I have been trying to remove viruses, spyware etc. from my PC without luck. I ran ATF cleaner, ERUNT, Malwarebytes (found and removed 38 things), all windows updates (excluding XP SP3 due to size), rootkit and OTListIt2, still having issues. SysRestorePoint would not run without v2 .NET framework, have tried windows system restore using two different restore points but this failed both times so perhaps this would not help anyway
Norton 360 anti-virus and anti-spyware scans currently clean (even before the malwarebytes scan). Viruses previously found and removed (symptoms started when no anti-virus was installed)
Symptoms include:
- Running regedit.exe, regedt32.exe do not open regedit, instead the desktop and task bar are removed for a second or two before being reinstated. Opening any .reg file or alternate registry editor does the same thing. Tried setting the registry editor block in gpedit.msc to disabled but this did not help
- Running reg.exe flashes the command prompt up then closes it
- System Protector rogue registry cleaner was running - managed to remove it but it still showed in control panel and when right-clicking a file offering to scan it. Now removed - guessing thanks to Malwarebytes
- System slow to load internet pages - ccSvcHist.exe, svchost.exe and dump something.exe often at the top in task manager
- Selecting google search results often does a jump and redirect
- Generic win32 host service, internet explorer and symantec service framework crashing on semi regular basis. Mobile Broadband internet sometimes being disconnected
- cmd.exe does the same thing as running regedit.exe and regedt32.exe but command.com works
- Task manager through Ctrl + Alt + Del and right-clicking on the taskbar was disabled - fixed by editing the restriction in gpedit.msc
- Changing the screen resolution isn't actually doing anything - can select the 1024x768 option and apply but the screen does not actually resize from 800x600
- Getting a black screen when performing a windows restart - using the windows turn off function then powering on works fine
- Windows System Restore is not working
I am running windows xp professional SP2, internet explorer 7
Here are the rootkit and OTListIt2 logs. Appreciate your help, have been googling and troubleshooting for 4 days with limited success
rootkit
--------
Microsoft Windows XP Professional (5.1.2600) Service Pack 2
C:\ [Fixed] - NTFS - (Total:76308 Mo/Free:3911 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:22 Mo/Free:0 Mo)
F:\ [Removable] (Total:0 Mo/Free:0 Mo)
Wed 04/01/2009|19:41
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\Ati2evxx.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\Ati2evxx.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
---------- C:\Program Files\Bonjour\mDNSResponder.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
---------- C:\Program Files\Spyware Doctor\pctsAuxs.exe
---------- C:\WINDOWS\system32\ctfmon.exe
---------- C:\Program Files\3 MobileBroadband\3 MobileBroadband.exe
---------- C:\Program Files\Spyware Doctor\pctsSvc.exe
---------- C:\Program Files\Spyware Doctor\pctsTray.exe
---------- c:\program files\idt\intelxpv_v83\wdm\STacSV.exe
---------- C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\Program Files\Internet Explorer\iexplore.exe
---------- C:\WINDOWS\system32\wuauclt.exe
---------- C:\WINDOWS\system32\wuauclt.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - Wed 04/01/2009|19:42
OTListIt
---------
OTListIt logfile created on: 4/1/2009 7:46:14 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.8.0 Folder = C:\Documents and Settings\Michael\Desktop\Virus
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1021.58 Mb Total Physical Memory | 569.11 Mb Available Physical Memory | 55.71% Memory free
2.39 Gb Paging File | 1.82 Gb Available in Paging File | 76.18% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 63.82 Gb Free Space | 85.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 23.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SNUGGLEGLOOM
Current User Name: Michael
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\3 MobileBroadband\3 MobileBroadband.exe ()
PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
PRC - c:\program files\idt\intelxpv_v83\wdm\STacSV.exe (IDT, Inc.)
PRC - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Michael\Desktop\Virus\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (N360 [Auto | Running]) -- C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe (Symantec Corporation)
SRV - (sdAuxService [Auto | Running]) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [Auto | Running]) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (STacSV [Auto | Running]) -- c:\program files\idt\intelxpv_v83\wdm\STacSV.exe (IDT, Inc.)
========== Driver Services (SafeList) ==========
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (BHDrvx86 [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\BHDrvx86.sys (Symantec Corporation)
DRV - (ccHP [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\ccHPx86.sys (Symantec Corporation)
DRV - (cercsr6 [Boot | Stopped]) -- C:\WINDOWS\System32\drivers\cercsr6.sys (Adaptec, Inc.)
