Hi,
Where do you think she may have picked up this malware? She mainly goes on ebay, paypal, youtube and her grandson sometimes plays on online games. It would be handy to know just so she can be extra vigilant. Also why didn't my Norton 360 stop it from coming in?
DDS (Ver_09-12-01.01) - NTFSx86
Run by Chris & Derek at 17:06:02.15 on 08/01/2010
Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_17
Microsoft
Windows Vista
Home Premium 6.0.6002.2.1252.44.1033.18.1918.903 [GMT 0:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k nȯne
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Iconix\IconixService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxbtcoms.exe
C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\Mozilla Firefox\firefox.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Chris & Derek\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
uDefault_Page_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_gb&c=84&bd=Pavilion&pf=cndtuSearch Bar =
hxxp://www.google.com/iemStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_gb&c=84&bd=Pavilion&pf=cndtmDefault_Page_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_gb&c=84&bd=Pavilion&pf=cndtBHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.5.2.11\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.5.2.11\IPSBHO.DLL
BHO: IconixBHOClass Class: {761233b6-f228-49e4-8f6b-668499d4e55a} - c:\program files\iconix\ieaddon\IconixBHO_41.dll
BHO: AOL Toolbar BHO: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.5.2.11\coIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Uniblue SpyEraser] "c:\program files\uniblue\spyeraser\SpyEraser.exe" -m
uRun: [Uniblue SpeedUpMyPC] c:\program files\uniblue\speedupmypc 3\StartSUMP2.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
IE: &AOL Toolbar Search - c:\programdata\aol\ietoolbar\resources\en-gb\local\search.html
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - {44E212AB-13EA-4CA4-BE65-197FBA170412} - c:\program files\iconix\ieaddon\IconixBHO_41.dll
IE: {BC3F6B6D-2E49-4603-B028-7411655713F3} - {0CC2F28D-D415-4FC6-A2E4-54B4D983609A} - c:\program files\iconix\ieaddon\IconixBHO_41.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} -
hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cabDPF: {17492023-C23A-453E-A040-C7C580BBF700} -
hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cabDPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} -
hxxp://launcher.station.sony.com/weblauncher/plugin/1.0.3.84/SOEWebInstaller.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cabHandler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.5.2.11\CoIEPlg.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - c:\windows\system32\EZUPBH~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\chris&~1\appdata\roaming\mozilla\firefox\profiles\v196jpcw.default\
FF - prefs.js: browser.startup.homepage -
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_gb&c=84&bd=Pavilion&pf=cndtFF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npraclient.dll
FF - plugin: c:\program files\sony online entertainment\npsoe.dll
FF - plugin: c:\programdata\realarcade\npraclient.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - hȋdden: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - hȋdden: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - hȋdden: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - hȋdden: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - hȋdden: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0305020.00b\SymEFA.sys [2016-4-12 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0305020.00b\BHDrvx86.sys [2016-4-12 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0305020.00b\cchpx86.sys [2016-4-12 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091230.004\IDSvix86.sys [2010-1-4 343088]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [2008-1-21 21504]
R2 IconixService;Iconix Update Service;c:\program files\common files\iconix\IconixService.exe [2009-1-14 282968]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.5.2.11\ccSvcHst.exe [2016-4-12 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-12-17 102448]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\drivers\netr73.sys [2009-5-24 501248]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0305020.00b\symndisv.sys [2016-4-12 48688]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
=============== Created Last 30 ================
2016-04-14 13:07:22 0 d-----w- c:\users\chris&~1\appdata\roaming\iMaxGen
2016-04-13 18:01:13 0 d-----w- c:\users\chris&~1\appdata\roaming\Gamers Digital
2016-04-13 18:01:13 0 d-----w- c:\programdata\Gamers Digital
2016-04-12 17:11:11 0 d-----w- c:\users\chris&~1\appdata\roaming\Game Mill Entertainment
