CptGorilla
Posts: 24 +0
Hi,
Thanks in advance for helping me with this. As with others, any program I've run that actually detects it is unable to kill it due to services.exe that causes a reboot with a 1 minute timer.
As a side note, I also sometimes get dwm to cause the desktop to zoom on buttons or icons (such as "ok", "cancel", "my computer" icon, etc.). Don't know if it's related or another problem all together. I know it's dwm because if I end the task, it fixes it for a while.
Another note, the DDS.com gave me a lot of trouble to run (tried maybe 2 dozen times). The Command Prompt screen would open for about 2 seconds and then close before the scan completed. Any retries and the Command Prompt would just flash open and close right away. I tried closing everything (via smart close program) and then manually closing anything remaining (anti-virus). Even tried in Safe-Mode and it didn't work. Tried DDS.piff version, still no luck. Eventually, I managed to get it to work by running it as soon as Windows logged me in, and it finally ran. Don't know if this information is usefull...
Thanks
-Matthew
____________________________
_________ MBAM LOG _________
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.08.13.05
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Matthew :: VISTAKAPOOT [administrator]
14/08/2012 12:47:24 AM
mbam-log-2012-08-14 (00-47-24).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 309722
Time elapsed: 37 minute(s), 29 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 6
C:\WINDOWS\assembly\GAC\Desktop.ini (Trojan.0access) -> Delete on reboot.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\00000004.@ (Rootkit.Zaccess) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\000000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\80000000.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\80000032.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
(end)
____________________________
_________GMER LOG_________
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-08-14 01:41:23
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 SAMSUNG_HD501LJ rev.CR100-10
Running: xi3e7vk6.exe; Driver: C:\Users\Matthew\AppData\Local\Temp\uwlirpow.sys
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-3 8465C1E8
Device \Driver\atapi \Device\Ide\IdePort0 8465C1E8
Device \Driver\atapi \Device\Ide\IdePort1 8465C1E8
Device \Driver\atapi \Device\Ide\IdePort2 8465C1E8
Device \Driver\atapi \Device\Ide\IdePort3 8465C1E8
Device \Driver\a3rpf8iu \Device\Scsi\a3rpf8iu1 862FD1E8
Device \FileSystem\Ntfs \Ntfs 8465D1E8
---- EOF - GMER 1.0.15 ----
____________________________
__________DDS LOG__________
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by Matthew at 17:00:54 on 2012-08-14
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2045.979 [GMT -4:00]
.
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Advanced SystemCare 5\ASCService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\spoolsv.exe
C:\Program Files\IObit Malware Fighter\IMFsrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Advanced SystemCare 5\ASCTray.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Skype\Updater\Updater.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\IObit Malware Fighter\IMF.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\conime.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=81&bd=Pavilion&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=81&bd=Pavilion&pf=desktop
uURLSearchHooks: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\6.2\iobitToolbarIE.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\6.2\iobitToolbarIE.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\6.2\iobitToolbarIE.dll
uRun: [Advanced SystemCare 5] "c:\program files\advanced systemcare 5\ASCTray.exe" /AutoStart
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IObit Malware Fighter] "c:\program files\iobit malware fighter\IMF.exe" /autostart
mRun: [<NO NAME>]
mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [Advanced SystemCare 5] "c:\program files\advanced systemcare 5\ASCTray.exe" /AutoStart
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_11_2_202_228_ActiveX.exe -update activex
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-explorer: HideSCAHealth = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{29C8FCB0-F484-416F-9B77-962B92DB250B} : DhcpNameServer = 24.200.243.189 24.200.210.241 24.200.228.113
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\matthew\appdata\roaming\mozilla\firefox\profiles\akwt74ew.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=685749&p=
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_268.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2012-6-6 15672]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-4-10 242240]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-4-4 63928]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\advanced systemcare 5\ASCService.exe [2012-2-12 913792]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-7-26 794560]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2012-6-27 1385896]
R2 IMFservice;IMF Service;c:\program files\iobit malware fighter\IMFsrv.exe [2012-2-12 821592]
R2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-3 160944]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [2010-7-21 44432]
R3 FileMonitor;FileMonitor;c:\program files\iobit malware fighter\drivers\wlh_x86\FileMonitor.sys [2012-7-10 20336]
R3 RegFilter;RegFilter;c:\program files\iobit malware fighter\drivers\wlh_x86\RegFilter.sys [2012-7-10 30640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-5-16 21504]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-25 136176]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-7-23 2348352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-25 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-8-14 113120]
S3 UrlFilter;UrlFilter;c:\program files\iobit malware fighter\drivers\wlh_x86\UrlFilter.sys [2012-7-10 19832]
S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904]
