll
    + 2009-02-20 08:14 . 2010-04-16 15:20 81920 c:\windows\system32\dllcache\ieencode.dll
    - 2009-02-20 08:14 . 2009-04-29 04:31 81920 c:\windows\system32\dllcache\ieencode.dll
    - 2006-05-09 11:41 . 2009-04-27 09:29 18432 c:\windows\system32\dllcache\iedw.exe
    + 2006-05-09 11:41 . 2010-04-16 13:29 18432 c:\windows\system32\dllcache\iedw.exe
    - 2006-05-10 05:25 . 2009-04-29 04:31 55808 c:\windows\system32\dllcache\extmgr.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 55808 c:\windows\system32\dllcache\extmgr.dll
    + 2009-12-14 07:35 . 2009-12-14 07:35 33280 c:\windows\system32\dllcache\csrsrv.dll
    + 2010-01-13 14:10 . 2010-01-13 14:10 85504 c:\windows\system32\dllcache\cabview.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 84992 c:\windows\system32\dllcache\avifil32.dll
    + 2009-07-17 18:55 . 2009-07-17 18:55 58880 c:\windows\system32\dllcache\atl.dll
    + 2010-03-05 14:57 . 2010-03-05 14:57 65536 c:\windows\system32\dllcache\asycfilt.dll
    + 2004-08-10 17:50 . 2009-12-14 07:35 33280 c:\windows\system32\csrsrv.dll
    + 2004-08-10 17:50 . 2010-01-13 14:10 85504 c:\windows\system32\cabview.dll
    + 2004-08-10 17:50 . 2009-11-27 16:37 84992 c:\windows\system32\avifil32.dll
    - 2004-08-10 17:50 . 2004-08-04 10:00 84992 c:\windows\system32\avifil32.dll
    - 2004-08-10 17:50 . 2004-08-04 10:00 58880 c:\windows\system32\atl.dll
    + 2004-08-10 17:50 . 2009-07-17 18:55 58880 c:\windows\system32\atl.dll
    + 2004-08-10 17:50 . 2010-03-05 14:57 65536 c:\windows\system32\asycfilt.dll
    + 2009-06-24 23:56 . 2009-06-24 23:56 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
    - 2007-04-14 00:58 . 2007-04-14 00:58 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
    + 2008-05-28 04:49 . 2008-05-28 04:49 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
    - 2007-04-14 00:57 . 2007-04-14 00:57 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
    + 2008-05-28 04:49 . 2008-05-28 04:49 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
    - 2007-04-14 00:57 . 2007-04-14 00:57 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
    + 2008-05-28 04:49 . 2008-05-28 04:49 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
    - 2007-04-14 01:30 . 2007-04-14 01:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    + 2008-05-28 05:30 . 2008-05-28 05:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    + 2010-07-19 16:51 . 2010-07-19 16:51 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe
    + 2009-11-27 17:33 . 2009-11-27 17:33 17920 c:\windows\Driver Cache\i386\msyuv.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 48128 c:\windows\Driver Cache\i386\iyuv_32.dll
    + 2010-07-19 16:54 . 2010-07-19 16:54 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_bdcaae57\System.Drawing.Design.dll
    + 2010-07-19 16:54 . 2010-07-19 16:54 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b7337b95\CustomMarshalers.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 81920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e299fd71b4c71854673c47f85b4cf180\Microsoft.Build.Framework.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 15360 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\662febc2f309e92a880682f527f4e426\dfsvc.ni.exe
    + 2010-07-19 17:01 . 2010-07-19 17:01 27136 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\1a67452bf4558b2574698b6008e7af74\Accessibility.ni.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 90112 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 90112 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2010-07-19 16:59 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB975025\update\spcustom.dll
    + 2010-07-19 16:59 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB975025\spmsg.dll
    + 2010-07-19 16:59 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB974571\update\spcustom.dll
    + 2010-07-19 16:59 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB974571\spmsg.dll
    + 2009-09-04 20:57 . 2009-09-04 20:57 58880 c:\windows\$hf_mig$\KB974571\SP3QFE\msasn1.dll
    + 2009-09-04 21:03 . 2009-09-04 21:03 58880 c:\windows\$hf_mig$\KB974571\SP3GDR\msasn1.dll
    + 2009-09-04 20:36 . 2009-09-04 20:36 58880 c:\windows\$hf_mig$\KB974571\SP2QFE\msasn1.dll
    + 2010-07-19 17:00 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB974112\update\spcustom.dll
    + 2010-07-19 17:00 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB974112\spmsg.dll
    + 2010-07-19 16:52 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB973815\update\spcustom.dll
    + 2010-07-19 16:52 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB973815\spmsg.dll
    + 2010-07-19 16:58 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB973507\update\spcustom.dll
    + 2010-07-19 16:58 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB973507\spmsg.dll
    + 2009-07-17 19:25 . 2009-07-17 19:25 58880 c:\windows\$hf_mig$\KB973507\SP3QFE\atl.dll
    + 2009-07-17 19:01 . 2009-07-17 19:01 58880 c:\windows\$hf_mig$\KB973507\SP3GDR\atl.dll
    + 2009-07-17 18:43 . 2009-07-17 18:43 58880 c:\windows\$hf_mig$\KB973507\SP2QFE\atl.dll
    + 2010-07-19 17:00 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB971657\update\spcustom.dll
    + 2010-07-19 17:00 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB971657\spmsg.dll
    + 2010-07-19 17:01 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB969059\update\spcustom.dll
    + 2010-07-19 17:01 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB969059\spmsg.dll
    + 2010-07-19 16:51 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB968389\update\spcustom.dll
    + 2010-07-19 16:51 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB968389\spmsg.dll
    + 2009-06-25 08:41 . 2009-06-25 08:41 54272 c:\windows\$hf_mig$\KB968389\SP3QFE\wdigest.dll
    + 2009-06-25 08:41 . 2009-06-25 08:41 56832 c:\windows\$hf_mig$\KB968389\SP3QFE\secur32.dll
    + 2009-06-24 10:28 . 2009-06-24 10:28 92928 c:\windows\$hf_mig$\KB968389\SP3QFE\ksecdd.sys
    + 2009-06-25 08:25 . 2009-06-25 08:25 54272 c:\windows\$hf_mig$\KB968389\SP3GDR\wdigest.dll
    + 2009-06-25 08:25 . 2009-06-25 08:25 56832 c:\windows\$hf_mig$\KB968389\SP3GDR\secur32.dll
    + 2009-06-24 11:18 . 2009-06-24 11:18 92928 c:\windows\$hf_mig$\KB968389\SP3GDR\ksecdd.sys
    + 2010-07-19 17:03 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB960859\update\spcustom.dll
    + 2010-07-19 17:03 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB960859\spmsg.dll
    + 2009-06-12 12:03 . 2009-06-12 12:03 80896 c:\windows\$hf_mig$\KB960859\SP3QFE\tlntsess.exe