2016-04-12 17:07:06 0 d-----w- c:\users\chris&~1\appdata\roaming\BrokenHearts
2016-04-12 00:00:59 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2016-04-12 00:00:59 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2016-04-12 00:00:58 25648 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2016-04-12 00:00:52 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2016-04-12 00:00:52 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2016-04-12 00:00:52 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2016-04-12 00:00:51 0 d-----w- c:\program files\Symantec
2016-04-12 00:00:18 0 d-----w- c:\windows\system32\drivers\N360
2016-04-12 00:00:14 0 d-----w- c:\program files\Norton 360
2016-04-12 00:00:12 0 d-----w- c:\programdata\Office Genuine Advantage
2010-01-07 14:55:51 0 d-----w- c:\users\chris&~1\appdata\roaming\Malwarebytes
2010-01-07 14:55:45 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 14:55:44 0 d-----w- c:\programdata\Malwarebytes
2010-01-07 14:55:43 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 14:55:43 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-06 18:47:08 0 d-----w- c:\users\chris&~1\appdata\roaming\BlamGames
2010-01-06 14:05:52 0 d-----w- c:\program files\Trend Micro
2010-01-04 13:13:11 0 d-----r- c:\program files\Norton Support
2010-01-04 09:27:34 0 dc-h--w- c:\programdata\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2010-01-01 19:10:43 0 d-----w- c:\programdata\TheFallTrilogy
2009-12-31 20:03:59 0 d-----w- c:\users\chris&~1\appdata\roaming\Virtual City
2009-12-31 19:18:01 0 d-----w- c:\users\chris&~1\appdata\roaming\Aveyond 3
2009-12-31 19:15:58 0 d-----w- c:\users\chris&~1\appdata\roaming\MastersOfMystery2
2009-12-31 16:40:29 0 d-----w- c:\users\chris&~1\appdata\roaming\Scholastic
2009-12-31 16:33:08 0 d-----w- c:\windows\I Spy Spooky Mansion
2009-12-31 16:33:08 0 d-----w- c:\program files\I Spy Spooky Mansion
2009-12-30 18:47:23 0 d-----w- c:\users\chris&~1\appdata\roaming\Scrabble Plus
2009-12-27 17:02:46 0 d-----w- c:\users\chris&~1\appdata\roaming\Virtual Prophecy
2009-12-26 16:14:03 0 d-----w- c:\programdata\The Mirror Mysteries
2009-12-26 16:14:01 78 ----a-w- c:\windows\Numerical
2009-12-26 16:14:01 76 ----a-w- c:\windows\Spatial
2009-12-26 16:14:01 75 ----a-w- c:\windows\Verbal
2009-12-26 16:14:01 75 ----a-w- c:\windows\Memory
2009-12-26 16:14:01 74 ----a-w- c:\windows\Logic
2009-12-26 16:14:01 73 ----a-w- c:\windows\Times New Roman
2009-12-26 16:14:01 454 ----a-w- c:\windows\0
2009-12-26 16:13:47 0 d-----w- c:\program files\The Mirror Mysteries
2009-12-26 09:47:23 0 d-----w- c:\users\chris&~1\appdata\roaming\OtherSide Realm of Eons
2009-12-25 23:16:20 1772 ----a-w- c:\users\chris & derek\Desktop4 Elements.lnk
2009-12-19 09:36:54 0 d-----w- c:\windows\system32\drivers\NSS
2009-12-19 09:36:54 0 d-----w- c:\program files\Norton Security Scan
2009-12-17 18:22:30 72704 ----a-w- c:\windows\system32\admparse.dll
2009-12-17 18:11:24 0 d-----w- c:\programdata\PCSettings
2009-12-17 18:11:09 0 d-----w- c:\programdata\Norton
2009-12-17 18:11:01 0 d-----w- c:\programdata\NortonInstaller
2009-12-17 18:11:01 0 d-----w- c:\program files\NortonInstaller
2009-12-17 18:02:48 154 ----a-w- c:\users\chris&~1\appdata\roaming\wklnhst.dat
2009-12-17 17:59:18 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-12-10 09:41:11 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-10 09:41:09 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-10 09:41:09 30720 ----a-w- c:\windows\system32\httpapi.dll
==================== Find3M ====================
2016-04-12 00:00:54 51200 ----a-w- c:\windows\inf\infpub.dat
2016-04-12 00:00:53 143360 ----a-w- c:\windows\inf\infstrng.dat
2016-04-12 00:00:53 143360 ----a-w- c:\windows\inf\infstor.dat
2009-11-21 06:40:20 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34:39 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34:39 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59:58 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 09:14:51 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-18 09:14:38 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 09:14:22 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-29 09:17:42 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-11 04:17:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-09-01 03:04:14 8192 --sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 17:07:52.58 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft
Windows Vista
Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 16/09/2008 20:03:30
System Uptime: 01/08/2010 10:50:59 (-4913 hours ago)
Motherboard: OEM_MB | | Acacia
Processor: AMD Athlon(tm) Dual Core Processor 4450e | Socket AM2 | 2300/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 286 GiB total, 194.784 GiB free.