S3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files\game booster 3\driver\WinRing0.sys [2012-8-11 14416]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2074-05-07 22:38:48 203576 ------w- c:\program files\microsoft games\age of empires iii\autopatcher2.exe
2012-08-14 04:20:04 -------- d-----w- c:\users\matthew\appdata\local\Macromedia
2012-08-14 04:18:22 -------- d-----w- c:\program files\Oracle
2012-08-14 04:16:37 772544 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-14 02:27:46 0 ----a-w- c:\windows\system32\REN4867.tmp
2012-08-14 02:27:46 0 ----a-w- c:\windows\system32\REN4866.tmp
2012-08-14 02:27:46 0 ----a-w- c:\windows\system32\REN4865.tmp
2012-08-13 07:49:22 43480 ----a-w- c:\windows\system32\drivers\atembtgp.sys
2012-08-11 21:09:19 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2012-08-11 21:09:19 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2012-08-11 21:09:19 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2012-08-11 21:09:19 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2012-08-11 21:09:17 -------- d-----w- c:\program files\Game Booster 3
2012-08-09 22:12:30 -------- d-----w- c:\users\matthew\appdata\local\LogMeIn Hamachi
2012-08-09 22:12:05 -------- d-----w- c:\program files\LogMeIn Hamachi
2012-08-08 05:57:33 -------- d-----w- c:\users\matthew\appdata\roaming\Synthesia
2012-08-07 22:43:03 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2012-08-07 22:42:27 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-08-07 22:42:27 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-08-07 22:40:31 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-08-07 22:40:31 278528 ----a-w- c:\windows\system32\schannel.dll
2012-08-07 22:40:31 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-08-07 22:39:57 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-08-07 22:39:39 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-08-05 23:27:39 -------- d-----w- c:\program files\common files\Microsoft Games
2012-08-05 23:27:34 34304 ------r- c:\program files\microsoft games\age of empires iii\SetupENU2.dll
2012-07-31 20:21:40 -------- d-----w- c:\programdata\Battle.net
2012-07-31 16:59:26 -------- d-----w- c:\program files\IObit Toolbar
2012-07-31 16:59:26 -------- d-----w- c:\program files\common files\Spigot
2012-07-31 16:59:26 -------- d-----w- c:\program files\Application Updater
2012-07-23 16:37:38 -------- d-----w- c:\windows\system32\RTCOM
2012-07-23 16:34:51 2193472 ----a-w- c:\windows\system32\FMAPO.dll
2012-07-23 16:27:41 645440 ----a-w- c:\windows\system32\nvvsvc.exe
2012-07-23 16:27:41 62272 ----a-w- c:\windows\system32\nvshext.dll
2012-07-23 16:27:41 3881792 ----a-w- c:\windows\system32\nvcpl.dll
2012-07-23 16:27:41 2719040 ----a-w- c:\windows\system32\nvsvc.dll
2012-07-23 16:27:41 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-07-23 16:24:02 61248 ----a-w- c:\windows\system32\OpenCL.dll
2012-07-23 16:24:01 19444544 ----a-w- c:\windows\system32\nvoglv32.dll
2012-07-23 16:24:01 10819392 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-07-23 16:24:00 5892928 ----a-w- c:\windows\system32\nvcuda.dll
2012-07-23 16:24:00 2517312 ----a-w- c:\windows\system32\nvcuvid.dll
2012-07-23 16:24:00 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-07-23 16:23:59 17543488 ----a-w- c:\windows\system32\nvcompiler.dll
2012-07-23 16:13:26 -------- d-----w- c:\program files\ffdshow
.
==================== Find3M ====================
.
2012-08-14 04:19:29 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-14 04:19:29 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-07 22:41:51 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-08-07 22:41:48 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-08-07 22:41:48 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-07 22:41:47 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-08-07 22:41:47 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-08-07 22:41:04 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-08-07 22:41:03 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-08-07 22:41:03 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-07-23 16:36:11 319456 ----a-w- c:\windows\DIFxAPI.dll
2012-07-06 02:06:20 687544 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-19 20:54:20 3240400 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys
2012-06-14 17:43:38 5096448 ----a-w- c:\windows\system32\RCoRes.dat
2012-06-08 20:18:46 3173008 ----a-w- c:\windows\system32\RtkAPO.dll
2012-06-06 20:41:54 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-06 20:41:54 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-06-06 20:41:41 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-06 20:41:29 905600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-06-06 20:34:44 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-06-06 20:34:44 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-06-06 20:34:44 1069056 ----a-w- c:\windows\system32\DWrite.dll
2012-06-06 20:34:43 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-06-06 20:34:43 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-06-06 14:44:20 645776 ----a-w- c:\windows\system32\RtkApoApi.dll
2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-01 13:37:38 2417808 ----a-w- c:\windows\system32\RtkPgExt.dll
2012-05-31 22:08:16 87696 ----a-w- c:\windows\system32\RtkCoInstII.dll
2012-05-26 17:51:16 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
2012-05-25 22:06:00 1706640 ----a-w- c:\windows\RtlExUpd.dll
2012-05-24 14:48:02 21888 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-05-17 15:29:22 7161696 ----a-w- c:\windows\system32\R4EEP32A.dll
2012-05-17 15:29:22 61792 ----a-w- c:\windows\system32\R4EEG32A.dll
2012-05-17 15:29:22 105824 ----a-w- c:\windows\system32\R4EEL32A.dll
2012-05-17 15:29:20 91488 ----a-w- c:\windows\system32\R4EEA32A.dll
2012-05-17 15:29:20 351072 ----a-w- c:\windows\system32\R4EED32A.dll
.
============= FINISH: 17:05:04.68 ===============
____________________________
________ATTACH LOG_________
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 15/05/2011 6:08:11 PM
System Uptime: 14/08/2012 4:59:31 PM (1 hours ago)
.