DRV - (e1express [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\e1e5132.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (hwdatacard [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ialm [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (IDSxpx86 [System | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090331.003\IDSxpx86.sys (Symantec Corporation)
DRV - (NAVENG [On_Demand | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090331.052\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090331.052\NAVEX15.SYS (Symantec Corporation)
DRV - (PCTCore [Boot | Running]) -- C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (SE2Ebus [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys (MCCI)
DRV - (SE2Emdfl [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys (MCCI)
DRV - (SE2Emdm [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys (MCCI)
DRV - (SE2Emgmt [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys (MCCI)
DRV - (se2End5 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\se2End5.sys (MCCI)
DRV - (SE2Eobex [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys (MCCI)
DRV - (se2Eunic [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\se2Eunic.sys (MCCI)
DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys ()
DRV - (SRTSP [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SRTSPX.SYS (Symantec Corporation)
DRV - (STHDA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (SymEFA [Boot | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMEFA.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) -- C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMIDS.SYS (Symantec Corporation)
DRV - (SymIM [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SymIMMP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMTDI.SYS (Symantec Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft....k/?LinkId=54843
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://au.games.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://au.games.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/08 18:35:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{1A16DA43-1CC3-42AA-9CC0-26FAE2E0E090}: C:\DOCUMENTS AND SETTINGS\MICHAEL\LOCAL SETTINGS\APPLICATION DATA\{1A16DA43-1CC3-42AA-9CC0-26FAE2E0E090}\ [2009/03/31 09:08:35 | 00,000,000 | ---D | M]
[2009/03/28 18:42:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\mozilla\Extensions
[2009/03/28 18:42:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/29 03:54:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\mozilla\Firefox\Profiles\h20omo8p.default\extensions
[2009/03/28 20:15:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\mozilla\Firefox\Profiles\h20omo8p.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.0.0.135\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKCU..\Run: [Mobile Partner] "C:\Program Files\3 MobileBroadband\3 MobileBroadband.exe" ()
O4 - Startup: C:\Documents and Settings\Michael\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\Michael\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe (Leader Technologies)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogOff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSecCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDevMgrPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoConfigPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVirtMemPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoFileSysPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoNetSetup = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoNetSetupIDPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoNetSetupSecurityPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoWorkgroupContents = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoEntireNetwork = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoFileSharingControl = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} http://games.bigfish...eb.1.0.0.21.cab (CPlayFirstFashionDasControl Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} http://games.bigfish...Web.1.0.0.9.cab (CPlayFirstCookingDasControl Object)
O16 - DPF: {26E6B759-DEEB-42A1-A21C-78CD29098411} http://games.bigfish...eb.1.0.0.11.cab (CPlayFirstFitnessDasControl Object)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.s...abs/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} http://apps.corel.co...IEGetPlugin.ocx (get_atlcom Class)
O16 - DPF: {4DCA1E08-4147-4A3D-8CA6-E095DF189FAB} http://games.bigfish...Web.1.0.0.9.cab (CPlayFirstNightshiftControl Object)
O16 - DPF: {74EF5274-F439-2168-B543-14745B625C72} http://games.bigfish...eb.1.0.0.11.cab (CPlayFirstWeddingDasControl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} http://games.bigfish...tg.1.0.0.33.cab (CPlayFirstddfotgControl Object)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D40F5876-A494-4124-8161-82625BB28C06} http://games.bigfish...eb.1.0.0.10.cab (CPlayFirstChocolatieControl Object)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} http://games.bigfish...inematycoon.cab (TikGames Online Control)
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} http://gamecenter.ob...sh.1.0.0.47.cab (CPlayFirstWeddingDashControl Object)
O16 - DPF: {F135A813-7152-4532-AC8D-28AC2136DFC7} http://games.bigfish...sh.1.0.0.10.cab (CPlayFirstParkingDasControl Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll (Symantec Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - E:\AutoRun.exe (Huawei Technologies Co., Ltd.) - [ CDFS ]
O32 - Autorun File - E:\AUTORUN.INF () - [ CDFS ]
O33 - MountPoints2\{5914b09a-0b98-11de-99c1-cda28a94d62d}\Shell - "" = AutoRun
O33 - MountPoints2\{5914b09a-0b98-11de-99c1-cda28a94d62d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5914b09a-0b98-11de-99c1-cda28a94d62d}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/09/03 11:07:56 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/09/03 11:07:56 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/04/01 19:41:35 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/04/01 19:39:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2009/04/01 18:54:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Malwarebytes