    + 2009-06-12 12:03 . 2009-06-12 12:03 76288 c:\windows\$hf_mig$\KB960859\SP3QFE\telnet.exe
    + 2009-06-12 12:31 . 2009-06-12 12:31 80896 c:\windows\$hf_mig$\KB960859\SP3GDR\tlntsess.exe
    + 2009-06-12 12:31 . 2009-06-12 12:31 76288 c:\windows\$hf_mig$\KB960859\SP3GDR\telnet.exe
    + 2009-06-12 11:49 . 2009-06-12 11:49 80896 c:\windows\$hf_mig$\KB960859\SP2QFE\tlntsess.exe
    + 2009-06-12 11:49 . 2009-06-12 11:49 76288 c:\windows\$hf_mig$\KB960859\SP2QFE\telnet.exe
    - 2008-04-14 02:09 . 2008-04-14 02:09 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2001-08-18 03:36 . 2009-11-27 16:37 8704 c:\windows\system32\tsbyuv.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 8704 c:\windows\system32\dllcache\tsbyuv.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 8704 c:\windows\Driver Cache\i386\tsbyuv.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    - 2008-04-14 02:08 . 2008-04-14 02:08 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    + 2006-04-14 19:00 . 2010-04-16 13:21 352768 c:\windows\system32\xpsp3res.dll
    + 2004-08-10 17:51 . 2009-04-10 05:01 413032 c:\windows\system32\wmspdmod.dll
    + 2004-08-10 17:51 . 2009-07-13 14:08 286720 c:\windows\system32\wmpdxm.dll
    + 2004-08-10 17:51 . 2009-06-10 06:32 132096 c:\windows\system32\wkssvc.dll
    - 2004-08-10 17:51 . 2006-08-17 12:28 132096 c:\windows\system32\wkssvc.dll
    + 2004-08-10 17:51 . 2009-12-24 07:05 177664 c:\windows\system32\wintrust.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 668672 c:\windows\system32\wininet.dll
    + 2004-08-10 17:51 . 2010-03-10 08:02 417792 c:\windows\system32\vbscript.dll
    - 2004-08-10 17:51 . 2007-12-18 14:40 417792 c:\windows\system32\vbscript.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 628224 c:\windows\system32\urlmon.dll
    + 2004-08-10 17:51 . 2009-10-16 02:51 119808 c:\windows\system32\t2embed.dll
    + 2004-08-10 17:51 . 2009-08-26 08:16 247326 c:\windows\system32\strmdll.dll
    - 2004-08-10 17:51 . 2008-10-03 10:15 247326 c:\windows\system32\strmdll.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 474112 c:\windows\system32\shlwapi.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 474112 c:\windows\system32\shlwapi.dll
    + 2004-08-10 17:51 . 2009-06-25 08:17 168448 c:\windows\system32\schannel.dll
    - 2004-08-10 17:51 . 2004-08-04 10:00 112128 c:\windows\system32\rastls.dll
    + 2004-08-10 17:51 . 2009-10-12 13:54 112128 c:\windows\system32\rastls.dll
    - 2004-08-10 17:51 . 2010-07-18 23:20 409114 c:\windows\system32\perfh009.dat
    + 2004-08-10 17:51 . 2010-07-19 16:57 409114 c:\windows\system32\perfh009.dat
    - 2004-08-10 17:51 . 2004-08-04 10:00 266752 c:\windows\system32\oakley.dll
    + 2004-08-10 17:51 . 2009-10-13 10:53 266752 c:\windows\system32\oakley.dll
    + 2004-08-10 17:51 . 2009-02-06 18:46 408064 c:\windows\system32\netlogon.dll
    + 2004-08-10 17:51 . 2009-08-05 09:11 204800 c:\windows\system32\mswebdvd.dll
    + 2004-08-10 17:51 . 2009-06-25 08:17 136192 c:\windows\system32\msv1_0.dll
    + 2004-08-10 18:01 . 2009-06-05 07:42 655872 c:\windows\system32\mstscax.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 532480 c:\windows\system32\mstime.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 532480 c:\windows\system32\mstime.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 146432 c:\windows\system32\msrating.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 146432 c:\windows\system32\msrating.dll
    - 2004-08-10 18:01 . 2004-08-04 10:00 343040 c:\windows\system32\mspaint.exe
    + 2004-08-10 18:01 . 2009-12-16 12:58 343040 c:\windows\system32\mspaint.exe
    + 2004-08-10 17:51 . 2010-04-16 15:20 449024 c:\windows\system32\mshtmled.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 449024 c:\windows\system32\mshtmled.dll
    + 2004-08-10 17:51 . 2009-06-25 08:17 729600 c:\windows\system32\lsasrv.dll
    + 2004-08-10 17:51 . 2009-06-25 08:17 301568 c:\windows\system32\kerberos.dll
    - 2004-08-10 17:51 . 2007-12-18 14:40 450560 c:\windows\system32\jscript.dll
    + 2004-08-10 17:51 . 2009-08-21 09:46 450560 c:\windows\system32\jscript.dll
    - 2004-08-10 18:02 . 2008-04-11 18:50 683520 c:\windows\system32\inetcomm.dll
    + 2004-08-10 18:02 . 2010-01-29 15:08 683520 c:\windows\system32\inetcomm.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 251904 c:\windows\system32\iepeers.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 251904 c:\windows\system32\iepeers.dll
    + 2004-08-10 17:57 . 2010-07-19 17:07 225616 c:\windows\system32\FNTCACHE.DAT
    - 2004-08-10 17:57 . 2009-06-11 17:47 225616 c:\windows\system32\FNTCACHE.DAT
    - 2004-08-10 17:51 . 2009-04-29 04:31 205312 c:\windows\system32\dxtrans.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 205312 c:\windows\system32\dxtrans.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 357888 c:\windows\system32\dxtmsft.dll
    - 2004-08-10 17:51 . 2009-04-29 04:31 357888 c:\windows\system32\dxtmsft.dll
    + 2004-08-10 17:51 . 2010-02-11 12:01 226880 c:\windows\system32\drivers\tcpip6.sys
    + 2006-04-14 18:39 . 2009-12-31 16:14 352640 c:\windows\system32\drivers\srv.sys
    + 2006-04-14 18:39 . 2010-02-24 12:31 454016 c:\windows\system32\drivers\mrxsmb.sys
    + 2004-08-10 17:51 . 2009-04-10 05:01 413032 c:\windows\system32\dllcache\wmspdmod.dll
    + 2004-08-10 17:51 . 2009-07-13 14:08 286720 c:\windows\system32\dllcache\wmpdxm.dll
    - 2006-08-17 12:28 . 2006-08-17 12:28 132096 c:\windows\system32\dllcache\wkssvc.dll
    + 2006-08-17 12:28 . 2009-06-10 06:32 132096 c:\windows\system32\dllcache\wkssvc.dll
    + 2009-12-24 07:05 . 2009-12-24 07:05 177664 c:\windows\system32\dllcache\wintrust.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 668672 c:\windows\system32\dllcache\wininet.dll
    + 2007-12-18 14:40 . 2010-03-10 08:02 417792 c:\windows\system32\dllcache\vbscript.dll
    - 2007-12-18 14:40 . 2007-12-18 14:40 417792 c:\windows\system32\dllcache\vbscript.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 628224 c:\windows\system32\dllcache\urlmon.dll
    + 2009-10-22 22:07 . 2009-06-21 22:04 153088 c:\windows\system32\dllcache\triedit.dll
    + 2006-08-16 09:37 . 2010-02-11 12:01 226880 c:\windows\system32\dllcache\tcpip6.sys
    + 2009-10-16 02:51 . 2009-10-16 02:51 119808 c:\windows\system32\dllcache\t2embed.dll
    + 2006-08-21 14:52 . 2009-08-26 08:16 247326 c:\windows\system32\dllcache\strmdll.dll
    - 2006-08-21 14:52 . 2008-10-03 10:15 247326 c:\windows\system32\dllcache\strmdll.dll
    + 2006-04-21 06:12 . 2009-12-31 16:14 352640 c:\windows\system32\dllcache\srv.sys
    - 2006-05-10 05:25 . 2009-04-29 04:31 474112