Motherboard: FOXCONN | | Napa
Processor: Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz | Socket 775 | 2000/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 456 GiB total, 219.779 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 1.285 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e965-e325-11ce-bfc1-08002be10318}
Description: CD-ROM Drive
Device ID: IDE\CDROMHL-DT-ST_DVD-RW_GSA-H60L________________DC08____\5&C2E7CDD&0&0.1.0
Manufacturer: (Standard CD-ROM drives)
Name: HL-DT-ST DVD-RW GSA-H60L ATA Device
PNP Device ID: IDE\CDROMHL-DT-ST_DVD-RW_GSA-H60L________________DC08____\5&C2E7CDD&0&0.1.0
Service: cdrom
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: NVIDIA nForce Networking Controller
Device ID: PCI\VEN_10DE&DEV_07DC&SUBSYS_2A64103C&REV_A2\3&2411E6FE&0&78
Manufacturer: NVIDIA
Name: NVIDIA nForce Networking Controller #2
PNP Device ID: PCI\VEN_10DE&DEV_07DC&SUBSYS_2A64103C&REV_A2\3&2411E6FE&0&78
Service: NVENETFD
.
Class GUID: {4d36e965-e325-11ce-bfc1-08002be10318}
Description: CD-ROM Drive
Device ID: SCSI\CDROM&VEN_YLOXC&PROD_ABGPMFW1YZ8X&REV_1.04\5&10D83825&0&000000
Manufacturer: (Standard CD-ROM drives)
Name: YLOXC ABGPMFW1YZ8X SCSI CdRom Device
PNP Device ID: SCSI\CDROM&VEN_YLOXC&PROD_ABGPMFW1YZ8X&REV_1.04\5&10D83825&0&000000
Service: cdrom
.
Class GUID: {4d36e965-e325-11ce-bfc1-08002be10318}
Description: CD-ROM Drive
Device ID: DTSOFTBUS&REV1\DTCDROM&REV1\1&79F5D87&1&00
Manufacturer: (Standard CD-ROM drives)
Name: DTSOFT Virtual CdRom Device
PNP Device ID: DTSOFTBUS&REV1\DTCDROM&REV1\1&79F5D87&1&00
Service: cdrom
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
.
7-Zip 9.20
Acrobat.com
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3)
Advanced SystemCare 5
Age of Empires III
Age of Empires III - The WarChiefs
Age of Pirates 2: City of Abandoned Ships ver.1.3.0
µTorrent
Audacity 1.3.13 (Unicode)
Axis & Allies
Compatibility Pack for the 2007 Office system
CyberLink DVD Suite Deluxe
DAEMON Tools Lite
DVD Architect Studio 5.0
Enhanced Multimedia Keyboard Solution
ffdshow [rev 3154] [2009-12-09]
FFmpeg v0.6.2 for Audacity
Game Booster 3
Google Earth Plug-in
Google Update Helper
Gorilla 2
Hardware Diagnostic Tools
Hewlett-Packard Active Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Customer Feedback
HP On-Screen Cap/Num/Scroll Lock Indicator
HP Picasso Media Center Add-In
IObit Malware Fighter
IObit Toolbar v6.2
Java Auto Updater
Java(TM) 7 Update 5
JavaFX 2.1.1
K-Lite Codec Pack 7.1.0 (Full)
LAME v3.98.3 for Audacity
LightScribe System Software 1.10.16.1
Logitech Webcam Software
Logitech Webcam Software Driver Package
LogMeIn Hamachi
Malwarebytes Anti-Malware version 1.61.0.1400
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft IntelliPoint 7.1
Microsoft IntelliType Pro 8.0
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Windows Media Video 9 VCM
Microsoft Works
Microsoft WSE 3.0 Runtime
Mozilla Firefox 14.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT Redists
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NVIDIA Control Panel 296.10
NVIDIA Drivers
NVIDIA Graphics Driver 296.10
NVIDIA Install Application
NVIDIA Update 1.7.11
NVIDIA Update Components
Pacific Storm
PVSonyDll
Python 2.5
Railroad Tycoon 3
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Skype™ 5.10
Smart Defrag 2
SmartClose 1.1
Soft Data Fax Modem with SmartCP
Sound Forge Audio Studio 10.0
StarCraft II
The Sims 2
The Sims 2 Family Fun Stuff
The Sims 2 Glamour Life Stuff
The Sims 2 Nightlife
The Sims 2 Open For Business
The Sims 2 Pets
The Sims 2 University
The Sims Medieval
The Sims™ 2 Apartment Life
The Sims™ 2 Bon Voyage
The Sims™ 2 Celebration! Stuff
The Sims™ 2 FreeTime
The Sims™ 2 H&M® Fashion Stuff
The Sims™ 2 IKEA® Home Stuff
The Sims™ 2 Kitchen & Bath Interior Design Stuff
The Sims™ 2 Mansion and Garden Stuff
The Sims™ 2 Seasons
The Sims™ 2 Teen Style Stuff
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Vegas Movie Studio HD Platinum 11.0
WeatherBug Gadget
WinHTTrack Website Copier 3.44-1
WinRAR 4.01 (32-bit)
.
==== Event Viewer Messages From Past Week ========
.
14/08/2012 5:02:32 PM, Error: Service Control Manager [7000] - The HP Health Check Service service failed to start due to the following error: The system cannot find the file specified.
14/08/2012 5:01:31 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt luafv
14/08/2012 5:01:31 PM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
14/08/2012 5:01:31 PM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
14/08/2012 5:01:31 PM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
14/08/2012 5:01:31 PM, Error: Service Control Manager [7000] - The UrlFilter service failed to start due to the following error: There are no more endpoints available from the endpoint mapper.
14/08/2012 5:00:12 PM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer HP LaserJet 2100 PCL6 with shared resource name HP LaserJet 2100 PCL6. Error 1753. The printer cannot be used by others on the network.
14/08/2012 5:00:00 PM, Error: EventLog [6008] - The previous system shutdown at 4:57:01 PM on 14/08/2012 was unexpected.
