Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:08:51 PM, on 4/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ign.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [DT HPW] "C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe" -startup_folder
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [Twain] C:\Program Files\Twain\Twain.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: MEMonitor.lnk.lnk = C:\Program Files\Sprint music manager\MEMonitor.exe
O4 - Startup: PowerReg Scheduler V3.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Search - ?p=ZJxdm128YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplane...C_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1005.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemreq.../sysreqlab2.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1152909381453
O16 - DPF: {A364AF35-0CDF-41E8-8F3B-E0E55E15EBA1} (Zenturi Active Programs Control) - http://www.programch...m/dll/nixon.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 9526 bytes
and the virtumondobegone log.
[04/26/2008, 12:55:04] - VirtumundoBeGone v1.5 ( "C:\Downloads\VirtumundoBeGone.exe" )
[04/26/2008, 12:55:21] - Detected System Information:
[04/26/2008, 12:55:21] - Windows Version: 5.1.2600, Service Pack 2
[04/26/2008, 12:55:21] - Current Username: Owner (Admin)
[04/26/2008, 12:55:21] - Windows is in NORMAL mode.
[04/26/2008, 12:55:21] - Searching for Browser Helper Objects:
[04/26/2008, 12:55:21] - BHO 1: {08EEDB03-6F99-4924-B5F6-BAEFD1E850E2} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - Checking for HKLM\...\Winlogon\Notify\vtUkllmk
[04/26/2008, 12:55:21] - Key not found: HKLM\...\Winlogon\Notify\vtUkllmk, continuing.
[04/26/2008, 12:55:21] - BHO 2: {0CC0022A-2FB3-4F16-A4A3-07D542F4684A} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - No filename found. Continuing.
[04/26/2008, 12:55:21] - BHO 3: {15421B84-3488-49A7-AD18-CBF84A3EFAF6} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - No filename found. Continuing.
[04/26/2008, 12:55:21] - BHO 4: {20009189-C355-4439-BE70-AC9D3BAFC2D4} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - Checking for HKLM\...\Winlogon\Notify\qoMdEuUK
[04/26/2008, 12:55:21] - Key not found: HKLM\...\Winlogon\Notify\qoMdEuUK, continuing.
[04/26/2008, 12:55:21] - BHO 5: {30E9B0AE-C088-43AA-BF22-91D84126B5BB} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - Checking for HKLM\...\Winlogon\Notify\pmnlmnND
[04/26/2008, 12:55:21] - Key not found: HKLM\...\Winlogon\Notify\pmnlmnND, continuing.
[04/26/2008, 12:55:21] - BHO 6: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (BitComet Helper)
[04/26/2008, 12:55:21] - BHO 7: {4180BD5F-CD9F-4C87-9825-A27B839235EB} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - No filename found. Continuing.
[04/26/2008, 12:55:21] - BHO 8: {44B99BFA-AD0B-495F-B64F-D762D96451AA} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - No filename found. Continuing.
[04/26/2008, 12:55:21] - BHO 9: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[04/26/2008, 12:55:21] - BHO 10: {549B5CA7-4A86-11D7-A4DF-000874180BB3} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - No filename found. Continuing.
[04/26/2008, 12:55:21] - BHO 11: {6A68C21C-8144-44AE-B071-6A47C7ACD650} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - Checking for HKLM\...\Winlogon\Notify\pmnkkKaA
[04/26/2008, 12:55:21] - Key not found: HKLM\...\Winlogon\Notify\pmnkkKaA, continuing.
[04/26/2008, 12:55:21] - BHO 12: {801B1EE4-6C7D-4E6B-823C-462214EFD291} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - Checking for HKLM\...\Winlogon\Notify\qoMDSJcd
[04/26/2008, 12:55:21] - Key not found: HKLM\...\Winlogon\Notify\qoMDSJcd, continuing.
[04/26/2008, 12:55:21] - BHO 13: {A22AB9FA-FC36-4ED5-91D9-435E02EAC345} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - Checking for HKLM\...\Winlogon\Notify\ssqoonMe
[04/26/2008, 12:55:21] - Key not found: HKLM\...\Winlogon\Notify\ssqoonMe, continuing.
[04/26/2008, 12:55:21] - BHO 14: {B02C5D38-E5A1-47DF-935C-67808783179A} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - Checking for HKLM\...\Winlogon\Notify\byXOiGXp
[04/26/2008, 12:55:21] - Key not found: HKLM\...\Winlogon\Notify\byXOiGXp, continuing.
[04/26/2008, 12:55:21] - BHO 15: {c50df854-a4ac-4dcd-87b7-33228fa1f813} ()
[04/26/2008, 12:55:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:21] - Checking for HKLM\...\Winlogon\Notify\utcdobea
[04/26/2008, 12:55:21] - Key not found: HKLM\...\Winlogon\Notify\utcdobea, continuing.
[04/26/2008, 12:55:21] - BHO 16: {E147205A-E12F-457B-9AEC-6696977532D6} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\jkkiIBuu
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\jkkiIBuu, continuing.