    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Tue 20 Jul 2010, 6:44 am

    c:\windows\system32\dllcache\shlwapi.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 474112 c:\windows\system32\dllcache\shlwapi.dll
    + 2007-04-25 14:21 . 2009-06-25 08:17 168448 c:\windows\system32\dllcache\schannel.dll
    + 2009-10-12 13:54 . 2009-10-12 13:54 112128 c:\windows\system32\dllcache\rastls.dll
    + 2009-10-13 10:53 . 2009-10-13 10:53 266752 c:\windows\system32\dllcache\oakley.dll
    + 2009-02-06 18:46 . 2009-02-06 18:46 408064 c:\windows\system32\dllcache\netlogon.dll
    + 2009-08-05 09:11 . 2009-08-05 09:11 204800 c:\windows\system32\dllcache\mswebdvd.dll
    + 2009-06-25 08:17 . 2009-06-25 08:17 136192 c:\windows\system32\dllcache\msv1_0.dll
    + 2009-10-22 22:06 . 2009-06-05 07:42 655872 c:\windows\system32\dllcache\mstscax.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 532480 c:\windows\system32\dllcache\mstime.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 532480 c:\windows\system32\dllcache\mstime.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 146432 c:\windows\system32\dllcache\msrating.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 146432 c:\windows\system32\dllcache\msrating.dll
    + 2009-12-16 12:58 . 2009-12-16 12:58 343040 c:\windows\system32\dllcache\mspaint.exe
    + 2006-05-10 05:25 . 2010-04-16 15:20 449024 c:\windows\system32\dllcache\mshtmled.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 449024 c:\windows\system32\dllcache\mshtmled.dll
    + 2006-05-05 09:41 . 2010-02-24 12:31 454016 c:\windows\system32\dllcache\mrxsmb.sys
    + 2006-08-17 12:28 . 2009-06-25 08:17 729600 c:\windows\system32\dllcache\lsasrv.dll
    + 2009-06-25 08:17 . 2009-06-25 08:17 301568 c:\windows\system32\dllcache\kerberos.dll
    - 2006-05-18 05:24 . 2007-12-18 14:40 450560 c:\windows\system32\dllcache\jscript.dll
    + 2006-05-18 05:24 . 2009-08-21 09:46 450560 c:\windows\system32\dllcache\jscript.dll
    - 2006-07-27 13:24 . 2008-04-11 18:50 683520 c:\windows\system32\dllcache\inetcomm.dll
    + 2006-07-27 13:24 . 2010-01-29 15:08 683520 c:\windows\system32\dllcache\inetcomm.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 251904 c:\windows\system32\dllcache\iepeers.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 251904 c:\windows\system32\dllcache\iepeers.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 205312 c:\windows\system32\dllcache\dxtrans.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 205312 c:\windows\system32\dllcache\dxtrans.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 357888 c:\windows\system32\dllcache\dxtmsft.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 357888 c:\windows\system32\dllcache\dxtmsft.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 151040 c:\windows\system32\dllcache\cdfview.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 151040 c:\windows\system32\dllcache\cdfview.dll
    + 2010-04-20 05:51 . 2010-04-20 05:51 285696 c:\windows\system32\dllcache\atmfd.dll
    + 2006-08-16 11:58 . 2010-02-12 04:47 100864 c:\windows\system32\dllcache\6to4svc.dll
    - 2004-08-10 17:50 . 2009-04-29 04:31 151040 c:\windows\system32\cdfview.dll
    + 2004-08-10 17:50 . 2010-04-16 15:20 151040 c:\windows\system32\cdfview.dll
    - 2004-08-10 17:50 . 2004-08-04 10:00 285696 c:\windows\system32\atmfd.dll
    + 2004-08-10 17:50 . 2010-04-20 05:51 285696 c:\windows\system32\atmfd.dll
    + 2004-08-10 17:50 . 2010-02-12 04:47 100864 c:\windows\system32\6to4svc.dll
    + 2009-08-08 06:35 . 2009-08-08 06:35 819016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    - 2007-04-14 00:58 . 2007-04-14 00:58 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
    + 2008-05-28 04:49 . 2008-05-28 04:49 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
    - 2007-04-14 00:56 . 2007-04-14 00:56 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
    + 2008-05-28 04:48 . 2008-05-28 04:48 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
    + 2008-05-28 05:30 . 2008-05-28 05:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
    - 2007-04-14 01:30 . 2007-04-14 01:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
    + 2010-07-19 16:51 . 2010-07-19 16:51 429568 c:\windows\Installer\15e37aa.msi
    + 2006-04-14 18:59 . 2010-02-24 12:31 454016 c:\windows\Driver Cache\i386\mrxsmb.sys
    + 2010-07-19 16:54 . 2010-07-19 16:54 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_10bd1d31\System.Drawing.dll
    + 2010-07-19 17:02 . 2010-07-19 17:02 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\6b8f2e778eba3931057217c2512b201c\System.Web.RegularExpressions.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 684032 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\4bdd3ce8337c4619dfb09de5ab3f9b62\System.Transactions.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 233472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\47d862e0dc37c830cc3397decf6c0590\System.ServiceProcess.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 733184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\428a3be3d5be01f129e0effdc455d831\System.Security.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 294912 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\ff85d9d54701c8cde7b513ff808fd5e3\System.EnterpriseServices.Wrapper.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 659456 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\ff85d9d54701c8cde7b513ff808fd5e3\System.EnterpriseServices.ni.dll
    + 2010-07-19 16:59 . 2010-07-19 16:59 229376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\4593151ab44d4f61e4cafaf9e77a8d25\System.Drawing.Design.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 512000 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\135aa2f31c01565700d44313b925a205\System.DirectoryServices.Protocols.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 167936 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ab1dd1079764acac4cbe55d6555f4ff7\Microsoft.Build.Utilities.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 876544 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\9e2334dbe9e76dd6fc2bde86c9b515b9\Microsoft.Build.Engine.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\58ec7ce15fd463d65d3e45db4e0613cf\CustomMarshalers.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 884736 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\2a66ea6b955eabdb437c6cfcac78c45e\AspNetMMCExt.ni.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 884736 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 884736 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    - 2008-04-14 02:08 . 2008-04-14 02:08 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    - 2008-04-14 02:08 . 2008-04-14 02:08 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 299008 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 299008 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    - 2008-04-14 02:08 . 2008-04-14 02:08 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 933888 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 933888 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 741376 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 741376 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2008-04-14 02:08 . 2008-04-14 02:08 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 671744 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 671744 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    - 2008-04-14 02:08 . 2008-04-14 02:08 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 261120 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 261120 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 483840 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 483840 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    + 2004-08-10 17:50 . 2009-11-21 16:36 470528 c:\windows\AppPatch\aclayers.dll
    + 2010-07-19 16:59 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB975025\update\updspapi.dll
    + 2010-07-19 16:59 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB975025\update\update.exe
    + 2010-07-19 16:59 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB975025\spuninst.exe
    + 2010-07-19 16:59 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB974571\update\updspapi.dll
    + 2010-07-19 16:59 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB974571\update\update.exe
    + 2010-07-19 16:59 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB974571\spuninst.exe
    + 2010-07-19 17:00 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB974112\update\updspapi.dll
    + 2010-07-19 17:00 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB974112\update\update.exe
    + 2010-07-19 17:00 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB974112\spuninst.exe
    + 2009-08-26 08:03 . 2009-08-26 08:03 247326 c:\windows\$hf_mig$\KB974112\SP3QFE\strmdll.dll
    + 2009-08-26 08:00 . 2009-08-26 08:00 247326 c:\windows\$hf_mig$\KB974112\SP3GDR\strmdll.dll
    + 2009-08-26 07:58 . 2009-08-26 07:58 247326 c:\windows\$hf_mig$\KB974112\SP2QFE\strmdll.dll
    + 2010-07-19 16:52 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB973815\update\updspapi.dll
    + 2010-07-19 16:52 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB973815\update\update.exe
    + 2010-07-19 16:52 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB973815\spuninst.exe
    + 2009-08-05 08:52 . 2009-08-05 08:52 204800 c:\windows\$hf_mig$\KB973815\SP3QFE\mswebdvd.dll
    + 2009-08-05 09:01 . 2009-08-05 09:01 204800 c:\windows\$hf_mig$\KB973815\SP3GDR\mswebdvd.dll
    + 2009-08-05 08:42 . 2009-08-05 08:42 204800 c:\windows\$hf_mig$\KB973815\SP2QFE\mswebdvd.dll
    + 2010-07-19 16:58 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB973507\update\updspapi.dll
    + 2010-07-19 16:58 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB973507\update\update.exe
    + 2010-07-19 16:58 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB973507\spuninst.exe
    + 2010-07-19 17:00 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB971657\update\updspapi.dll
    + 2010-07-19 17:00 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB971657\update\update.exe
    + 2010-07-19 17:00 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB971657\spuninst.exe
    + 2009-06-10 06:17 . 2009-06-10 06:17 134144 c:\windows\$hf_mig$\KB971657\SP3QFE\wkssvc.dll
    + 2009-06-10 06:14 . 2009-06-10 06:14 132096 c:\windows\$hf_mig$\KB971657\SP3GDR\wkssvc.dll
    + 2009-06-10 06:26 . 2009-06-10 06:26 134144 c:\windows\$hf_mig$\KB971657\SP2QFE\wkssvc.dll
    + 2010-07-19 17:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB969059\update\updspapi.dll
    + 2010-07-19 17:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB969059\update\update.exe
    + 2010-07-19 17:01 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB969059\spuninst.exe
    + 2010-07-19 16:51 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB968389\update\updspapi.dll
    + 2010-07-19 16:51 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB968389\update\update.exe
    + 2010-07-19 16:51 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB968389\spuninst.exe
    + 2009-06-25 08:41 . 2009-06-25 08:41 147456 c:\windows\$hf_mig$\KB968389\SP3QFE\schannel.dll
    + 2009-06-25 08:41 . 2009-06-25 08:41 136704 c:\windows\$hf_mig$\KB968389\SP3QFE\msv1_0.dll
    + 2009-06-26 09:41 . 2009-06-26 09:41 730112 c:\windows\$hf_mig$\KB968389\SP3QFE\lsasrv.dll
    + 2009-06-25 08:41 . 2009-06-25 08:41 301568 c:\windows\$hf_mig$\KB968389\SP3QFE\kerberos.dll
    + 2009-06-25 08:25 . 2009-06-25 08:25 147456 c:\windows\$hf_mig$\KB968389\SP3GDR\schannel.dll
    + 2009-06-25 08:25 . 2009-06-25 08:25 136192 c:\windows\$hf_mig$\KB968389\SP3GDR\msv1_0.dll