14/08/2012 4:56:47 PM, Error: Service Control Manager [7001] - The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
14/08/2012 4:55:39 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt luafv spldr Wanarpv6
14/08/2012 4:55:39 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
14/08/2012 4:55:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
14/08/2012 4:55:02 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
14/08/2012 4:55:00 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
14/08/2012 4:54:53 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
14/08/2012 4:54:47 PM, Error: Microsoft-Windows-TerminalServices-LocalSessionManager [1048] - Terminal Service start failed. The relevant status code was This service cannot be started in Safe Mode .
14/08/2012 4:54:47 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TermService with arguments "" in order to run the server: {F9A874B6-F8A8-4D73-B5A8-AB610816828B}
14/08/2012 4:53:38 PM, Error: sptd [4] - Driver detected an internal error in its data structures for .
14/08/2012 4:47:40 PM, Error: Service Control Manager [7000] - The UrlFilter service failed to start due to the following error: Cannot create a file when that file already exists.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 1 time(s).
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Tablet PC Input Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The ReadyBoost service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Portable Device Enumerator Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The PnP-X IP Bus Enumerator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Human Interface Device Access service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:22:57 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
14/08/2012 12:22:57 AM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
14/08/2012 12:22:57 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
14/08/2012 1:47:21 AM, Error: Service Control Manager [7034] - The Advanced SystemCare Service 5 service terminated unexpectedly. It has done this 1 time(s).
13/08/2012 3:19:39 PM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer HP LaserJet 2100 PCL6 with shared resource name HP LaserJet 2100 PCL6. Error 2114. The printer cannot be used by others on the network.
13/08/2012 11:58:52 PM, Error: EventLog [6008] - The previous system shutdown at 11:43:34 PM on 13/08/2012 was unexpected.
13/08/2012 1:00:03 PM, Error: EventLog [6008] - The previous system shutdown at 3:47:27 AM on 13/08/2012 was unexpected.
11/08/2012 2:03:03 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the IPBusEnum service.
10/08/2012 5:02:41 PM, Error: Microsoft-Windows-ResourcePublication [1002] - Element Provider\Microsoft.Base.Publication/Publication/Computer failed to publish. Ensure that both PKEY_PUBSVCS_METADATA and PKEY_PUBSVCS_TYPE are set properly on the function instance and there were no errors adding the function instance.
10/08/2012 5:02:35 PM, Error: Microsoft-Windows-TaskScheduler [702] - Task Scheduler failed to initialize the RPC server for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147944152.
10/08/2012 5:02:35 PM, Error: Microsoft-Windows-TaskScheduler [701] - Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147944152.
10/08/2012 5:02:35 PM, Error: Microsoft-Windows-TaskScheduler [408] - Task Scheduler service failed to initialize idle state detection module. Idle tasks may not be started as required. Additional Data: Error Value: 2147944152.
10/08/2012 5:02:35 PM, Error: Microsoft-Windows-TaskScheduler [408] - Task Scheduler service failed to initialize idle state detection module. Idle tasks may not be started as required. Additional Data: Error Value: 1752.
10/08/2012 5:00:42 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the SSDP Discovery service, but this action failed with the following error: An instance of the service is already running.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7034] - The Function Discovery Provider Host service terminated unexpectedly. It has done this 1 time(s).
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Workstation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Windows Time service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The UPnP Device Host service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The SSDP Discovery service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Secure Socket Tunneling Protocol Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Network Store Interface Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Network List Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Function Discovery Resource Publication service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The COM+ Event System service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
10/08/2012 5:00:38 PM, Error: Service Control Manager [7034] - The Network Location Awareness service terminated unexpectedly. It has done this 3 time(s).
10/08/2012 5:00:35 PM, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:35 PM, Error: Service Control Manager [7031] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 11000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The Telephony service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The DNS Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The Cryptographic Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:29 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:26 PM, Error: Service Control Manager [7031] - The Windows Font Cache Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:23 PM, Error: Service Control Manager [7031] - The Diagnostic Policy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:17 PM, Error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s).
10/08/2012 5:00:14 PM, Error: Service Control Manager [7031] - The Windows Error Reporting Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 4:51:00 PM, Error: EventLog [6008] - The previous system shutdown at 4:49:06 PM on 10/08/2012 was unexpected.
10/08/2012 4:18:36 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B68-F52A-11D8-B9A5-505054503030}
10/08/2012 3:57:33 PM, Error: EventLog [6008] - The previous system shutdown at 3:56:11 PM on 10/08/2012 was unexpected.
10/08/2012 3:36:11 PM, Error: EventLog [6008] - The previous system shutdown at 3:34:24 PM on 10/08/2012 was unexpected.
10/08/2012 2:10:07 AM, Error: EventLog [6008] - The previous system shutdown at 2:08:50 AM on 10/08/2012 was unexpected.
09/08/2012 6:12:52 PM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 7A7900000000. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
09/08/2012 6:12:23 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the LogMeIn Hamachi Tunneling Engine service to connect.
09/08/2012 6:12:23 PM, Error: Service Control Manager [7000] - The LogMeIn Hamachi Tunneling Engine service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
09/08/2012 6:12:21 PM, Error: Service Control Manager [7030] - The LogMeIn Hamachi Tunneling Engine service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
09/08/2012 6:07:08 PM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 7A7905094BB2. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
.
==== End Of File ===========================
Thanks in advance for helping me with this. As with others, any program I've run that actually detects it is unable to kill it due to services.exe that causes a reboot with a 1 minute timer.