[2009/04/01 18:53:56 | 00,000,696 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/01 18:53:55 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/01 18:53:52 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/01 18:53:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/01 18:53:50 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/01 18:51:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/04/01 18:49:22 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\Michael\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/01 18:49:09 | 00,000,611 | ---- | C] () -- C:\DOCUME~1\Michael\Desktop\NTREGOPT.lnk
[2009/04/01 18:49:09 | 00,000,592 | ---- | C] () -- C:\DOCUME~1\Michael\Desktop\ERUNT.lnk
[2009/04/01 18:49:07 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/04/01 18:26:22 | 00,000,000 | ---D | C] -- C:\hijackthis
[2009/04/01 18:14:54 | 00,000,452 | ---- | C] () -- C:\WINDOWS\tasks\XoftSpySE 2.job
[2009/04/01 18:14:53 | 00,000,366 | ---- | C] () -- C:\WINDOWS\tasks\XoftSpySE.job
[2009/04/01 18:14:51 | 00,000,682 | ---- | C] () -- C:\DOCUME~1\Michael\Desktop\XoftSpySE.lnk
[2009/04/01 18:14:51 | 00,000,000 | ---D | C] -- C:\Program Files\XoftSpySE
[2009/04/01 16:50:40 | 25,932,272 | ---- | C] () -- C:\WINDOWS\Copy of Software.reg
[2009/04/01 16:09:43 | 00,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009/04/01 05:37:58 | 25,932,272 | ---- | C] () -- C:\WINDOWS\Software.reg
[2009/04/01 05:31:20 | 00,000,000 | ---D | C] -- C:\WINDOWS\Special Agent P. C. Secure
[2009/04/01 05:31:20 | 00,000,000 | ---D | C] -- C:\Program Files\Easy Desk Utilities
[2009/04/01 05:10:00 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Michael\Desktop\Virus
[2009/04/01 04:51:55 | 00,159,600 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2009/04/01 04:51:45 | 00,130,424 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2009/04/01 04:51:45 | 00,073,840 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2009/04/01 04:51:32 | 00,064,392 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2009/04/01 04:51:32 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2009/04/01 04:51:21 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2009/04/01 04:51:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\PC Tools
[2009/04/01 04:51:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2009/04/01 04:51:19 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\STKIT432.DLL
[2009/04/01 04:51:18 | 01,081,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSCOMCTL.OCX
[2009/04/01 04:51:14 | 00,000,000 | ---D | C] -- C:\Program Files\Registry Mechanic
[2009/04/01 03:16:01 | 00,000,000 | ---D | C] -- C:\EmergencyUtils
[2009/04/01 03:10:02 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/04/01 02:23:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Uniblue
[2009/04/01 02:23:11 | 00,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2009/04/01 02:03:00 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2009/04/01 02:01:34 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
[2009/04/01 01:43:20 | 00,000,000 | R--D | C] -- C:\Program Files\Norton Support
[2009/04/01 01:04:41 | 00,016,244 | ---- | C] () -- C:\WINDOWS\System32\rrt_is.wav
[2009/04/01 01:04:41 | 00,007,302 | ---- | C] () -- C:\WINDOWS\System32\rrt_vf.wav
[2009/04/01 01:04:41 | 00,007,148 | ---- | C] () -- C:\WINDOWS\System32\rrt_tv.wav
[2009/04/01 01:04:41 | 00,006,282 | ---- | C] () -- C:\WINDOWS\System32\rrt_tn.wav
[2009/04/01 01:03:43 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009/03/31 21:10:56 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2009/03/31 14:28:13 | 00,001,572 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Play My Games.lnk
[2009/03/31 14:28:13 | 00,001,550 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\More Great Games.lnk
[2009/03/31 14:28:12 | 00,000,000 | ---D | C] -- C:\Program Files\bfgclient
[2009/03/31 14:27:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
[2009/03/31 12:26:29 | 00,000,648 | ---- | C] () -- C:\DOCUME~1\Michael\Desktop\wlkbuddy.lnk
[2009/03/31 12:26:04 | 00,000,000 | ---D | C] -- C:\Program Files\wlkbuddy
[2009/03/31 12:25:41 | 00,763,863 | ---- | C] () -- C:\DOCUME~1\Michael\My Documents\install.exe
[2009/03/31 11:43:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Symantec
[2009/03/31 11:18:43 | 74,949,864 | ---- | C] (Symantec Corporation) -- C:\DOCUME~1\Michael\My Documents\N360S300EN.exe
[2009/03/31 09:56:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2009/03/31 09:56:29 | 01,108,782 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\Cat.DB
[2009/03/31 09:56:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Downloaded Installations
[2009/03/31 09:56:15 | 00,036,400 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SymIM.sys
[2009/03/31 09:56:11 | 00,124,464 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/03/31 09:56:11 | 00,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2009/03/31 09:56:11 | 00,007,386 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/03/31 09:56:11 | 00,000,805 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/03/31 09:56:11 | 00,000,000 | ---D | C] -- C:\Program Files\Symantec
[2009/03/31 09:56:11 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2009/03/31 09:56:04 | 00,001,909 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Norton 360.LNK
[2009/03/31 09:56:03 | 00,310,320 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.sys
[2009/03/31 09:56:03 | 00,307,760 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.sys
[2009/03/31 09:56:03 | 00,217,392 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symtdi.sys
[2009/03/31 09:56:03 | 00,089,776 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symfw.sys
[2009/03/31 09:56:03 | 00,043,696 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.sys
[2009/03/31 09:56:03 | 00,039,984 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symndisv.sys