    + 2009-06-25 08:25 . 2009-06-25 08:25 730112 c:\windows\$hf_mig$\KB968389\SP3GDR\lsasrv.dll
    + 2009-06-25 08:25 . 2009-06-25 08:25 301568 c:\windows\$hf_mig$\KB968389\SP3GDR\kerberos.dll
    + 2010-07-19 17:03 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB960859\update\updspapi.dll
    + 2010-07-19 17:03 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB960859\update\update.exe
    + 2010-07-19 17:03 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB960859\spuninst.exe
    + 2009-10-22 22:07 . 2009-08-13 13:55 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll
    + 2009-07-21 04:03 . 2009-07-21 04:03 1348432 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9876.0_x-ww_a621d1d5\msxml4.dll
    + 2004-08-10 17:51 . 2010-04-03 10:39 2377576 c:\windows\system32\WMVCore.dll
    + 2004-08-10 17:51 . 2009-07-13 14:08 5537792 c:\windows\system32\wmp.dll
    - 2004-08-10 17:51 . 2007-04-30 12:20 5537792 c:\windows\system32\wmp.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 1509888 c:\windows\system32\shdocvw.dll
    - 2004-08-10 17:51 . 2006-06-22 05:06 1435648 c:\windows\system32\query.dll
    + 2004-08-10 17:51 . 2009-07-17 16:27 1435648 c:\windows\system32\query.dll
    + 2004-08-10 17:51 . 2010-02-05 18:40 1291264 c:\windows\system32\quartz.dll
    + 2004-08-10 17:51 . 2010-02-16 17:35 2143744 c:\windows\system32\ntoskrnl.exe
    + 2004-08-04 03:59 . 2010-02-16 16:57 2021888 c:\windows\system32\ntkrnlpa.exe
    + 2009-07-21 04:05 . 2009-07-21 04:05 1348432 c:\windows\system32\msxml4.dll
    + 2004-08-10 17:51 . 2009-07-31 04:57 1172480 c:\windows\system32\msxml3.dll
    + 2004-08-10 17:51 . 2010-04-16 15:20 3073024 c:\windows\system32\mshtml.dll
    + 2004-08-10 17:51 . 2010-04-03 10:39 2377576 c:\windows\system32\dllcache\WMVCore.dll
    + 2009-07-13 14:08 . 2009-07-13 14:08 5537792 c:\windows\system32\dllcache\wmp.dll
    + 2007-03-08 13:47 . 2010-05-02 05:56 1850880 c:\windows\system32\dllcache\win32k.sys
    + 2006-05-29 15:32 . 2010-04-16 15:20 1509888 c:\windows\system32\dllcache\shdocvw.dll
    - 2006-06-22 05:06 . 2006-06-22 05:06 1435648 c:\windows\system32\dllcache\query.dll
    + 2006-06-22 05:06 . 2009-07-17 16:27 1435648 c:\windows\system32\dllcache\query.dll
    + 2007-10-29 22:43 . 2010-02-05 18:40 1291264 c:\windows\system32\dllcache\quartz.dll
    + 2007-02-28 09:55 . 2010-02-16 17:37 2186880 c:\windows\system32\dllcache\ntoskrnl.exe
    + 2007-02-28 09:15 . 2010-02-16 16:57 2021888 c:\windows\system32\dllcache\ntkrpamp.exe
    + 2007-02-28 09:15 . 2010-02-17 15:57 2063744 c:\windows\system32\dllcache\ntkrnlpa.exe
    + 2007-02-28 09:53 . 2010-02-16 17:35 2143744 c:\windows\system32\dllcache\ntkrnlmp.exe
    + 2006-09-13 05:01 . 2009-07-31 04:57 1172480 c:\windows\system32\dllcache\msxml3.dll
    + 2006-11-08 05:06 . 2010-01-29 15:08 1315840 c:\windows\system32\dllcache\msoe.dll
    + 2006-05-19 15:06 . 2010-04-16 15:20 3073024 c:\windows\system32\dllcache\mshtml.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 1054208 c:\windows\system32\dllcache\danim.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 1054208 c:\windows\system32\dllcache\danim.dll
    + 2006-05-10 05:25 . 2010-04-16 15:20 1024000 c:\windows\system32\dllcache\browseui.dll
    - 2006-05-10 05:25 . 2009-04-29 04:31 1024000 c:\windows\system32\dllcache\browseui.dll
    + 2004-08-10 17:50 . 2010-04-16 15:20 1054208 c:\windows\system32\danim.dll
    - 2004-08-10 17:50 . 2009-04-29 04:31 1054208 c:\windows\system32\danim.dll
    + 2004-08-10 17:50 . 2010-04-16 15:20 1024000 c:\windows\system32\browseui.dll
    - 2004-08-10 17:50 . 2009-04-29 04:31 1024000 c:\windows\system32\browseui.dll
    + 2009-08-08 06:35 . 2009-08-08 06:35 5849920 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    + 2009-08-08 06:35 . 2009-08-08 06:35 4345856 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    - 2007-04-14 01:35 . 2007-04-14 01:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
    + 2008-05-28 05:35 . 2008-05-28 05:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
    - 2007-04-14 01:35 . 2007-04-14 01:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
    + 2008-05-28 05:35 . 2008-05-28 05:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
    + 2008-05-28 04:48 . 2008-05-28 04:48 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
    - 2007-04-14 00:57 . 2007-04-14 00:57 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
    + 2008-05-28 04:48 . 2008-05-28 04:48 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
    - 2007-04-14 00:57 . 2007-04-14 00:57 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
    + 2008-05-28 04:43 . 2008-05-28 04:43 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
    - 2007-04-14 00:50 . 2007-04-14 00:50 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
    + 2009-08-10 03:32 . 2009-08-10 03:32 5288960 c:\windows\Installer\15e37c8.msp
    + 2005-03-02 00:59 . 2010-02-16 17:37 2186880 c:\windows\Driver Cache\i386\ntoskrnl.exe
    + 2006-04-14 19:01 . 2010-02-16 16:57 2021888 c:\windows\Driver Cache\i386\ntkrpamp.exe
    + 2005-03-02 00:34 . 2010-02-17 15:57 2063744 c:\windows\Driver Cache\i386\ntkrnlpa.exe
    + 2006-04-14 19:01 . 2010-02-16 17:35 2143744 c:\windows\Driver Cache\i386\ntkrnlmp.exe
    + 2010-07-19 16:54 . 2010-07-19 16:54 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_026d0291\System.dll
    + 2010-07-19 16:54 . 2010-07-19 16:54 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_1774c0a8\System.Xml.dll
    + 2010-07-19 16:54 . 2010-07-19 16:54 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_00c03d1c\System.Windows.Forms.dll
    + 2010-07-19 16:54 . 2010-07-19 16:54 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_7e785275\System.Design.dll
    + 2010-07-19 16:54 . 2010-07-19 16:54 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_f1a6c14e\mscorlib.dll
    + 2010-07-19 16:58 . 2010-07-19 16:58 8310784 c:\windows\assembly\NativeImages_v2.0.50727_32\System\ccfeb59f4a9b75909eb2d1121232a769\System.ni.dll
    + 2010-07-19 16:59 . 2010-07-19 16:59 5771264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\717cce3690d643df19d6a4117283048e\System.Xml.ni.dll
    + 2010-07-19 17:02 . 2010-07-19 17:02 1986560 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\aa319d767042e97c692041f76f123f2f\System.Web.Services.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 2342912 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\b7092e8403b56e3913488855e45a35ff\System.Web.Mobile.ni.dll
    + 2010-07-19 16:59 . 2010-07-19 16:59 1667072 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\e58e83951091f2616344c5d2a6787660\System.Drawing.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 1224704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\e96695c65a4104ee4687f3e5f0581d34\System.DirectoryServices.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 1798144 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\f0a1895c7d475f156ed4cdd9f0bd2797\System.Deployment.ni.dll
    + 2010-07-19 16:58 . 2010-07-19 16:58 7102464 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\b39a611d2b2fc659d5472dd76b24d3b2\System.Data.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 1011712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e2de26078a8c3d29dbfcf408e23aa2b1\System.Configuration.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 1740800 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\ed0cdc51d89bb41a9ab760ca3cf52bf9\Microsoft.VisualBasic.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 1695744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\b846f5c1b90e4222e79a420d92062f79\Microsoft.Build.Tasks.ni.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 3076096 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 3076096 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 2068480 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    - 2008-04-14 02:08 . 2008-04-14 02:08 2068480 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 5013504 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 5013504 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 5070848 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 5070848 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 5431296 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    - 2008-04-14 02:08 . 2008-04-14 02:08 5431296 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 3036160 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    - 2008-04-14 02:09 . 2008-04-14 02:09 3036160 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    + 2010-07-19 16:56 . 2010-07-19 16:56 4345856 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2010-07-19 16:54 . 2010-07-19 16:54 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
    - 2007-08-22 23:33 . 2007-08-22 23:33 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
    + 2010-07-19 16:54 . 2010-07-19 16:54 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
    - 2007-08-22 23:33 . 2007-08-22 23:33 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
    + 2009-07-17 16:01 . 2009-07-17 16:01 1435648 c:\windows\$hf_mig$\KB969059\SP3QFE\query.dll
    + 2009-07-17 16:22 . 2009-07-17 16:22 1435648 c:\windows\$hf_mig$\KB969059\SP3GDR\query.dll
    + 2009-07-17 16:10 . 2009-07-17 16:10 1435648 c:\windows\$hf_mig$\KB969059\SP2QFE\query.dll
    + 2009-08-11 01:08 . 2009-08-11 01:08 11315712 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp
    + 2009-08-10 18:09 . 2009-08-10 18:09 17254912 c:\windows\Installer\15e37c0.msp
    + 2010-07-19 16:59 . 2010-07-19 16:59 13193216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\9d25b8eabd8203e4d0490363140c4526\System.Windows.Forms.ni.dll
    + 2010-07-19 17:01 . 2010-07-19 17:01 12517376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\16a34a274ee877b4cf03d1a1bb57eb82\System.Web.ni.dll
    + 2010-07-19 16:59 . 2010-07-19 16:59 10936320 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\2aab58cae4d998cf867f483302e94c27\System.Design.ni.dll
    + 2010-07-19 16:57 . 2010-07-19 16:57 11436032 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\fee8c8ba9b84a7832274adcbfc9d5ca4\mscorlib.ni.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Download"="c:\program files\Bellsouth\HelpCenter\ssGet.exe" [2008-02-29 893952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ShowLOMControl"="1 (0x1)" [X]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
    "SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
    "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-14 98304]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
    "VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
    "MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-12 1121792]
    "MSKAGENTEXE"="c:\progra~1\McAfee\SPAMKI~1\MSKAGE~1.EXE" [2010-07-19 25600]
    "tgcmd"="c:\program files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
    "lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2005-09-30 200704]
    "EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2005-08-01 94208]
    "ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
    "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-4-14 156784]
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-14 24576]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/17/2010 1:25 PM 64288]
    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/17/2010 11:38 AM 218592]
    R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [7/17/2010 11:43 AM 112592]
    R3 lxci_device;lxci_device;c:\windows\system32\lxcicoms.exe -service --> c:\windows\system32\lxcicoms.exe -service [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/12/2010 4:55 AM 1352832]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/17/2010 11:38 AM 366840]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]