As a side note, I also sometimes get dwm to cause the desktop to zoom on buttons or icons (such as "ok", "cancel", "my computer" icon, etc.). Don't know if it's related or another problem all together. I know it's dwm because if I end the task, it fixes it for a while.
Another note, the DDS.com gave me a lot of trouble to run (tried maybe 2 dozen times). The Command Prompt screen would open for about 2 seconds and then close before the scan completed. Any retries and the Command Prompt would just flash open and close right away. I tried closing everything (via smart close program) and then manually closing anything remaining (anti-virus). Even tried in Safe-Mode and it didn't work. Tried DDS.piff version, still no luck. Eventually, I managed to get it to work by running it as soon as Windows logged me in, and it finally ran. Don't know if this information is usefull...
Thanks
-Matthew
____________________________
_________ MBAM LOG _________
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.08.13.05
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Matthew :: VISTAKAPOOT [administrator]
14/08/2012 12:47:24 AM
mbam-log-2012-08-14 (00-47-24).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 309722
Time elapsed: 37 minute(s), 29 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 6
C:\WINDOWS\assembly\GAC\Desktop.ini (Trojan.0access) -> Delete on reboot.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\00000004.@ (Rootkit.Zaccess) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\000000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\80000000.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{43fb0745-9066-0a4a-f454-9a9f7b50258f}\U\80000032.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
(end)
____________________________
_________GMER LOG_________
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-08-14 01:41:23
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 SAMSUNG_HD501LJ rev.CR100-10
Running: xi3e7vk6.exe; Driver: C:\Users\Matthew\AppData\Local\Temp\uwlirpow.sys
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-3 8465C1E8
Device \Driver\atapi \Device\Ide\IdePort0 8465C1E8
Device \Driver\atapi \Device\Ide\IdePort1 8465C1E8
Device \Driver\atapi \Device\Ide\IdePort2 8465C1E8
Device \Driver\atapi \Device\Ide\IdePort3 8465C1E8
Device \Driver\a3rpf8iu \Device\Scsi\a3rpf8iu1 862FD1E8
Device \FileSystem\Ntfs \Ntfs 8465D1E8
---- EOF - GMER 1.0.15 ----
____________________________
__________DDS LOG__________
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by Matthew at 17:00:54 on 2012-08-14
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2045.979 [GMT -4:00]
.
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Advanced SystemCare 5\ASCService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\spoolsv.exe
C:\Program Files\IObit Malware Fighter\IMFsrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Advanced SystemCare 5\ASCTray.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Skype\Updater\Updater.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\IObit Malware Fighter\IMF.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\conime.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=81&bd=Pavilion&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=81&bd=Pavilion&pf=desktop
uURLSearchHooks: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\6.2\iobitToolbarIE.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\6.2\iobitToolbarIE.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\6.2\iobitToolbarIE.dll
uRun: [Advanced SystemCare 5] "c:\program files\advanced systemcare 5\ASCTray.exe" /AutoStart
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IObit Malware Fighter] "c:\program files\iobit malware fighter\IMF.exe" /autostart
mRun: [<NO NAME>]
mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [Advanced SystemCare 5] "c:\program files\advanced systemcare 5\ASCTray.exe" /AutoStart
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_11_2_202_228_ActiveX.exe -update activex
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-explorer: HideSCAHealth = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{29C8FCB0-F484-416F-9B77-962B92DB250B} : DhcpNameServer = 24.200.243.189 24.200.210.241 24.200.228.113
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\matthew\appdata\roaming\mozilla\firefox\profiles\akwt74ew.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=685749&p=
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_268.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2012-6-6 15672]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-4-10 242240]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-4-4 63928]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\advanced systemcare 5\ASCService.exe [2012-2-12 913792]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-7-26 794560]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2012-6-27 1385896]
R2 IMFservice;IMF Service;c:\program files\iobit malware fighter\IMFsrv.exe [2012-2-12 821592]
R2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-3 160944]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [2010-7-21 44432]
R3 FileMonitor;FileMonitor;c:\program files\iobit malware fighter\drivers\wlh_x86\FileMonitor.sys [2012-7-10 20336]
R3 RegFilter;RegFilter;c:\program files\iobit malware fighter\drivers\wlh_x86\RegFilter.sys [2012-7-10 30640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-5-16 21504]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-25 136176]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-7-23 2348352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-25 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-8-14 113120]
S3 UrlFilter;UrlFilter;c:\program files\iobit malware fighter\drivers\wlh_x86\UrlFilter.sys [2012-7-10 19832]
S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904]
S3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files\game booster 3\driver\WinRing0.sys [2012-8-11 14416]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2074-05-07 22:38:48 203576 ------w- c:\program files\microsoft games\age of empires iii\autopatcher2.exe
2012-08-14 04:20:04 -------- d-----w- c:\users\matthew\appdata\local\Macromedia
2012-08-14 04:18:22 -------- d-----w- c:\program files\Oracle
2012-08-14 04:16:37 772544 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-14 02:27:46 0 ----a-w- c:\windows\system32\REN4867.tmp
2012-08-14 02:27:46 0 ----a-w- c:\windows\system32\REN4866.tmp