[2009/03/31 09:56:03 | 00,037,296 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symndis.sys
[2009/03/31 09:56:03 | 00,034,736 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symids.sys
[2009/03/31 09:56:02 | 00,482,352 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\cchpx86.sys
[2009/03/31 09:56:02 | 00,258,608 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.sys
[2009/03/31 09:55:46 | 00,003,373 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.inf
[2009/03/31 09:55:46 | 00,001,753 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\ccHPx86.inf
[2009/03/31 09:55:46 | 00,001,528 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymNet.inf
[2009/03/31 09:55:46 | 00,001,389 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.inf
[2009/03/31 09:55:46 | 00,001,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.inf
[2009/03/31 09:55:46 | 00,000,640 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.inf
[2009/03/31 09:55:46 | 00,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\isolate.ini
[2009/03/31 09:55:36 | 00,009,423 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymNet.cat
[2009/03/31 09:55:36 | 00,007,410 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.cat
[2009/03/31 09:55:36 | 00,007,372 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.cat
[2009/03/31 09:55:36 | 00,007,364 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.CAT
[2009/03/31 09:55:36 | 00,007,355 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.cat
[2009/03/31 09:55:36 | 00,007,347 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\ccHPx86.cat
[2009/03/31 09:55:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360\0300000.087
[2009/03/31 09:55:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
[2009/03/31 09:55:34 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2009/03/31 09:55:34 | 00,000,000 | ---D | C] -- C:\Program Files\Norton 360
[2009/03/31 09:55:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2009/03/31 09:55:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2009/03/31 09:55:23 | 00,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2009/03/31 09:55:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/03/31 09:23:07 | 00,000,418 | ---- | C] () -- C:\WINDOWS\tasks\RegTool Scan.job
[2009/03/31 09:23:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\RegTool
[2009/03/31 09:08:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\{1A16DA43-1CC3-42AA-9CC0-26FAE2E0E090}
[2009/03/31 09:08:31 | 00,155,648 | ---- | C] (Mozilla Foundation) -- C:\WINDOWS\atefidel.dll
[2009/03/31 08:56:19 | 00,042,496 | ---- | C] (Johnson-Grace Company) -- C:\WINDOWS\Ctozovilo.dll
[2009/03/30 11:07:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GamesBar
[2009/03/30 11:07:14 | 00,000,000 | ---D | C] -- C:\Program Files\GamesBar
[2009/03/29 05:15:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2009/03/29 05:15:50 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2009/03/29 05:14:42 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie7
[2009/03/29 05:14:27 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
[2009/03/29 05:13:57 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
[2009/03/29 05:13:08 | 00,121,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xmllite.dll
[2009/03/29 03:58:20 | 00,000,000 | ---D | C] -- C:\plan change receipt
[2009/03/29 03:58:07 | 00,000,000 | ---D | C] -- C:\katamari
[2009/03/29 03:57:51 | 00,000,000 | ---D | C] -- C:\video card driver
[2009/03/29 03:55:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2009/03/29 03:36:57 | 00,000,434 | ---- | C] () -- C:\WINDOWS\tasks\RegFixPro Scan.job
[2009/03/29 03:36:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\RegFixPro
[2009/03/29 03:23:46 | 00,004,608 | ---- | C] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/29 03:23:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\movies
[2009/03/29 03:08:02 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmpns.dll
[2009/03/28 18:42:27 | 00,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/03/28 18:42:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Mozilla
[2009/03/28 18:42:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Mozilla
[2009/03/28 17:24:07 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2009/03/26 12:32:57 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Michael\My Documents\My Games
[2009/03/26 12:32:45 | 00,001,782 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Age of Mythology - The Titans Expansion.lnk
[2009/03/25 13:54:57 | 00,520,192 | ---- | C] (ScreenTime Media) -- C:\WINDOWS\System32\Beautiful Katamari.scr
[2009/03/25 13:54:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Beautiful Katamari dir
[2009/03/23 10:11:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2009/03/23 10:05:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Google
[2009/03/23 10:04:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Google
[2009/03/23 10:02:50 | 00,000,000 | ---D | C] -- C:\Program Files\Google
[2009/03/23 02:17:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2009/03/21 14:39:25 | 00,001,773 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Age of Mythology.lnk
[2009/03/21 12:41:51 | 00,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2009/03/21 12:40:29 | 00,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2009/03/21 12:39:57 | 00,000,000 | ---D | C] -- C:\ATI
[2009/03/17 08:54:39 | 00,002,137 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\iTunes.lnk
[2009/03/17 08:54:22 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/03/17 08:54:19 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/03/17 08:54:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/03/17 08:54:06 | 00,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2009/03/17 08:53:50 | 00,001,604 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\QuickTime Player.lnk
[2009/03/17 08:53:14 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2009/03/17 08:53:14 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2009/03/17 08:52:53 | 00,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/17 08:52:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Apple