D: is FIXED (NTFS) - 13 GiB total, 1.719 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB CF Reader
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_CF_READER&REV_1.01#920321111113&1#
Manufacturer: Generic
Name: USB CF Reader
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_CF_READER&REV_1.01#920321111113&1#
Service: WUDFRd
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB MS Reader
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_MS_READER&REV_1.03#920321111113&3#
Manufacturer: Generic
Name: USB MS Reader
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_MS_READER&REV_1.03#920321111113&3#
Service: WUDFRd
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB SD Reader
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_SD_READER&REV_1.00#920321111113&0#
Manufacturer: Generic
Name: USB SD Reader
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_SD_READER&REV_1.00#920321111113&0#
Service: WUDFRd
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB SM Reader
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_SM_READER&REV_1.02#920321111113&2#
Manufacturer: Generic
Name: USB SM Reader
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_SM_READER&REV_1.02#920321111113&2#
Service: WUDFRd
==== System Restore Points ===================
RP295: 04/12/2009 00:00:06 - Scheduled Checkpoint
RP296: 04/12/2009 12:22:08 - Scheduled Checkpoint
RP297: 04/12/2009 14:55:09 - Uniblue RegistryBooster 2009
RP298: 05/12/2009 13:24:54 - Scheduled Checkpoint
RP299: 06/12/2009 15:01:13 - Scheduled Checkpoint
RP300: 07/12/2009 09:37:57 - Scheduled Checkpoint
RP301: 08/12/2009 13:52:35 - Scheduled Checkpoint
RP302: 09/12/2009 09:20:35 - Scheduled Checkpoint
RP303: 10/12/2009 00:00:05 - Scheduled Checkpoint
RP304: 10/12/2009 09:37:09 - Windows Update
RP305: 10/12/2009 15:34:24 - Uniblue RegistryBooster 2009
RP306: 11/12/2009 16:53:13 - Scheduled Checkpoint
RP309: 17/12/2009 17:58:48 - Windows Update
RP310: 17/12/2009 18:20:10 - Windows Update
RP312: 25/12/2009 08:33:54 - Windows Update
RP307: 12/04/2016 01:54:07 - Scheduled Checkpoint
RP308: 12/04/2016 19:19:55 - Scheduled Checkpoint
RP311: 13/04/2016 14:41:21 - Scheduled Checkpoint
==== Installed Programs ======================
10 Days To Save The World-The Adventures Of Diana Salinger .
10 Days To Save The World 1.00
1001 Nights The Adventures Of Sindbad 1.00
4 Elements .
ActiveCheck component for HP Active Support Library
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.2
Adobe Shockwave Player 11.5
Agatha Christie - Dead Mans Folly
Age Of Oracles-Tara's Journey .
Alabama Smith in the Quest of Fate 1.00
Alexandra Fortune Mystery of the Lunar Archipelago 1.00
Amazing Adventures The Caribbean Secret 1.00
AOL Toolbar 5.0
µTorrent
Becky Brogan The Mystery of Meane Manor
Between the Worlds 1.00
Big Fish Games Client
Born Into Darkness 1.00
Brain Trainer
Broken Hearts - A Soldier's Duty 1.00
Campfire Legends The Hookman 1.00
Cards_Calendar_OrderGift_DoMorePlugout
Compatibility Pack for the 2007 Office system
Coupon Printer
Curse of the Pharaoh Tears of Sekhmet 1.00
CyberLink DVD Suite Deluxe
Dark Tales - Edgar Allan Poes Murders in the Rue Morgue Collectors Edition 1.00
Detective Agency .
Dream Sleuth 1.00
Enhanced Multimedia Keyboard Solution
Express Burn
Forgotten Riddles - The Moonlight Sonatas
GearDrvs
GHOST Hunters-The Haunting Of Majesty Manor .
Google Toolbar for Internet Explorer
Hardware Diagnostic Tools
Harlequin Presents hȋdden Object of Desire 1.00
hȋdden Magic .