2012-08-14 02:27:46 0 ----a-w- c:\windows\system32\REN4865.tmp
2012-08-13 07:49:22 43480 ----a-w- c:\windows\system32\drivers\atembtgp.sys
2012-08-11 21:09:19 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2012-08-11 21:09:19 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2012-08-11 21:09:19 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2012-08-11 21:09:19 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2012-08-11 21:09:17 -------- d-----w- c:\program files\Game Booster 3
2012-08-09 22:12:30 -------- d-----w- c:\users\matthew\appdata\local\LogMeIn Hamachi
2012-08-09 22:12:05 -------- d-----w- c:\program files\LogMeIn Hamachi
2012-08-08 05:57:33 -------- d-----w- c:\users\matthew\appdata\roaming\Synthesia
2012-08-07 22:43:03 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2012-08-07 22:42:27 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-08-07 22:42:27 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-08-07 22:40:31 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-08-07 22:40:31 278528 ----a-w- c:\windows\system32\schannel.dll
2012-08-07 22:40:31 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-08-07 22:39:57 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-08-07 22:39:39 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-08-05 23:27:39 -------- d-----w- c:\program files\common files\Microsoft Games
2012-08-05 23:27:34 34304 ------r- c:\program files\microsoft games\age of empires iii\SetupENU2.dll
2012-07-31 20:21:40 -------- d-----w- c:\programdata\Battle.net
2012-07-31 16:59:26 -------- d-----w- c:\program files\IObit Toolbar
2012-07-31 16:59:26 -------- d-----w- c:\program files\common files\Spigot
2012-07-31 16:59:26 -------- d-----w- c:\program files\Application Updater
2012-07-23 16:37:38 -------- d-----w- c:\windows\system32\RTCOM
2012-07-23 16:34:51 2193472 ----a-w- c:\windows\system32\FMAPO.dll
2012-07-23 16:27:41 645440 ----a-w- c:\windows\system32\nvvsvc.exe
2012-07-23 16:27:41 62272 ----a-w- c:\windows\system32\nvshext.dll
2012-07-23 16:27:41 3881792 ----a-w- c:\windows\system32\nvcpl.dll
2012-07-23 16:27:41 2719040 ----a-w- c:\windows\system32\nvsvc.dll
2012-07-23 16:27:41 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-07-23 16:24:02 61248 ----a-w- c:\windows\system32\OpenCL.dll
2012-07-23 16:24:01 19444544 ----a-w- c:\windows\system32\nvoglv32.dll
2012-07-23 16:24:01 10819392 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-07-23 16:24:00 5892928 ----a-w- c:\windows\system32\nvcuda.dll
2012-07-23 16:24:00 2517312 ----a-w- c:\windows\system32\nvcuvid.dll
2012-07-23 16:24:00 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-07-23 16:23:59 17543488 ----a-w- c:\windows\system32\nvcompiler.dll
2012-07-23 16:13:26 -------- d-----w- c:\program files\ffdshow
.
==================== Find3M ====================
.
2012-08-14 04:19:29 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-14 04:19:29 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-07 22:41:51 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-08-07 22:41:48 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-08-07 22:41:48 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-07 22:41:47 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-08-07 22:41:47 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-08-07 22:41:04 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-08-07 22:41:03 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-08-07 22:41:03 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-07-23 16:36:11 319456 ----a-w- c:\windows\DIFxAPI.dll
2012-07-06 02:06:20 687544 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-19 20:54:20 3240400 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys
2012-06-14 17:43:38 5096448 ----a-w- c:\windows\system32\RCoRes.dat
2012-06-08 20:18:46 3173008 ----a-w- c:\windows\system32\RtkAPO.dll
2012-06-06 20:41:54 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-06 20:41:54 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-06-06 20:41:41 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-06 20:41:29 905600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-06-06 20:34:44 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-06-06 20:34:44 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-06-06 20:34:44 1069056 ----a-w- c:\windows\system32\DWrite.dll
2012-06-06 20:34:43 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-06-06 20:34:43 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-06-06 14:44:20 645776 ----a-w- c:\windows\system32\RtkApoApi.dll
2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-01 13:37:38 2417808 ----a-w- c:\windows\system32\RtkPgExt.dll
2012-05-31 22:08:16 87696 ----a-w- c:\windows\system32\RtkCoInstII.dll
2012-05-26 17:51:16 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
2012-05-25 22:06:00 1706640 ----a-w- c:\windows\RtlExUpd.dll
2012-05-24 14:48:02 21888 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-05-17 15:29:22 7161696 ----a-w- c:\windows\system32\R4EEP32A.dll
2012-05-17 15:29:22 61792 ----a-w- c:\windows\system32\R4EEG32A.dll
2012-05-17 15:29:22 105824 ----a-w- c:\windows\system32\R4EEL32A.dll
2012-05-17 15:29:20 91488 ----a-w- c:\windows\system32\R4EEA32A.dll
2012-05-17 15:29:20 351072 ----a-w- c:\windows\system32\R4EED32A.dll
.
============= FINISH: 17:05:04.68 ===============
____________________________
________ATTACH LOG_________
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 15/05/2011 6:08:11 PM
System Uptime: 14/08/2012 4:59:31 PM (1 hours ago)
.
Motherboard: FOXCONN | | Napa
Processor: Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz | Socket 775 | 2000/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 456 GiB total, 219.779 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 1.285 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e965-e325-11ce-bfc1-08002be10318}
Description: CD-ROM Drive
Device ID: IDE\CDROMHL-DT-ST_DVD-RW_GSA-H60L________________DC08____\5&C2E7CDD&0&0.1.0
Manufacturer: (Standard CD-ROM drives)
Name: HL-DT-ST DVD-RW GSA-H60L ATA Device
PNP Device ID: IDE\CDROMHL-DT-ST_DVD-RW_GSA-H60L________________DC08____\5&C2E7CDD&0&0.1.0
Service: cdrom
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: NVIDIA nForce Networking Controller
Device ID: PCI\VEN_10DE&DEV_07DC&SUBSYS_2A64103C&REV_A2\3&2411E6FE&0&78
Manufacturer: NVIDIA
Name: NVIDIA nForce Networking Controller #2
PNP Device ID: PCI\VEN_10DE&DEV_07DC&SUBSYS_2A64103C&REV_A2\3&2411E6FE&0&78
Service: NVENETFD
.