[2009/03/17 08:52:51 | 00,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2009/03/17 08:52:29 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2009/03/17 08:52:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2009/03/17 08:51:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Apple Computer
[2009/03/16 15:02:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Adobe
[2009/03/10 20:48:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\PlayFirst
[2009/03/10 20:48:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/03/10 20:48:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/10 20:48:07 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Oberon Media
[2009/03/10 20:48:06 | 00,000,000 | ---D | C] -- C:\Program Files\Oberon Media
[2009/03/09 03:24:41 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2009/03/08 18:37:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2009/03/08 18:35:01 | 00,000,000 | ---D | C] -- C:\Program Files\Java
[2009/03/08 18:33:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Sun
[2009/03/08 17:15:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2009/03/08 17:15:47 | 00,000,906 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Mystery P.I. - The Lottery Ticket.lnk
[2009/03/08 17:15:46 | 00,000,000 | ---D | C] -- C:\Program Files\PopCap Games
[2009/03/08 15:57:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Macromedia
[2009/03/08 15:29:15 | 00,272,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthport.sys
[2009/03/08 15:29:15 | 00,272,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys
[2009/03/08 15:21:08 | 00,000,790 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\3 MobileBroadband.lnk
[2009/03/08 15:20:55 | 00,872,192 | ---- | C] (DiBcom SA) -- C:\WINDOWS\System32\drivers\mod7700.sys
[2009/03/08 15:20:55 | 00,103,168 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbfake.sys
[2009/03/08 15:20:55 | 00,101,376 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbmdm.sys
[2009/03/08 15:20:55 | 00,100,992 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbnet.sys
[2009/03/08 15:20:55 | 00,024,448 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewdcsc.sys
[2009/03/08 15:20:25 | 00,000,000 | ---D | C] -- C:\Program Files\3 MobileBroadband
[2009/03/07 20:23:56 | 00,001,857 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\MSN Installer.lnk
[2009/03/07 19:00:12 | 00,018,704 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\se2End5.sys
[2009/03/07 19:00:08 | 00,090,800 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\se2Eunic.sys
[2009/03/07 19:00:08 | 00,004,128 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\se2Ecr.sys
[2009/03/07 17:49:37 | 21,244,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/03/07 17:38:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Apple Computer
[2009/03/07 17:37:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\AdobeUM
[2009/03/07 17:35:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Sony Ericsson
[2009/03/07 17:35:05 | 00,088,688 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\SE2Emgmt.sys
[2009/03/07 17:35:01 | 00,086,560 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\SE2Eobex.sys
[2009/03/07 17:34:52 | 00,097,184 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\SE2Emdm.sys
[2009/03/07 17:34:52 | 00,009,360 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\SE2Emdfl.sys
[2009/03/07 17:34:52 | 00,006,240 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\SE2Ecmnt.sys
[2009/03/07 17:34:52 | 00,006,240 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\SE2Ecm.sys
[2009/03/07 17:34:48 | 00,061,600 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\SE2Ebus.sys
[2009/03/07 17:34:48 | 00,005,872 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\SE2Ewhnt.sys
[2009/03/07 17:34:48 | 00,005,872 | R--- | C] (MCCI) -- C:\WINDOWS\System32\drivers\SE2Ewh.sys
[2009/03/07 17:32:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Adobe
[2009/03/07 17:32:47 | 00,002,007 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Adobe Photoshop Album Starter Edition 3.0.lnk
[2009/03/07 17:32:16 | 00,001,740 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Adobe Reader 7.0.lnk
[2009/03/07 17:32:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2009/03/07 17:29:45 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/03/07 17:29:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/07 17:27:56 | 00,015,360 | ---- | C] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/07 17:27:30 | 00,000,000 | ---D | C] -- C:\Program Files\Disc2Phone
[2009/03/07 17:24:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\ApplicationHistory
[2009/03/07 17:20:12 | 00,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2009/03/07 17:20:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2009/03/07 17:20:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTemp
[2009/03/07 17:18:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Teleca
[2009/03/07 17:17:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Sony Ericsson
[2009/03/07 17:15:39 | 00,002,673 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Sony Ericsson PC Suite.lnk
[2009/03/07 17:15:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2009/03/07 17:15:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sony Ericsson
[2009/03/07 17:15:24 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Sony Ericsson Shared
[2009/03/07 17:15:21 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Teleca Shared
[2009/03/07 17:15:20 | 00,000,000 | ---D | C] -- C:\Program Files\Sony Ericsson
[2009/03/07 17:15:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Teleca
[2009/03/07 17:15:14 | 00,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2009/03/07 17:10:48 | 00,001,589 | ---- | C] () -- C:\DOCUME~1\Michael\Desktop\The Puzzle Collection.lnk
[2009/03/07 17:10:16 | 00,000,882 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Acrobat Reader 5.1.lnk
