I got up this morning and computer was working funny. I rebooted and crypt_20 would not end. I had no idea what this file was. I clicked end program and rebooted. I ran malwarebytes and found 6 or so virus's and/or rootkits. I rebooted and ran again. found 2 nasties this time. I repeated again and still 2 nasties. Girlfriend said she was on youtube and got redirected off site and something started and she closed it right away. Not in time I guess.
Rather than bother anyone with this online, I decided to just reformat. After reformatting I ran malwarebytes again and had 14 viruses and/or rootkits. So if reformatting won't get rid of them I think I need help.
The GmerOne.log is completely blank, but the rest is below.
Thanks in advance for any help. (currently can't open iexplorer etc...)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-10-11 02:42:26
Windows 5.1.2600 Service Pack 2
Running: tmorzbyi.exe; Driver: C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\awgdypod.sys
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Canon iP1600\PrinterDriverData@CnmSLM_TimeLastUpdated 1949031
---- EOF - GMER 1.0.15 ----
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4793
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13
10/11/2010 5:31:00 AM
mbam-log-2010-10-11 (05-31-00).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 319529
Time elapsed: 2 hour(s), 45 minute(s), 51 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 8
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\program files\microsoft\desktoplayer.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe) Good: (userinit.exe) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\hp\drivers\hplsbwatcher\lsburnwatcherSrv.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
C:\ComboFix\NircmdBSrv.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
C:\ComboFix\PEVSrv.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Desktop\fix computer\ATF-CleanerSrv.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
D:\MiniNT\system32\RESTORESrv.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
D:\MiniNT\system32\MBRSrv.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
D:\MiniNT\system32\shutdownSrv.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
C:\Program Files\Microsoft\desktoplayer.exe (Trojan.Agent) -> Delete on reboot.
DDS (Ver_10-10-10.03) - NTFSx86
Run by HP_Owner at 5:36:12.60 on Mon 10/11/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.958.516 [GMT -3:00]
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\HP_Owner\Desktop\fix computer\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.ca/
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\309731\program\Updates from HP.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1286756524402
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1286763704765
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2010-10-11 06:26:29 459264 ------w- c:\windows\system32\dllcache\msfeeds.dll
2010-10-11 06:26:29 268288 ------w- c:\windows\system32\dllcache\iertutil.dll
2010-10-11 06:26:28 52224 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-10-11 06:26:27 63488 ------w- c:\windows\system32\dllcache\icardie.dll
2010-10-11 06:26:27 380928 ------w- c:\windows\system32\dllcache\ieapfltr.dll
2010-10-11 06:26:27 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2010-10-11 06:26:24 2452872 ------w- c:\windows\system32\dllcache\ieapfltr.dat
2010-10-11 06:26:19 6067200 ------w- c:\windows\system32\dllcache\ieframe.dll
2010-10-11 03:44:36 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-10-11 02:06:49 8704 ----a-w- c:\windows\system32\CNMVS75.DLL
2010-10-11 02:06:49 59392 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPP75.DLL
2010-10-11 02:06:49 20992 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPD75.DLL
2010-10-11 02:06:49 139776 ----a-w- c:\windows\system32\CNMLM75.DLL
2010-10-11 02:06:44 90112 ----a-w- c:\windows\system32\CNMCP75.exe
2010-10-11 01:23:16 17920 ------w- c:\windows\system32\dllcache\msyuv.dll
2010-10-11 01:23:07 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-10-11 01:22:33 8704 ------w- c:\windows\system32\dllcache\tsbyuv.dll
2010-10-11 01:22:33 48128 ------w- c:\windows\system32\dllcache\iyuv_32.dll
2010-10-11 00:59:53 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-11 00:59:44 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-11 00:59:07 -------- d-----w- c:\windows\system32\CatRoot_bak