Class GUID: {4d36e965-e325-11ce-bfc1-08002be10318}
Description: CD-ROM Drive
Device ID: SCSI\CDROM&VEN_YLOXC&PROD_ABGPMFW1YZ8X&REV_1.04\5&10D83825&0&000000
Manufacturer: (Standard CD-ROM drives)
Name: YLOXC ABGPMFW1YZ8X SCSI CdRom Device
PNP Device ID: SCSI\CDROM&VEN_YLOXC&PROD_ABGPMFW1YZ8X&REV_1.04\5&10D83825&0&000000
Service: cdrom
.
Class GUID: {4d36e965-e325-11ce-bfc1-08002be10318}
Description: CD-ROM Drive
Device ID: DTSOFTBUS&REV1\DTCDROM&REV1\1&79F5D87&1&00
Manufacturer: (Standard CD-ROM drives)
Name: DTSOFT Virtual CdRom Device
PNP Device ID: DTSOFTBUS&REV1\DTCDROM&REV1\1&79F5D87&1&00
Service: cdrom
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
.
7-Zip 9.20
Acrobat.com
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3)
Advanced SystemCare 5
Age of Empires III
Age of Empires III - The WarChiefs
Age of Pirates 2: City of Abandoned Ships ver.1.3.0
µTorrent
Audacity 1.3.13 (Unicode)
Axis & Allies
Compatibility Pack for the 2007 Office system
CyberLink DVD Suite Deluxe
DAEMON Tools Lite
DVD Architect Studio 5.0
Enhanced Multimedia Keyboard Solution
ffdshow [rev 3154] [2009-12-09]
FFmpeg v0.6.2 for Audacity
Game Booster 3
Google Earth Plug-in
Google Update Helper
Gorilla 2
Hardware Diagnostic Tools
Hewlett-Packard Active Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Customer Feedback
HP On-Screen Cap/Num/Scroll Lock Indicator
HP Picasso Media Center Add-In
IObit Malware Fighter
IObit Toolbar v6.2
Java Auto Updater
Java(TM) 7 Update 5
JavaFX 2.1.1
K-Lite Codec Pack 7.1.0 (Full)
LAME v3.98.3 for Audacity
LightScribe System Software 1.10.16.1
Logitech Webcam Software
Logitech Webcam Software Driver Package
LogMeIn Hamachi
Malwarebytes Anti-Malware version 1.61.0.1400
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft IntelliPoint 7.1
Microsoft IntelliType Pro 8.0
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Windows Media Video 9 VCM
Microsoft Works
Microsoft WSE 3.0 Runtime
Mozilla Firefox 14.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT Redists
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NVIDIA Control Panel 296.10
NVIDIA Drivers
NVIDIA Graphics Driver 296.10
NVIDIA Install Application
NVIDIA Update 1.7.11
NVIDIA Update Components
Pacific Storm
PVSonyDll
Python 2.5
Railroad Tycoon 3
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Skype™ 5.10
Smart Defrag 2
SmartClose 1.1
Soft Data Fax Modem with SmartCP
Sound Forge Audio Studio 10.0
StarCraft II
The Sims 2
The Sims 2 Family Fun Stuff
The Sims 2 Glamour Life Stuff
The Sims 2 Nightlife
The Sims 2 Open For Business
The Sims 2 Pets
The Sims 2 University
The Sims Medieval
The Sims™ 2 Apartment Life
The Sims™ 2 Bon Voyage
The Sims™ 2 Celebration! Stuff
The Sims™ 2 FreeTime
The Sims™ 2 H&M® Fashion Stuff
The Sims™ 2 IKEA® Home Stuff
The Sims™ 2 Kitchen & Bath Interior Design Stuff
The Sims™ 2 Mansion and Garden Stuff
The Sims™ 2 Seasons
The Sims™ 2 Teen Style Stuff
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Vegas Movie Studio HD Platinum 11.0
WeatherBug Gadget
WinHTTrack Website Copier 3.44-1
WinRAR 4.01 (32-bit)
.
==== Event Viewer Messages From Past Week ========
.
14/08/2012 5:02:32 PM, Error: Service Control Manager [7000] - The HP Health Check Service service failed to start due to the following error: The system cannot find the file specified.
14/08/2012 5:01:31 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt luafv
14/08/2012 5:01:31 PM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
14/08/2012 5:01:31 PM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
14/08/2012 5:01:31 PM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
14/08/2012 5:01:31 PM, Error: Service Control Manager [7000] - The UrlFilter service failed to start due to the following error: There are no more endpoints available from the endpoint mapper.
14/08/2012 5:00:12 PM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer HP LaserJet 2100 PCL6 with shared resource name HP LaserJet 2100 PCL6. Error 1753. The printer cannot be used by others on the network.
14/08/2012 5:00:00 PM, Error: EventLog [6008] - The previous system shutdown at 4:57:01 PM on 14/08/2012 was unexpected.