[04/26/2008, 12:55:22] - BHO 17: {F50B3F5E-856E-4757-9BB1-B35D46CA7719} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\urqQjkhF
[04/26/2008, 12:55:22] - Found: HKLM\...\Winlogon\Notify\urqQjkhF - This is probably Virtumundo.
[04/26/2008, 12:55:22] - Assigning {F50B3F5E-856E-4757-9BB1-B35D46CA7719} MSEvents Object
[04/26/2008, 12:55:22] - BHO list has been changed! Starting over...
[04/26/2008, 12:55:22] - BHO 1: {08EEDB03-6F99-4924-B5F6-BAEFD1E850E2} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\vtUkllmk
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\vtUkllmk, continuing.
[04/26/2008, 12:55:22] - BHO 2: {0CC0022A-2FB3-4F16-A4A3-07D542F4684A} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - No filename found. Continuing.
[04/26/2008, 12:55:22] - BHO 3: {15421B84-3488-49A7-AD18-CBF84A3EFAF6} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - No filename found. Continuing.
[04/26/2008, 12:55:22] - BHO 4: {20009189-C355-4439-BE70-AC9D3BAFC2D4} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\qoMdEuUK
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\qoMdEuUK, continuing.
[04/26/2008, 12:55:22] - BHO 5: {30E9B0AE-C088-43AA-BF22-91D84126B5BB} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\pmnlmnND
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\pmnlmnND, continuing.
[04/26/2008, 12:55:22] - BHO 6: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (BitComet Helper)
[04/26/2008, 12:55:22] - BHO 7: {4180BD5F-CD9F-4C87-9825-A27B839235EB} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - No filename found. Continuing.
[04/26/2008, 12:55:22] - BHO 8: {44B99BFA-AD0B-495F-B64F-D762D96451AA} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - No filename found. Continuing.
[04/26/2008, 12:55:22] - BHO 9: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[04/26/2008, 12:55:22] - BHO 10: {549B5CA7-4A86-11D7-A4DF-000874180BB3} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - No filename found. Continuing.
[04/26/2008, 12:55:22] - BHO 11: {6A68C21C-8144-44AE-B071-6A47C7ACD650} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\pmnkkKaA
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\pmnkkKaA, continuing.
[04/26/2008, 12:55:22] - BHO 12: {801B1EE4-6C7D-4E6B-823C-462214EFD291} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\qoMDSJcd
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\qoMDSJcd, continuing.
[04/26/2008, 12:55:22] - BHO 13: {A22AB9FA-FC36-4ED5-91D9-435E02EAC345} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\ssqoonMe
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\ssqoonMe, continuing.
[04/26/2008, 12:55:22] - BHO 14: {B02C5D38-E5A1-47DF-935C-67808783179A} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\byXOiGXp
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\byXOiGXp, continuing.
[04/26/2008, 12:55:22] - BHO 15: {c50df854-a4ac-4dcd-87b7-33228fa1f813} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\utcdobea
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\utcdobea, continuing.
[04/26/2008, 12:55:22] - BHO 16: {E147205A-E12F-457B-9AEC-6696977532D6} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - Checking for HKLM\...\Winlogon\Notify\jkkiIBuu
[04/26/2008, 12:55:22] - Key not found: HKLM\...\Winlogon\Notify\jkkiIBuu, continuing.
[04/26/2008, 12:55:22] - BHO 17: {F50B3F5E-856E-4757-9BB1-B35D46CA7719} (MSEvents Object)
[04/26/2008, 12:55:22] - ALERT: Found MSEvents Object!
[04/26/2008, 12:55:22] - BHO 18: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} ()
[04/26/2008, 12:55:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:22] - No filename found. Continuing.
[04/26/2008, 12:55:22] - Finished Searching Browser Helper Objects
[04/26/2008, 12:55:22] - *** Detected MSEvents Object
[04/26/2008, 12:55:22] - Trying to remove MSEvents Object...
[04/26/2008, 12:55:23] - Terminating Process: IEXPLORE.EXE
[04/26/2008, 12:55:23] - Terminating Process: RUNDLL32.EXE
[04/26/2008, 12:55:23] - Disabling Automatic Shell Restart
[04/26/2008, 12:55:23] - Terminating Process: EXPLORER.EXE
[04/26/2008, 12:55:24] - Suspending the NT Session Manager System Service
[04/26/2008, 12:55:24] - Terminating Windows NT Logon/Logoff Manager
[04/26/2008, 12:55:24] - Re-enabling Automatic Shell Restart
[04/26/2008, 12:55:24] - File to disable: C:\WINDOWS\system32\urqQjkhF.dll
[04/26/2008, 12:55:24] - Renaming C:\WINDOWS\system32\urqQjkhF.dll -> C:\WINDOWS\system32\urqQjkhF.dll.vir
[04/26/2008, 12:55:24] - File successfully renamed!