    2009-10-13 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (CLOVVORN-Shu Lovvorn).job
    - c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-04-14 22:18]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = [You must be registered and logged in to see this link.]
    mStart Page = [You must be registered and logged in to see this link.]
    mWindow Title = Windows Internet Explorer provided by Comcast
    uInternet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
    uSearchAssistant = [You must be registered and logged in to see this link.]
    uSearchURL,(Default) = [You must be registered and logged in to see this link.]
    Trusted Zone: musicmatch.com\online
    DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - [You must be registered and logged in to see this link.]
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
    Rootkit scan 2010-07-19 15:37
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2010-07-19 15:39:16
    ComboFix-quarantined-files.txt 2010-07-19 19:39
    ComboFix2.txt 2010-07-19 10:35
    ComboFix3.txt 2010-07-19 01:12
    ComboFix4.txt 2010-07-18 23:23

    Pre-Run: 42,336,399,360 bytes free
    Post-Run: 42,326,847,488 bytes free

    - - End Of File - - 34A9AE55A70401D959330D69A029B7BA

    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sneakyone on Tue 20 Jul 2010, 6:55 am

    Hi,

    I will give you some guidelines at the end, the CFScript isn't killing the Renovate worm like I want it to, time to destroy the worm now.

    Please download Malwarebytes Anti-Malware from Here.


    Double Click mbam-setup.exe to install the application.

    • Make sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.

    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

    =========

    Re-running ComboFix to remove infections:

    1. Close any open browsers.
    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    3. Open notepad and copy/paste the text in the quotebox below into it:
      Code:

      RenV::
      c:\program files\NetWaiting\netwaiting                  .exe
      c:\program files\NetWaiting\netwaiting                .exe
      c:\program files\NetWaiting\netwaiting              .exe
      c:\program files\NetWaiting\netwaiting            .exe
      c:\program files\NetWaiting\netwaiting          .exe
      c:\program files\NetWaiting\netwaiting        .exe
      c:\program files\NetWaiting\netwaiting      .exe
      c:\program files\NetWaiting\netwaiting    .exe
      c:\program files\NetWaiting\netwaiting  .exe

    4. Save this as CFScript.txt, in the same location as ComboFix.exe



    5. Referring to the picture above, drag CFScript into ComboFix.exe
    6. When finished, it shall produce a log for you at C:\ComboFix.txt
    7. Please post the contents of the log in your next reply.


    I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Tue 20 Jul 2010, 7:32 am

    ComboFix 10-07-16.02 - Christina Lovvorn 07/19/2010 16:20:33.6.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.668 [GMT -4:00]
    Running from: c:\documents and settings\Christina Lovvorn\Desktop\commy.exe
    Command switches used :: c:\documents and settings\Christina Lovvorn\Desktop\CFscript.txt
    AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
    FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .

    ((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
    .