14/08/2012 4:56:47 PM, Error: Service Control Manager [7001] - The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
14/08/2012 4:55:39 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt luafv spldr Wanarpv6
14/08/2012 4:55:39 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
14/08/2012 4:55:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
14/08/2012 4:55:02 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
14/08/2012 4:55:00 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
14/08/2012 4:54:53 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
14/08/2012 4:54:47 PM, Error: Microsoft-Windows-TerminalServices-LocalSessionManager [1048] - Terminal Service start failed. The relevant status code was This service cannot be started in Safe Mode .
14/08/2012 4:54:47 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TermService with arguments "" in order to run the server: {F9A874B6-F8A8-4D73-B5A8-AB610816828B}
14/08/2012 4:53:38 PM, Error: sptd [4] - Driver detected an internal error in its data structures for .
14/08/2012 4:47:40 PM, Error: Service Control Manager [7000] - The UrlFilter service failed to start due to the following error: Cannot create a file when that file already exists.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 1 time(s).
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Tablet PC Input Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The ReadyBoost service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Portable Device Enumerator Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The PnP-X IP Bus Enumerator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Human Interface Device Access service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:27:44 AM, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
14/08/2012 12:22:57 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
14/08/2012 12:22:57 AM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
14/08/2012 12:22:57 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
14/08/2012 1:47:21 AM, Error: Service Control Manager [7034] - The Advanced SystemCare Service 5 service terminated unexpectedly. It has done this 1 time(s).
13/08/2012 3:19:39 PM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer HP LaserJet 2100 PCL6 with shared resource name HP LaserJet 2100 PCL6. Error 2114. The printer cannot be used by others on the network.
13/08/2012 11:58:52 PM, Error: EventLog [6008] - The previous system shutdown at 11:43:34 PM on 13/08/2012 was unexpected.
13/08/2012 1:00:03 PM, Error: EventLog [6008] - The previous system shutdown at 3:47:27 AM on 13/08/2012 was unexpected.
11/08/2012 2:03:03 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the IPBusEnum service.
10/08/2012 5:02:41 PM, Error: Microsoft-Windows-ResourcePublication [1002] - Element Provider\Microsoft.Base.Publication/Publication/Computer failed to publish. Ensure that both PKEY_PUBSVCS_METADATA and PKEY_PUBSVCS_TYPE are set properly on the function instance and there were no errors adding the function instance.
10/08/2012 5:02:35 PM, Error: Microsoft-Windows-TaskScheduler [702] - Task Scheduler failed to initialize the RPC server for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147944152.
10/08/2012 5:02:35 PM, Error: Microsoft-Windows-TaskScheduler [701] - Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147944152.
10/08/2012 5:02:35 PM, Error: Microsoft-Windows-TaskScheduler [408] - Task Scheduler service failed to initialize idle state detection module. Idle tasks may not be started as required. Additional Data: Error Value: 2147944152.
10/08/2012 5:02:35 PM, Error: Microsoft-Windows-TaskScheduler [408] - Task Scheduler service failed to initialize idle state detection module. Idle tasks may not be started as required. Additional Data: Error Value: 1752.
10/08/2012 5:00:42 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the SSDP Discovery service, but this action failed with the following error: An instance of the service is already running.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7034] - The Function Discovery Provider Host service terminated unexpectedly. It has done this 1 time(s).
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Workstation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Windows Time service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The UPnP Device Host service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The SSDP Discovery service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Secure Socket Tunneling Protocol Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Network Store Interface Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Network List Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The Function Discovery Resource Publication service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:41 PM, Error: Service Control Manager [7031] - The COM+ Event System service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
10/08/2012 5:00:38 PM, Error: Service Control Manager [7034] - The Network Location Awareness service terminated unexpectedly. It has done this 3 time(s).
10/08/2012 5:00:35 PM, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:35 PM, Error: Service Control Manager [7031] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 11000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The Telephony service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The DNS Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:32 PM, Error: Service Control Manager [7031] - The Cryptographic Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:29 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:26 PM, Error: Service Control Manager [7031] - The Windows Font Cache Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/08/2012 5:00:23 PM, Error: Service Control Manager [7031] - The Diagnostic Policy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 5:00:17 PM, Error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s).
10/08/2012 5:00:14 PM, Error: Service Control Manager [7031] - The Windows Error Reporting Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
10/08/2012 4:51:00 PM, Error: EventLog [6008] - The previous system shutdown at 4:49:06 PM on 10/08/2012 was unexpected.
10/08/2012 4:18:36 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B68-F52A-11D8-B9A5-505054503030}
10/08/2012 3:57:33 PM, Error: EventLog [6008] - The previous system shutdown at 3:56:11 PM on 10/08/2012 was unexpected.
10/08/2012 3:36:11 PM, Error: EventLog [6008] - The previous system shutdown at 3:34:24 PM on 10/08/2012 was unexpected.
10/08/2012 2:10:07 AM, Error: EventLog [6008] - The previous system shutdown at 2:08:50 AM on 10/08/2012 was unexpected.
09/08/2012 6:12:52 PM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 7A7900000000. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
09/08/2012 6:12:23 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the LogMeIn Hamachi Tunneling Engine service to connect.
09/08/2012 6:12:23 PM, Error: Service Control Manager [7000] - The LogMeIn Hamachi Tunneling Engine service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
09/08/2012 6:12:21 PM, Error: Service Control Manager [7030] - The LogMeIn Hamachi Tunneling Engine service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
09/08/2012 6:07:08 PM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 7A7905094BB2. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
.
==== End Of File ===========================