2010-10-11 00:53:38 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-10-11 00:53:38 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-10-11 00:41:18 -------- d-sh--r- C:\cmdcons
2010-10-11 00:40:57 -------- d-----w- c:\windows\setupupd
2010-10-11 00:34:20 -------- d-sh--r- c:\windows\system32\dllcache
2010-10-11 00:31:11 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-10-11 00:31:11 -------- d-----w- c:\windows\system32\PreInstall
2010-10-11 00:24:49 22744 ----a-w- c:\windows\system32\wuauserv.dll
2010-10-11 00:24:49 22744 ----a-w- c:\windows\system32\dllcache\wuauserv.dll
2010-10-11 00:24:49 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2010-10-11 00:24:49 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2010-10-11 00:24:48 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2010-10-11 00:24:48 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2010-10-11 00:24:48 -------- d-----w- c:\windows\system32\SoftwareDistribution
2010-10-11 00:09:45 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-10-11 00:09:44 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-10-11 00:09:43 133616 ------w- c:\windows\system32\pxafs.dll
2010-10-10 23:54:26 -------- d-s---w- c:\documents and settings\hp_owner\UserData
2010-10-10 23:53:50 -------- d-----w- c:\docume~1\hp_owner\applic~1\Ylsus
2010-10-10 23:53:50 -------- d-----w- c:\docume~1\hp_owner\applic~1\Ydtiyw
2010-10-10 23:52:20 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-10-10 20:11:25 -------- d-----w- C:\ComboFix
2010-10-10 14:22:02 -------- d-----w- c:\program files\windows
2010-10-07 01:49:37 -------- d-----w- c:\docume~1\hp_owner\applic~1\Bery
2010-09-14 22:51:39 241664 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2010-09-14 22:51:39 241664 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2010-09-14 22:51:39 241664 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2010-09-14 22:51:39 241664 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
==================== Find3M ====================
2010-10-10 15:04:18 782336 ----a-w- C:\StubInstaller.exe
2009-10-21 08:10:31 14265 ----a-w- c:\program files\common files\nadyh.scr
2009-10-21 08:10:30 13638 ----a-w- c:\program files\common files\ovawuq.sys
2009-10-21 08:10:30 10872 ----a-w- c:\program files\common files\xatar.com
2009-10-21 07:57:20 11122 ----a-w- c:\program files\common files\emumy.exe
2009-08-13 06:54:14 19444 ----a-w- c:\program files\common files\aqewymuvov.vbs
2009-08-13 06:54:13 18715 ----a-w- c:\program files\common files\edowymu.vbs
2009-08-13 06:54:13 18544 ----a-w- c:\program files\common files\ezyhife.reg
2009-08-13 06:54:13 15608 ----a-w- c:\program files\common files\batytucyb.dll
============= FINISH: 5:39:26.92 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-10-10.03)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 10/11/2010 12:50:04 AM
System Uptime: 10/11/2010 5:32:57 AM (0 hours ago)
Motherboard: MSI | | ALBACORE
Processor: AMD Athlon(tm) 64 Processor 3500+ | Socket 939 | 1772/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 179 GiB total, 53.94 GiB free.
D: is FIXED (FAT32) - 7 GiB total, 1.378 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
K: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
Adobe Acrobat - Reader 6.0.2 Update
Adobe Reader 6.0.1
Agere Systems PCI Soft Modem
AiO_Scan
AiOSoftware
ATI Control Panel
ATI Display Driver
Blackhawk Striker 2 from Hewlett-Packard Desktops (remove only)
Blasterball 2 from Hewlett-Packard Desktops (remove only)
Blasterball 2 Holidays from Hewlett-Packard Desktops (remove only)
Blasterball 2 Remix from Hewlett-Packard Desktops (remove only)
Bounce Symphony from Hewlett-Packard Desktops (remove only)
BufferChm
CameraDrivers
Canon iP1600
Copy
CP_AtenaShokunin1Config
cp_dwSharkTaleAlbums1
cp_dwSharkTaleCards1
cp_dwShrek2Albums1
cp_dwShrek2Cards1
CP_PLSBusinessFlyers
CreativeProjects
CreativeProjectsTemplates
Crystal Maze from Hewlett-Packard Desktops (remove only)
CueTour
Destinations
Director
DivX Setup
DocProc
DocumentViewer
Easy Internet Sign-up
Fax
ffdshow v1.1.3562 [2010-09-07]
Final Drive Nitro from Hewlett-Packard Desktops (remove only)
FinalBurner Free v2.20.0.187
Google Toolbar for Internet Explorer
Help and Support Additions
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB981793)
HP Boot Optimizer
HP Deskjet Printer Preload
HP Help and Support 4.0
HP Image Zone 4.8.6
HP Image Zone Plus 4.8.6
HP Organize
HP Photosmart Cameras 4.5
HP Product Assistant
HP PSC & OfficeJet 4.7
HP Software Update
HPIZplus450
HpSdpAppCoreApp
HPSystemDiagnostics
InstantShare
IntelliMover Data Transfer Demo