[2009/03/07 17:10:14 | 00,000,000 | ---D | C] -- C:\WINDOWS\Profiles
[2009/03/07 17:10:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2009/03/07 17:10:13 | 00,000,000 | ---D | C] -- C:\Program Files\Adobe
[2009/03/07 17:10:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\InterTrust
[2009/03/07 17:10:13 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Michael\My Documents\My eBooks
[2009/03/07 17:09:29 | 00,000,000 | ---D | C] -- C:\Program Files\The Puzzle Collection
[2009/03/07 17:05:40 | 00,000,856 | ---- | C] () -- C:\DOCUME~1\Michael\Desktop\MahJongg.LNK
[2009/03/07 17:03:58 | 00,000,000 | ---D | C] -- C:\Program Files\Classic Games
[2009/03/07 17:03:33 | 00,000,036 | ---- | C] () -- C:\WINDOWS\Tiny_Run.ini
[2009/03/07 17:01:50 | 00,001,801 | ---- | C] () -- C:\DOCUME~1\Michael\Desktop\Age of Empires.lnk
[2009/03/07 16:57:45 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Games
[2009/03/07 16:48:18 | 00,001,909 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\RollerCoaster Tycoon 2 Triple Thrill Pack.lnk
[2009/03/07 16:48:13 | 00,225,280 | ---- | C] (Leader Technologies) -- C:\Documents and Settings\Michael\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
[2009/03/07 16:48:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Leadertech
[2009/03/07 16:45:24 | 00,000,000 | ---D | C] -- C:\Program Files\Atari
[2009/03/07 13:20:49 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak
[2009/03/07 13:20:39 | 05,365,922 | -H-- | C] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\IconCache.db
[2009/03/07 13:20:26 | 00,012,598 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
[2009/03/07 13:19:12 | 02,180,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2009/03/07 13:19:12 | 02,136,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2009/03/07 13:19:12 | 02,015,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2009/03/07 13:19:11 | 02,057,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2009/03/07 13:18:58 | 00,453,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2009/03/07 13:18:06 | 00,000,786 | ---- | C] () -- C:\DOCUME~1\Michael\Desktop\Windows Media Player.lnk
[2009/03/07 13:18:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Identities
[2009/03/07 13:18:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2009/03/07 13:18:01 | 00,017,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2009/03/07 13:17:58 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2009/03/07 13:17:56 | 00,000,078 | -HS- | C] () -- C:\DOCUME~1\Michael\My Documents\desktop.ini
[2009/03/07 13:17:56 | 00,000,000 | R--D | C] -- C:\DOCUME~1\Michael\My Documents\My Pictures
[2009/03/07 13:17:56 | 00,000,000 | R--D | C] -- C:\DOCUME~1\Michael\My Documents\My Music
[2009/03/07 13:17:51 | 00,000,084 | -HS- | C] () -- C:\Documents and Settings\Michael\Start Menu\Programs\Startup\desktop.ini
[2009/03/07 13:17:51 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Michael\Application Data\desktop.ini
[2009/03/07 13:17:50 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Michael\Application Data\Microsoft
[2009/03/07 13:17:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Microsoft
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/04/01 19:36:52 | 00,000,452 | ---- | M] () -- C:\WINDOWS\tasks\XoftSpySE 2.job
[2009/04/01 19:36:51 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/01 19:36:47 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/01 19:35:17 | 05,365,922 | -H-- | M] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\IconCache.db
[2009/04/01 19:21:16 | 00,000,696 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/01 18:49:22 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\Michael\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/01 18:49:09 | 00,000,611 | ---- | M] () -- C:\DOCUME~1\Michael\Desktop\NTREGOPT.lnk
[2009/04/01 18:49:09 | 00,000,592 | ---- | M] () -- C:\DOCUME~1\Michael\Desktop\ERUNT.lnk
[2009/04/01 18:14:54 | 00,000,366 | ---- | M] () -- C:\WINDOWS\tasks\XoftSpySE.job
[2009/04/01 18:14:51 | 00,000,682 | ---- | M] () -- C:\DOCUME~1\Michael\Desktop\XoftSpySE.lnk
[2009/04/01 16:22:28 | 00,000,010 | ---- | M] () -- C:\WINDOWS\WININIT.INI
[2009/04/01 12:00:00 | 00,000,434 | ---- | M] () -- C:\WINDOWS\tasks\RegFixPro Scan.job
[2009/04/01 12:00:00 | 00,000,418 | ---- | M] () -- C:\WINDOWS\tasks\RegTool Scan.job
[2009/04/01 06:02:02 | 00,000,477 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/04/01 06:02:02 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/04/01 06:02:02 | 00,000,211 | -H-- | M] () -- C:\boot.ini
[2009/04/01 05:38:05 | 25,932,272 | ---- | M] () -- C:\WINDOWS\Software.reg
[2009/04/01 05:38:05 | 25,932,272 | ---- | M] () -- C:\WINDOWS\Copy of Software.reg
[2009/04/01 04:49:06 | 00,002,137 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\iTunes.lnk
[2009/04/01 02:03:33 | 01,108,782 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\Cat.DB
[2009/04/01 01:04:41 | 00,016,244 | ---- | M] () -- C:\WINDOWS\System32\rrt_is.wav
[2009/04/01 01:04:41 | 00,007,302 | ---- | M] () -- C:\WINDOWS\System32\rrt_vf.wav
[2009/04/01 01:04:41 | 00,007,148 | ---- | M] () -- C:\WINDOWS\System32\rrt_tv.wav
[2009/04/01 01:04:41 | 00,006,282 | ---- | M] () -- C:\WINDOWS\System32\rrt_tn.wav
[2009/03/31 14:30:25 | 00,001,550 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\More Great Games.lnk
[2009/03/31 14:28:13 | 00,001,572 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Play My Games.lnk
[2009/03/31 12:26:29 | 00,000,648 | ---- | M] () -- C:\DOCUME~1\Michael\Desktop\wlkbuddy.lnk
[2009/03/31 12:26:01 | 00,763,863 | ---- | M] () -- C:\DOCUME~1\Michael\My Documents\install.exe
[2009/03/31 09:56:11 | 00,124,464 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/03/31 09:56:11 | 00,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2009/03/31 09:56:11 | 00,007,386 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/03/31 09:56:11 | 00,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/03/31 09:56:04 | 00,001,909 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Norton 360.LNK