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Advisor
HP Customer Experience Enhancements
HP Customer Feedback
HP Demo
HP Easy Setup - Frontend
HP Games
HP MediaSmart DVD
HP On-Screen Cap/Num/Scroll Lock Indicator
HP Photosmart Essential 2.5
HP Photosmart Essential 3.0
HP Picasso Media Center Add-In
HP Recovery Manager RSS
HP Update
HPAsset component for HP Active Support Library
HPPhotoSmartPhotobookWebPack1
I Spy Spooky Mansion
Iconix
eMail ID
Insider Tales The Secret Of Casanova 1.00
iTunes
Jane Angel Templar Mystery 1.00
Java(TM) 6 Update 17
Java(TM) SE Runtime Environment 6 Update 1
LabelPrint
Lexmark 5200 Series
LightScribe System Software
Lost City of Z 1.00
Lost Realms The Curse of Babylon 1.00
Magic Desktop
Malwarebytes' Anti-Malware
Masters Of Mystery-Blood Of Betrayal .
Microsoft .NET Framework 3.5 SP1
Microsoft Office Home and Student 60 day trial
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Works
Mishap An Accidental Haunting 1.00
Mozilla Firefox (3.0.15)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Murder, She Wrote 1.00
muvee autoProducer 6.1
myibay eBay bid sniper 1.0.39
Mystery of Cleopatra 1.00
NCH Toolbox
Norton 360
Norton Security Scan
NVIDIA Drivers
OGA Notifier 2.0.0048.0
Power2Go
PowerDirector
Profiler The Hopscotch Killer
PSSWCORE
PuppetShow Mystery of Joyville 1.00
Python 2.5.2
QuickTime
RealArcade
Realtek High Definition Audio Driver
Reincarnations Awakening 1.00
Route 66 .
Samantha Swift and the Mystery From Atlantis 1.00
Scrabble Plus 1.00
Slice Audio File Splitter
Superior Save .
Syberia 1 1.00
The Dark Hills of Cherai 1.00
The Fall Trilogy 1.00
The Mirror Mysteries
The Otherside Realm of Eons 1.10
The Return of Monte Cristo
The Tudors 1.00
Uniblue DriverScanner 2009
Uniblue PowerSuite
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VideoToolkit01
Vuze
WavePad Sound Editor
WinRAR archiver
Youda Legend - The Curse of the Amsterdam Diamond 1.00
==== Event Viewer Messages From Past Week ========
14/04/2016 12:47:16, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -199144617 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
13/04/2016 00:54:00, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -198857118 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
12/04/2016 04:45:51, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -199200384 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
12/04/2016 01:08:32, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
12/04/2016 01:07:39, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
12/04/2016 01:05:36, Error: Service Control Manager [7022] - The Background Intelligent Transfer Service service hung on starting.
12/04/2016 01:01:16, Error: Service Control Manager [7030] - The -- service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
12/04/2016 01:01:16, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the -- service to connect.
12/04/2016 01:01:16, Error: Service Control Manager [7000] - The -- service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/04/2016 01:00:41, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -199205509 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
12/04/2016 01:00:34, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -199098095 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
12/04/2016 01:00:15, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -199339633 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
12/04/2016 01:00:13, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -199148433 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
12/04/2016 01:00:12, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -199196570 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
12/04/2016 01:00:12, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -199134282 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
12/04/2016 01:00:00, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -199140836 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.232.182:123) is working properly.
08/01/2010 10:53:00, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt
08/01/2010 10:53:00, Error: Service Control Manager [7001] - The Windows Media Player Network Sharing Service service depends on the UPnP Device Host service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
08/01/2010 10:53:00, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
04/01/2010 19:49:31, Error: EventLog [6008] - The previous system shutdown at 19:47:09 on 04/01/2010 was unexpected.
04/01/2010 09:29:46, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
04/01/2010 09:24:42, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
04/01/2010 09:10:19, Error: EventLog [6008] - The previous system shutdown at 11:30:20 on 03/01/2010 was unexpected.
03/01/2010 09:44:38, Error: EventLog [6008] - The previous system shutdown at 09:20:05 on 03/01/2010 was unexpected.
01/01/2010 09:24:50, Error: EventLog [6008] - The previous system shutdown at 05:43:14 on 01/01/2010 was unexpected.
==== End Of File ===========================