    2010-07-19 20:02 . 2010-07-19 20:02 -------- d-----w- c:\documents and settings\Christina Lovvorn\Application Data\Malwarebytes
    2010-07-19 20:02 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-07-19 20:02 . 2010-07-19 20:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-07-19 20:02 . 2010-07-19 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-07-19 20:02 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-07-19 16:52 . 2010-07-19 16:52 -------- d-----w- c:\windows\ServicePackFiles
    2010-07-18 23:27 . 2009-11-21 16:36 470528 ------w- c:\windows\system32\dllcache\aclayers.dll
    2010-07-18 23:27 . 2010-06-14 14:30 743936 ------w- c:\windows\system32\dllcache\helpsvc.exe
    2010-07-18 23:27 . 2009-10-15 17:21 82432 ------w- c:\windows\system32\dllcache\fontsub.dll
    2010-07-18 23:27 . 2009-10-23 14:27 3555328 ------w- c:\windows\system32\dllcache\moviemk.exe
    2010-07-17 17:25 . 2010-07-17 17:25 -------- dc----w- c:\windows\system32\DRVSTORE
    2010-07-17 17:25 . 2010-07-12 08:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-07-17 17:25 . 2010-07-17 17:25 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-07-17 17:15 . 2010-07-17 17:15 -------- d-----w- c:\documents and settings\Christina Lovvorn\Local Settings\Application Data\Sunbelt Software
    2010-07-17 17:14 . 2010-07-17 17:14 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
    2010-07-17 17:14 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
    2010-07-17 17:13 . 2010-07-17 17:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-07-17 17:13 . 2010-07-17 17:13 -------- d-----w- c:\program files\Lavasoft
    2010-07-17 15:43 . 2010-01-27 17:51 767952 ----a-w- c:\windows\BDTSupport.dll
    2010-07-17 15:43 . 2010-01-22 12:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
    2010-07-17 15:43 . 2009-10-28 04:36 1152444 ----a-w- c:\windows\UDB.zip
    2010-07-17 15:43 . 2008-11-26 15:08 131 ----a-w- c:\windows\IDB.zip
    2010-07-17 15:43 . 2010-01-22 12:56 165840 ----a-w- c:\windows\PCTBDRes.dll
    2010-07-17 15:43 . 2010-01-22 12:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
    2010-07-17 15:38 . 2010-02-05 13:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2010-07-17 15:38 . 2010-03-29 14:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2010-07-17 15:38 . 2009-11-23 17:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2010-07-17 15:38 . 2010-04-08 18:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2010-07-17 15:38 . 2010-07-17 19:06 -------- d-----w- c:\program files\Spyware Doctor
    2010-07-17 15:38 . 2010-07-17 15:44 -------- d-----w- c:\program files\Common Files\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\Christina Lovvorn\Application Data\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2010-07-17 15:37 . 2010-07-19 20:15 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-07-17 09:38 . 2010-07-17 09:38 53304 ----a-w- c:\documents and settings\Klovvorn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-07-17 09:38 . 2010-07-17 09:38 -------- d-----w- c:\documents and settings\Klovvorn\Local Settings\Application Data\Nancy Drew

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-19 17:12 . 2009-08-12 21:32 7639760 ----a-w- c:\documents and settings\Christina Lovvorn\HC43SInstaller.exe
    2010-07-19 00:57 . 2006-04-14 19:07 -------- d-----w- c:\program files\NetWaiting
    2010-07-19 00:57 . 2006-07-07 21:44 -------- d-----w- c:\program files\LIVEUPDATE
    2010-07-17 15:26 . 2006-09-19 23:45 -------- d-----w- c:\program files\Lx_cats
    2010-06-14 14:30 . 2004-08-10 18:02 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    2010-05-02 05:56 . 2004-08-10 17:51 1850880 ----a-w- c:\windows\system32\win32k.sys
    2006-05-21 10:05 . 2006-05-21 10:04 88 --sh--r- c:\windows\system32\575D6DB162.sys
    2006-05-21 10:05 . 2006-05-21 10:04 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
    .
    Code:
    <pre>
    c:\program files\NetWaiting\netwaiting                  .exe
    c:\program files\NetWaiting\netwaiting                .exe
    c:\program files\NetWaiting\netwaiting              .exe
    c:\program files\NetWaiting\netwaiting            .exe
    c:\program files\NetWaiting\netwaiting          .exe
    c:\program files\NetWaiting\netwaiting        .exe
    c:\program files\NetWaiting\netwaiting      .exe
    c:\program files\NetWaiting\netwaiting    .exe
    c:\program files\NetWaiting\netwaiting  .exe
    </pre>

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Download"="c:\program files\Bellsouth\HelpCenter\ssGet.exe" [2008-02-29 893952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ShowLOMControl"="1 (0x1)" [X]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
    "SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
    "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-14 98304]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
    "VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
    "MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-12 1121792]
    "tgcmd"="c:\program files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
    "lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2005-09-30 200704]
    "EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2005-08-01 94208]
    "ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
    "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-4-14 156784]
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-14 24576]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/17/2010 1:25 PM 64288]
    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/17/2010 11:38 AM 218592]
    R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [7/17/2010 11:43 AM 112592]
    R3 lxci_device;lxci_device;c:\windows\system32\lxcicoms.exe -service --> c:\windows\system32\lxcicoms.exe -service [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/12/2010 4:55 AM 1352832]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/17/2010 11:38 AM 366840]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]

    2009-10-13 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (CLOVVORN-Shu Lovvorn).job
    - c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-04-14 22:18]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = [You must be registered and logged in to see this link.]
    mStart Page = [You must be registered and logged in to see this link.]
    mWindow Title = Windows Internet Explorer provided by Comcast
    uInternet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
    uSearchAssistant = [You must be registered and logged in to see this link.]
    uSearchURL,(Default) = [You must be registered and logged in to see this link.]
    Trusted Zone: musicmatch.com\online
    DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - [You must be registered and logged in to see this link.]
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
    Rootkit scan 2010-07-19 16:26
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2010-07-19 16:28:39
    ComboFix-quarantined-files.txt 2010-07-19 20:28
    ComboFix2.txt 2010-07-19 19:39
    ComboFix3.txt 2010-07-19 10:35
    ComboFix4.txt 2010-07-19 01:12
    ComboFix5.txt 2010-07-19 20:19

    Pre-Run: 42,311,213,056 bytes free
    Post-Run: 42,305,921,024 bytes free

    - - End Of File - - 790B5089D28F8AB59DEFBC13CD6CDAA1

    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Tue 20 Jul 2010, 7:33 am

    Malwarebytes' Anti-Malware 1.46
    [You must be registered and logged in to see this link.]

    Database version: 4327

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 6.0.2900.2180

    7/19/2010 4:11:47 PM
    mbam-log-2010-07-19 (16-11-47).txt

    Scan type: Quick scan
    Objects scanned: 150186
    Time elapsed: 6 minute(s), 44 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 5
    Registry Data Items Infected: 0
    Folders Infected: 2
    Files Infected: 97

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mskagentexe (Trojan.Dropper) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\l (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mbt (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mfa (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udfa (Backdoor.Bot) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\Documents and Settings\All Users\Application Data\14487630 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374 (Rogue.Multiple) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Program Files\McAfee\SpamKiller\mskage~1.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\3.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\8.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\vapa.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\xxqkc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\yiuvab.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe74 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe51 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe46 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe1357 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe1441 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe169 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe216 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe227 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe279 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe393 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wpv211232248330.cpx (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wpv231232248398.cpx (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wpv321232248330.cpx (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wpv991232248330.cpx (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\siyadoro.s (Rogue.SecurityTool) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe101 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe113 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe137 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe1378 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe244 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe253 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe263 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe616 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe72 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe54 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe56 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe598 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe60 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe61 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe62 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe67 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe68 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe787 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe81 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe80 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe82 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe85 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe86 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe87 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe89 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe92 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe96 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\reader_s.exe98 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe102 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe110 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe123 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe170 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe172 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe217 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe228 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe234 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hkcmd.exe50 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe55 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe5541 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe64 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe786 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe80 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe89 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\igfxtray.exe98 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\drivers\e602a061.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Christina Lovvorn\reader_s.exe56 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Christina Lovvorn\reader_s.exe58 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Christina Lovvorn\reader_s.exe87 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Klovvorn\reader_s.exe60 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\sysguard.exe119 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\sysguard.exe54 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\sysguard.exe593 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\sysguard.exe85 (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\Installer\e3ca7.msi (Rootkit.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\14487630\14487630.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374 .exe (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe136 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe1377 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe243 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe252 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe262 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe68 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe71 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe73 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe75 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe78 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe79 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe80 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe86 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe88 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe91 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe95 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\18574374.exe99 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\18574374\pc18574374ins (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.