[2009/03/31 09:56:03 | 00,310,320 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.sys
[2009/03/31 09:56:03 | 00,307,760 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.sys
[2009/03/31 09:56:03 | 00,217,392 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symtdi.sys
[2009/03/31 09:56:03 | 00,089,776 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symfw.sys
[2009/03/31 09:56:03 | 00,043,696 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.sys
[2009/03/31 09:56:03 | 00,039,984 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symndisv.sys
[2009/03/31 09:56:03 | 00,037,296 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symndis.sys
[2009/03/31 09:56:03 | 00,036,400 | R--- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SymIM.sys
[2009/03/31 09:56:03 | 00,034,736 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symids.sys
[2009/03/31 09:56:02 | 00,482,352 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\cchpx86.sys
[2009/03/31 09:56:02 | 00,258,608 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.sys
[2009/03/31 09:55:46 | 00,003,373 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.inf
[2009/03/31 09:55:46 | 00,001,753 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\ccHPx86.inf
[2009/03/31 09:55:46 | 00,001,528 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymNet.inf
[2009/03/31 09:55:46 | 00,001,389 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.inf
[2009/03/31 09:55:46 | 00,001,383 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.inf
[2009/03/31 09:55:46 | 00,000,640 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.inf
[2009/03/31 09:55:46 | 00,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\isolate.ini
[2009/03/31 09:55:36 | 00,009,423 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymNet.cat
[2009/03/31 09:55:36 | 00,007,410 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.cat
[2009/03/31 09:55:36 | 00,007,372 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.cat
[2009/03/31 09:55:36 | 00,007,364 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.CAT
[2009/03/31 09:55:36 | 00,007,355 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.cat
[2009/03/31 09:55:36 | 00,007,347 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\ccHPx86.cat
[2009/03/31 09:55:16 | 74,949,864 | ---- | M] (Symantec Corporation) -- C:\DOCUME~1\Michael\My Documents\N360S300EN.exe
[2009/03/31 09:08:34 | 00,155,648 | ---- | M] (Mozilla Foundation) -- C:\WINDOWS\atefidel.dll
[2009/03/31 08:56:19 | 00,042,496 | ---- | M] (Johnson-Grace Company) -- C:\WINDOWS\Ctozovilo.dll
[2009/03/29 05:18:48 | 00,000,078 | -HS- | M] () -- C:\DOCUME~1\Michael\My Documents\desktop.ini
[2009/03/29 05:16:03 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/03/29 03:29:28 | 00,004,608 | ---- | M] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/29 03:08:03 | 00,000,786 | ---- | M] () -- C:\DOCUME~1\Michael\Desktop\Windows Media Player.lnk
[2009/03/29 02:57:30 | 00,098,256 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/29 02:10:04 | 00,015,360 | ---- | M] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/28 18:42:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2009/03/28 12:09:07 | 00,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/03/26 16:49:56 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/26 16:49:50 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/26 12:32:46 | 00,001,782 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Age of Mythology - The Titans Expansion.lnk
[2009/03/25 13:54:57 | 00,520,192 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\System32\Beautiful Katamari.scr
[2009/03/21 15:35:09 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/21 14:39:25 | 00,001,773 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Age of Mythology.lnk
[2009/03/21 12:41:51 | 00,000,000 | ---- | M] () -- C:\WINDOWS\ativpsrm.bin
[2009/03/17 13:56:58 | 00,002,673 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Sony Ericsson PC Suite.lnk
[2009/03/17 08:53:50 | 00,001,604 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\QuickTime Player.lnk
[2009/03/17 08:53:14 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/03/17 08:53:14 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2009/03/08 17:15:47 | 00,000,906 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Mystery P.I. - The Lottery Ticket.lnk
[2009/03/08 15:22:56 | 00,439,376 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/08 15:22:56 | 00,380,350 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/03/08 15:22:56 | 00,052,764 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/03/08 15:21:08 | 00,000,790 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\3 MobileBroadband.lnk
[2009/03/07 20:23:56 | 00,001,857 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\MSN Installer.lnk
[2009/03/07 17:32:48 | 00,002,007 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Adobe Photoshop Album Starter Edition 3.0.lnk
[2009/03/07 17:32:16 | 00,001,740 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Adobe Reader 7.0.lnk
[2009/03/07 17:10:48 | 00,001,589 | ---- | M] () -- C:\DOCUME~1\Michael\Desktop\The Puzzle Collection.lnk
[2009/03/07 17:10:16 | 00,000,882 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Acrobat Reader 5.1.lnk
[2009/03/07 17:05:40 | 00,000,856 | ---- | M] () -- C:\DOCUME~1\Michael\Desktop\MahJongg.LNK
[2009/03/07 17:03:33 | 00,000,036 | ---- | M] () -- C:\WINDOWS\Tiny_Run.ini
[2009/03/07 17:01:50 | 00,001,801 | ---- | M] () -- C:\DOCUME~1\Michael\Desktop\Age of Empires.lnk
[2009/03/07 16:48:18 | 00,001,909 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\RollerCoaster Tycoon 2 Triple Thrill Pack.lnk
[2009/03/07 16:48:13 | 00,225,280 | ---- | M] (Leader Technologies) -- C:\Documents and Settings\Michael\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
[2009/03/07 13:20:24 | 00,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