InterVideo WinDVD Player
iTunes
J2SE Runtime Environment 5.0
Java Auto Updater
Java(TM) 6 Update 21
KBD
Lexibox Deluxe from Hewlett-Packard Desktops (remove only)
LS_HSI
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Works
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 4.0
Overball from Hewlett-Packard Desktops (remove only)
PanoStandAlone
PC-Doctor for Windows
Phoenix Assault from Hewlett-Packard Desktops (remove only)
PhotoGallery
Photosmart 320,370,7400,8100,8400 Series
Polar Bowler from Hewlett-Packard Desktops (remove only)
Polar Golfer from Hewlett-Packard Desktops (remove only)
PrintScreen
PS2
PSPrinters06
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
QFolder
QuickProjects
QuickTime
Readme
RealPlayer
Remove Microsoft Money 2005 installer
Remove Quicken New User Edition installer
Remove WeatherBug installer
Scan
ScannerCopy
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB982381)
Segoe UI
Shooting Stars Pool from Hewlett-Packard Desktops (remove only)
SkinsHP1
Slyder from Hewlett-Packard Desktops (remove only)
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Super Granny from Hewlett-Packard Desktops (remove only)
Tradewinds from Hewlett-Packard Desktops (remove only)
TrayApp
Unload
Update for Windows XP (KB898461)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Updates from HP
VC80CRTRedist - 8.0.50727.4053
WebFldrs XP
WebReg
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Upload Tool
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB891781
WinRAR archiver
WinZip 14.5
==== Event Viewer Messages From Past Week ========
10/11/2010 12:26:32 AM, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\windows nt\accessories\wordpad.exe. This file was restored to the original version to maintain system stability. The file version of the bad file is 5.1.2600.3355, the version of the system file is 5.1.2600.3355.
10/11/2010 12:26:25 AM, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\windows media player\wmplayer.exe. This file was restored to the original version to maintain system stability. The file version of the bad file is 10.0.0.3646, the version of the system file is 10.0.0.3646.
10/11/2010 12:26:25 AM, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\windows media player\setup_wm.exe. This file was restored to the original version to maintain system stability. The file version of the bad file is 10.0.0.3646, the version of the system file is 10.0.0.3646.
10/11/2010 12:26:19 AM, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\windows media player\mpvis.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 10.0.0.3646, the version of the system file is 10.0.0.3646.
10/11/2010 12:26:18 AM, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\windows media player\migrate.exe. This file was restored to the original version to maintain system stability. The file version of the bad file is 10.0.0.3646, the version of the system file is 10.0.0.3646.
10/11/2010 12:09:43 AM, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\outlook express\msoe.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3664, the version of the system file is 6.0.2900.3664.
10/10/2010 9:51:53 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
10/10/2010 9:21:04 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
10/10/2010 9:09:17 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.ATL. Reference error message: The referenced assembly is not installed on your system. .
10/10/2010 9:09:17 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\DivX\DivX Transcode Engine\mtw178.ddc. Reference error message: The operation completed successfully. .
10/10/2010 9:09:17 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\DivX\DivX Transcode Engine\gzHF330.ddc. Reference error message: The operation completed successfully. .
10/10/2010 9:09:17 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.ATL could not be found and Last Error was The referenced assembly is not installed on your system.
10/10/2010 8:54:54 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
10/10/2010 8:54:54 PM, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\tmp9fec816f\kill.exe. Reference error message: The operation completed successfully. .
10/10/2010 8:54:54 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
10/10/2010 11:02:09 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: fasttx2k
10/10/2010 10:32:28 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft GDI+ Detection Tool (KB873374).
==== End Of File ===========================