    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sneakyone on Tue 20 Jul 2010, 8:10 am

    Hi,

    Do you also have the ComboFix log?


    I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Tue 20 Jul 2010, 8:14 am

    It was above the malware log...

    ComboFix 10-07-16.02 - Christina Lovvorn 07/19/2010 16:20:33.6.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.668 [GMT -4:00]
    Running from: c:\documents and settings\Christina Lovvorn\Desktop\commy.exe
    Command switches used :: c:\documents and settings\Christina Lovvorn\Desktop\CFscript.txt
    AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
    FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .

    ((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
    .

    2010-07-19 20:02 . 2010-07-19 20:02 -------- d-----w- c:\documents and settings\Christina Lovvorn\Application Data\Malwarebytes
    2010-07-19 20:02 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-07-19 20:02 . 2010-07-19 20:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-07-19 20:02 . 2010-07-19 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-07-19 20:02 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-07-19 16:52 . 2010-07-19 16:52 -------- d-----w- c:\windows\ServicePackFiles
    2010-07-18 23:27 . 2009-11-21 16:36 470528 ------w- c:\windows\system32\dllcache\aclayers.dll
    2010-07-18 23:27 . 2010-06-14 14:30 743936 ------w- c:\windows\system32\dllcache\helpsvc.exe
    2010-07-18 23:27 . 2009-10-15 17:21 82432 ------w- c:\windows\system32\dllcache\fontsub.dll
    2010-07-18 23:27 . 2009-10-23 14:27 3555328 ------w- c:\windows\system32\dllcache\moviemk.exe
    2010-07-17 17:25 . 2010-07-17 17:25 -------- dc----w- c:\windows\system32\DRVSTORE
    2010-07-17 17:25 . 2010-07-12 08:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-07-17 17:25 . 2010-07-17 17:25 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-07-17 17:15 . 2010-07-17 17:15 -------- d-----w- c:\documents and settings\Christina Lovvorn\Local Settings\Application Data\Sunbelt Software
    2010-07-17 17:14 . 2010-07-17 17:14 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
    2010-07-17 17:14 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
    2010-07-17 17:13 . 2010-07-17 17:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-07-17 17:13 . 2010-07-17 17:13 -------- d-----w- c:\program files\Lavasoft
    2010-07-17 15:43 . 2010-01-27 17:51 767952 ----a-w- c:\windows\BDTSupport.dll
    2010-07-17 15:43 . 2010-01-22 12:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
    2010-07-17 15:43 . 2009-10-28 04:36 1152444 ----a-w- c:\windows\UDB.zip
    2010-07-17 15:43 . 2008-11-26 15:08 131 ----a-w- c:\windows\IDB.zip
    2010-07-17 15:43 . 2010-01-22 12:56 165840 ----a-w- c:\windows\PCTBDRes.dll
    2010-07-17 15:43 . 2010-01-22 12:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
    2010-07-17 15:38 . 2010-02-05 13:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2010-07-17 15:38 . 2010-03-29 14:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2010-07-17 15:38 . 2009-11-23 17:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2010-07-17 15:38 . 2010-04-08 18:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2010-07-17 15:38 . 2010-07-17 19:06 -------- d-----w- c:\program files\Spyware Doctor
    2010-07-17 15:38 . 2010-07-17 15:44 -------- d-----w- c:\program files\Common Files\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\Christina Lovvorn\Application Data\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2010-07-17 15:37 . 2010-07-19 20:15 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-07-17 09:38 . 2010-07-17 09:38 53304 ----a-w- c:\documents and settings\Klovvorn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-07-17 09:38 . 2010-07-17 09:38 -------- d-----w- c:\documents and settings\Klovvorn\Local Settings\Application Data\Nancy Drew

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-19 17:12 . 2009-08-12 21:32 7639760 ----a-w- c:\documents and settings\Christina Lovvorn\HC43SInstaller.exe
    2010-07-19 00:57 . 2006-04-14 19:07 -------- d-----w- c:\program files\NetWaiting
    2010-07-19 00:57 . 2006-07-07 21:44 -------- d-----w- c:\program files\LIVEUPDATE
    2010-07-17 15:26 . 2006-09-19 23:45 -------- d-----w- c:\program files\Lx_cats
    2010-06-14 14:30 . 2004-08-10 18:02 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    2010-05-02 05:56 . 2004-08-10 17:51 1850880 ----a-w- c:\windows\system32\win32k.sys
    2006-05-21 10:05 . 2006-05-21 10:04 88 --sh--r- c:\windows\system32\575D6DB162.sys
    2006-05-21 10:05 . 2006-05-21 10:04 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
    .
    Code:
    <pre>
    c:\program files\NetWaiting\netwaiting                  .exe
    c:\program files\NetWaiting\netwaiting                .exe
    c:\program files\NetWaiting\netwaiting              .exe
    c:\program files\NetWaiting\netwaiting            .exe
    c:\program files\NetWaiting\netwaiting          .exe
    c:\program files\NetWaiting\netwaiting        .exe
    c:\program files\NetWaiting\netwaiting      .exe
    c:\program files\NetWaiting\netwaiting    .exe
    c:\program files\NetWaiting\netwaiting  .exe
    </pre>

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Download"="c:\program files\Bellsouth\HelpCenter\ssGet.exe" [2008-02-29 893952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ShowLOMControl"="1 (0x1)" [X]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
    "SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
    "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-14 98304]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
    "VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
    "MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-12 1121792]
    "tgcmd"="c:\program files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
    "lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2005-09-30 200704]
    "EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2005-08-01 94208]
    "ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
    "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-4-14 156784]
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-14 24576]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/17/2010 1:25 PM 64288]
    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/17/2010 11:38 AM 218592]
    R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [7/17/2010 11:43 AM 112592]
    R3 lxci_device;lxci_device;c:\windows\system32\lxcicoms.exe -service --> c:\windows\system32\lxcicoms.exe -service [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/12/2010 4:55 AM 1352832]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/17/2010 11:38 AM 366840]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]

    2009-10-13 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (CLOVVORN-Shu Lovvorn).job
    - c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-04-14 22:18]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = [You must be registered and logged in to see this link.]
    mStart Page = [You must be registered and logged in to see this link.]
    mWindow Title = Windows Internet Explorer provided by Comcast
    uInternet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
    uSearchAssistant = [You must be registered and logged in to see this link.]
    uSearchURL,(Default) = [You must be registered and logged in to see this link.]
    Trusted Zone: musicmatch.com\online
    DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - [You must be registered and logged in to see this link.]
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
    Rootkit scan 2010-07-19 16:26
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2010-07-19 16:28:39
    ComboFix-quarantined-files.txt 2010-07-19 20:28
    ComboFix2.txt 2010-07-19 19:39
    ComboFix3.txt 2010-07-19 10:35
    ComboFix4.txt 2010-07-19 01:12
    ComboFix5.txt 2010-07-19 20:19

    Pre-Run: 42,311,213,056 bytes free
    Post-Run: 42,305,921,024 bytes free

    - - End Of File - - 790B5089D28F8AB59DEFBC13CD6CDAA1

    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sneakyone on Tue 20 Jul 2010, 8:27 am

    Ah, I see.

    This thing just won't die.....

    Re-running ComboFix to remove infections:

    1. Close any open browsers.
    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    3. Open notepad and copy/paste the text in the quotebox below into it:
      Code:

      KillAll::

      RenV::
      c:\program files\NetWaiting\netwaiting                  .exe
      c:\program files\NetWaiting\netwaiting                .exe
      c:\program files\NetWaiting\netwaiting              .exe
      c:\program files\NetWaiting\netwaiting            .exe
      c:\program files\NetWaiting\netwaiting          .exe
      c:\program files\NetWaiting\netwaiting        .exe
      c:\program files\NetWaiting\netwaiting      .exe
      c:\program files\NetWaiting\netwaiting    .exe
      c:\program files\NetWaiting\netwaiting  .exe

    4. Save this as CFScript.txt, in the same location as ComboFix.exe



    5. Referring to the picture above, drag CFScript into ComboFix.exe
    6. When finished, it shall produce a log for you at C:\ComboFix.txt
    7. Please post the contents of the log in your next reply.