[2009/03/07 13:17:22 | 00,000,263 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2009/03/06 16:45:06 | 00,130,424 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ABE89FFE
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3064D21D
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:37994DBE
< End of report >
OTListIt Extras
-----------------
OTListIt Extras logfile created on: 4/1/2009 7:46:14 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.8.0 Folder = C:\Documents and Settings\Michael\Desktop\Virus
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1021.58 Mb Total Physical Memory | 569.11 Mb Available Physical Memory | 55.71% Memory free
2.39 Gb Paging File | 1.82 Gb Available in Paging File | 76.18% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 63.82 Gb Free Space | 85.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 23.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SNUGGLEGLOOM
Current User Name: Michael
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{162B71B8-8464-4680-A086-601D555B331D}" = Apple Mobile Device Support
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2222B364-0854-4265-B32E-A142DB9DC7BB}" = Intel® PRO Network Connections 11.2.0.69
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 13
"{2EA45803-BEB7-46C4-9ADC-46A5F9E7BB77}" = GEAR driver installer for x86 and x64
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4C5D15D2-5351-4F05-A96E-56C20554F977}" = RollerCoaster Tycoon 2 Triple Thrill Pack
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{C26B06A9-27BB-45B0-9873-9C623EC2BA38}" = iTunes
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD35616B-ECAE-4D48-8F3A-677035EFB26F}" = The Puzzle Collection
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E63E34A7-E552-412B-9E40-FD6FC5227ABA}" = Uniblue RegistryBooster 2009
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FC906D5C-91F9-4DA4-A765-6DCBB669F317}" = Sony Ericsson PC Suite
"{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}" = Disc2Phone
"3 MobileBroadband" = 3 MobileBroadband
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"Age of Empires" = Microsoft Age of Empires
"Age of Mythology 1.0" = Age of Mythology
"Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion
"ATI Display Driver" = ATI Display Driver
"Beautiful Katamari" = Beautiful Katamari Screen Saver
"BFGC" = Big Fish Games Client
"Classic Games" = Classic Games
"ERUNT_is1" = ERUNT 1.1j
"GamesBar" = GamesBar 2.0.1.12
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSNINST" = MSN
"Mystery P.I. - The Lottery Ticket 1.0.0.5" = Mystery P.I. - The Lottery Ticket 1.0.0.5
"N360" = Norton 360
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Connections Drivers
"Registry Mechanic_is1" = Registry Mechanic 8.0
"Special Agent P. C. Secure1.3.01" = Special Agent P. C. Secure
"Spyware Doctor" = Spyware Doctor 6.0
"Uniblue RegistryBooster 2009" = Uniblue RegistryBooster 2009
"XoftSpySE" = XoftSpySE
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/30/2009 6:11:03 PM | Computer Name = SNUGGLEGLOOM | Source = ESENT | ID = 490
Description = wuauclt (1724) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/30/2009 6:11:13 PM | Computer Name = SNUGGLEGLOOM | Source = ESENT | ID = 490
Description = wuauclt (1724) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/30/2009 6:11:23 PM | Computer Name = SNUGGLEGLOOM | Source = ESENT | ID = 490
Description = wuauclt (3528) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/30/2009 6:11:33 PM | Computer Name = SNUGGLEGLOOM | Source = ESENT | ID = 490
Description = wuauclt (3528) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/30/2009 6:11:44 PM | Computer Name = SNUGGLEGLOOM | Source = ESENT | ID = 490
Description = wuauclt (3584) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/30/2009 6:11:54 PM | Computer Name = SNUGGLEGLOOM | Source = ESENT | ID = 490
Description = wuauclt (3584) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/30/2009 6:19:10 PM | Computer Name = SNUGGLEGLOOM | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.
Error - 3/30/2009 6:46:23 PM | Computer Name = SNUGGLEGLOOM | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x00011d69.
Error - 3/30/2009 6:46:30 PM | Computer Name = SNUGGLEGLOOM | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.
Error - 3/30/2009 8:39:54 PM | Computer Name = SNUGGLEGLOOM | Source = Application Error | ID = 1000
Description = Faulting application ccSvcHst.exe, version 108.1.0.24, faulting module
unknown, version 0.0.0.0, fault address 0x10031e39.
[ System Events ]
Error - 3/23/2009 12:01:43 AM | Computer Name = SNUGGLEGLOOM | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.
Error - 3/23/2009 12:03:34 AM | Computer Name = SNUGGLEGLOOM | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.
Error - 3/23/2009 12:05:11 AM | Computer Name = SNUGGLEGLOOM | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.
Error - 3/23/2009 12:09:57 AM | Computer Name = SNUGGLEGLOOM | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.
Error - 3/25/2009 4:07:30 AM | Computer Name = SNUGGLEGLOOM | Source = Srv | ID = 2006
Description = The server received an incorrectly formatted request from \\115.130.32.146.
Error - 3/25/2009 7:38:46 AM | Computer Name = SNUGGLEGLOOM | Source = Srv | ID = 2006
Description = The server received an incorrectly formatted request from \\115.130.40.93.
Error - 3/26/2009 9:27:37 AM | Computer Name = SNUGGLEGLOOM | Source = Srv | ID = 2006
Description = The server received an incorrectly formatted request from \\115.130.12.146.
Error - 3/27/2009 7:42:23 AM | Computer Name = SNUGGLEGLOOM | Source = Srv | ID = 2006
Description = The server received an incorrectly formatted request from \\115.130.15.223.
Error - 3/27/2009 8:34:03 AM | Computer Name = SNUGGLEGLOOM | Source = Srv | ID = 2006
Description = The server received an incorrectly formatted request from \\115.130.27.214.
Error - 3/28/2009 1:46:40 AM | Computer Name = SNUGGLEGLOOM | Source = Srv | ID = 2006
Description = The server received an incorrectly formatted request from \\115.130.43.32.
< End of report >