    I'm livin' life in the fast lane.


    Sneakyone

    Tech Officer
    Tech Officer

    Posts : 2707
    Joined : 2010-01-10
    Operating System : Windows 7 Ultimate 64-bit

    View user profile http://twitter.com/AVerySneakyone

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by joffreyj on Tue 20 Jul 2010, 9:11 am

    ComboFix 10-07-16.02 - Christina Lovvorn 07/19/2010 17:59:09.7.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.531 [GMT -4:00]
    Running from: c:\documents and settings\Christina Lovvorn\Desktop\commy.exe
    Command switches used :: c:\documents and settings\Christina Lovvorn\Desktop\CFscript.txt
    AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
    FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .

    ((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
    .

    2010-07-19 20:02 . 2010-07-19 20:02 -------- d-----w- c:\documents and settings\Christina Lovvorn\Application Data\Malwarebytes
    2010-07-19 20:02 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-07-19 20:02 . 2010-07-19 20:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-07-19 20:02 . 2010-07-19 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-07-19 20:02 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-07-19 16:52 . 2010-07-19 16:52 -------- d-----w- c:\windows\ServicePackFiles
    2010-07-18 23:27 . 2009-11-21 16:36 470528 ------w- c:\windows\system32\dllcache\aclayers.dll
    2010-07-18 23:27 . 2010-06-14 14:30 743936 ------w- c:\windows\system32\dllcache\helpsvc.exe
    2010-07-18 23:27 . 2009-10-15 17:21 82432 ------w- c:\windows\system32\dllcache\fontsub.dll
    2010-07-18 23:27 . 2009-10-23 14:27 3555328 ------w- c:\windows\system32\dllcache\moviemk.exe
    2010-07-17 17:25 . 2010-07-17 17:25 -------- dc----w- c:\windows\system32\DRVSTORE
    2010-07-17 17:25 . 2010-07-12 08:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-07-17 17:25 . 2010-07-17 17:25 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-07-17 17:15 . 2010-07-17 17:15 -------- d-----w- c:\documents and settings\Christina Lovvorn\Local Settings\Application Data\Sunbelt Software
    2010-07-17 17:14 . 2010-07-17 17:14 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
    2010-07-17 17:14 . 2010-07-12 08:56 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
    2010-07-17 17:13 . 2010-07-17 17:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-07-17 17:13 . 2010-07-17 17:13 -------- d-----w- c:\program files\Lavasoft
    2010-07-17 15:43 . 2010-01-27 17:51 767952 ----a-w- c:\windows\BDTSupport.dll
    2010-07-17 15:43 . 2010-01-22 12:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
    2010-07-17 15:43 . 2009-10-28 04:36 1152444 ----a-w- c:\windows\UDB.zip
    2010-07-17 15:43 . 2008-11-26 15:08 131 ----a-w- c:\windows\IDB.zip
    2010-07-17 15:43 . 2010-01-22 12:56 165840 ----a-w- c:\windows\PCTBDRes.dll
    2010-07-17 15:43 . 2010-01-22 12:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
    2010-07-17 15:38 . 2010-02-05 13:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2010-07-17 15:38 . 2010-03-29 14:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2010-07-17 15:38 . 2009-11-23 17:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2010-07-17 15:38 . 2010-04-08 18:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2010-07-17 15:38 . 2010-07-17 19:06 -------- d-----w- c:\program files\Spyware Doctor
    2010-07-17 15:38 . 2010-07-17 15:44 -------- d-----w- c:\program files\Common Files\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\Christina Lovvorn\Application Data\PC Tools
    2010-07-17 15:38 . 2010-07-17 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2010-07-17 15:37 . 2010-07-19 22:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-07-17 09:38 . 2010-07-17 09:38 53304 ----a-w- c:\documents and settings\Klovvorn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-07-17 09:38 . 2010-07-17 09:38 -------- d-----w- c:\documents and settings\Klovvorn\Local Settings\Application Data\Nancy Drew

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-19 17:12 . 2009-08-12 21:32 7639760 ----a-w- c:\documents and settings\Christina Lovvorn\HC43SInstaller.exe
    2010-07-19 00:57 . 2006-04-14 19:07 -------- d-----w- c:\program files\NetWaiting
    2010-07-19 00:57 . 2006-07-07 21:44 -------- d-----w- c:\program files\LIVEUPDATE
    2010-07-17 15:26 . 2006-09-19 23:45 -------- d-----w- c:\program files\Lx_cats
    2010-06-14 14:30 . 2004-08-10 18:02 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    2010-05-02 05:56 . 2004-08-10 17:51 1850880 ----a-w- c:\windows\system32\win32k.sys
    2006-05-21 10:05 . 2006-05-21 10:04 88 --sh--r- c:\windows\system32\575D6DB162.sys
    2006-05-21 10:05 . 2006-05-21 10:04 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
    .
    Code:
    <pre>
    c:\program files\NetWaiting\netwaiting                  .exe
    c:\program files\NetWaiting\netwaiting                .exe
    c:\program files\NetWaiting\netwaiting              .exe
    c:\program files\NetWaiting\netwaiting            .exe
    c:\program files\NetWaiting\netwaiting          .exe
    c:\program files\NetWaiting\netwaiting        .exe
    c:\program files\NetWaiting\netwaiting      .exe
    c:\program files\NetWaiting\netwaiting    .exe
    c:\program files\NetWaiting\netwaiting  .exe
    </pre>

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Download"="c:\program files\Bellsouth\HelpCenter\ssGet.exe" [2008-02-29 893952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ShowLOMControl"="1 (0x1)" [X]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
    "SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
    "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-14 98304]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
    "VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
    "MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-12 1121792]
    "tgcmd"="c:\program files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
    "lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2005-09-30 200704]
    "EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2005-08-01 94208]
    "ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
    "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-4-14 156784]
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-14 24576]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/17/2010 1:25 PM 64288]
    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/17/2010 11:38 AM 218592]
    R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [7/17/2010 11:43 AM 112592]
    R3 lxci_device;lxci_device;c:\windows\system32\lxcicoms.exe -service --> c:\windows\system32\lxcicoms.exe -service [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/12/2010 4:55 AM 1352832]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/17/2010 11:38 AM 366840]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]

    2009-10-13 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (CLOVVORN-Shu Lovvorn).job
    - c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-04-14 22:18]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = [You must be registered and logged in to see this link.]
    mStart Page = [You must be registered and logged in to see this link.]
    mWindow Title = Windows Internet Explorer provided by Comcast
    uInternet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
    uSearchAssistant = [You must be registered and logged in to see this link.]
    uSearchURL,(Default) = [You must be registered and logged in to see this link.]
    Trusted Zone: musicmatch.com\online
    DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - [You must be registered and logged in to see this link.]
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
    Rootkit scan 2010-07-19 18:04
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Intel\Wireless\Bin\WLKeeper.exe
    c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\progra~1\mcafee.com\agent\mctskshd.exe
    c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
    c:\program files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    c:\windows\system32\wdfmgr.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\stsystra.exe
    c:\windows\system32\lxcicoms.exe
    c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
    c:\program files\Microsoft Office\Office\1033\msoffice.exe
    .
    **************************************************************************
    .
    Completion time: 2010-07-19 18:09:49 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-07-19 22:09
    ComboFix2.txt 2010-07-19 20:28
    ComboFix3.txt 2010-07-19 19:39
    ComboFix4.txt 2010-07-19 10:35
    ComboFix5.txt 2010-07-19 21:58

    Pre-Run: 42,319,192,064 bytes free
    Post-Run: 42,308,018,176 bytes free

    - - End Of File - - C98329C80E7A2B8A3999C069DC1FAA3B

    joffreyj

    Newbie Surfer
    Newbie Surfer

    Posts : 16
    Joined : 2010-07-18
    Operating System : windows xp home edition

    View user profile

    Back to top Go down

    Re: ntuser.dll calc.dll error messages

    Post by Sponsored content Today at 9:24 pm


    Sponsored content


    Back to top Go down

    Page 1 of 2 1, 2  Next

    View previous topic View next topic Back to top


     
    Permissions in this forum:
    You cannot reply to topics in this forum