[04/26/2008, 12:55:24] - Removing HKLM\...\Browser Helper Objects\{F50B3F5E-856E-4757-9BB1-B35D46CA7719}
[04/26/2008, 12:55:24] - Removing HKCR\CLSID\{F50B3F5E-856E-4757-9BB1-B35D46CA7719}
[04/26/2008, 12:55:24] - Adding Kill Bit for ActiveX for GUID: {F50B3F5E-856E-4757-9BB1-B35D46CA7719}
[04/26/2008, 12:55:24] - Deleting ATLEvents/MSEvents Registry entries
[04/26/2008, 12:55:24] - Removing HKLM\...\Winlogon\Notify\urqQjkhF
[04/26/2008, 12:55:24] - Searching for Browser Helper Objects:
[04/26/2008, 12:55:24] - BHO 1: {08EEDB03-6F99-4924-B5F6-BAEFD1E850E2} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - Checking for HKLM\...\Winlogon\Notify\vtUkllmk
[04/26/2008, 12:55:24] - Key not found: HKLM\...\Winlogon\Notify\vtUkllmk, continuing.
[04/26/2008, 12:55:24] - BHO 2: {0CC0022A-2FB3-4F16-A4A3-07D542F4684A} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - No filename found. Continuing.
[04/26/2008, 12:55:24] - BHO 3: {15421B84-3488-49A7-AD18-CBF84A3EFAF6} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - No filename found. Continuing.
[04/26/2008, 12:55:24] - BHO 4: {20009189-C355-4439-BE70-AC9D3BAFC2D4} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - Checking for HKLM\...\Winlogon\Notify\qoMdEuUK
[04/26/2008, 12:55:24] - Key not found: HKLM\...\Winlogon\Notify\qoMdEuUK, continuing.
[04/26/2008, 12:55:24] - BHO 5: {30E9B0AE-C088-43AA-BF22-91D84126B5BB} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - Checking for HKLM\...\Winlogon\Notify\pmnlmnND
[04/26/2008, 12:55:24] - Key not found: HKLM\...\Winlogon\Notify\pmnlmnND, continuing.
[04/26/2008, 12:55:24] - BHO 6: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (BitComet Helper)
[04/26/2008, 12:55:24] - BHO 7: {4180BD5F-CD9F-4C87-9825-A27B839235EB} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - No filename found. Continuing.
[04/26/2008, 12:55:24] - BHO 8: {44B99BFA-AD0B-495F-B64F-D762D96451AA} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - No filename found. Continuing.
[04/26/2008, 12:55:24] - BHO 9: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[04/26/2008, 12:55:24] - BHO 10: {549B5CA7-4A86-11D7-A4DF-000874180BB3} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - No filename found. Continuing.
[04/26/2008, 12:55:24] - BHO 11: {6A68C21C-8144-44AE-B071-6A47C7ACD650} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - Checking for HKLM\...\Winlogon\Notify\pmnkkKaA
[04/26/2008, 12:55:24] - Key not found: HKLM\...\Winlogon\Notify\pmnkkKaA, continuing.
[04/26/2008, 12:55:24] - BHO 12: {801B1EE4-6C7D-4E6B-823C-462214EFD291} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - Checking for HKLM\...\Winlogon\Notify\qoMDSJcd
[04/26/2008, 12:55:24] - Key not found: HKLM\...\Winlogon\Notify\qoMDSJcd, continuing.
[04/26/2008, 12:55:24] - BHO 13: {A22AB9FA-FC36-4ED5-91D9-435E02EAC345} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - Checking for HKLM\...\Winlogon\Notify\ssqoonMe
[04/26/2008, 12:55:24] - Key not found: HKLM\...\Winlogon\Notify\ssqoonMe, continuing.
[04/26/2008, 12:55:24] - BHO 14: {B02C5D38-E5A1-47DF-935C-67808783179A} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - Checking for HKLM\...\Winlogon\Notify\byXOiGXp
[04/26/2008, 12:55:24] - Key not found: HKLM\...\Winlogon\Notify\byXOiGXp, continuing.
[04/26/2008, 12:55:24] - BHO 15: {c50df854-a4ac-4dcd-87b7-33228fa1f813} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - Checking for HKLM\...\Winlogon\Notify\utcdobea
[04/26/2008, 12:55:24] - Key not found: HKLM\...\Winlogon\Notify\utcdobea, continuing.
[04/26/2008, 12:55:24] - BHO 16: {E147205A-E12F-457B-9AEC-6696977532D6} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - Checking for HKLM\...\Winlogon\Notify\jkkiIBuu
[04/26/2008, 12:55:24] - Key not found: HKLM\...\Winlogon\Notify\jkkiIBuu, continuing.
[04/26/2008, 12:55:24] - BHO 17: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} ()
[04/26/2008, 12:55:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 12:55:24] - No filename found. Continuing.
[04/26/2008, 12:55:24] - Finished Searching Browser Helper Objects
[04/26/2008, 12:55:24] - Finishing up...
[04/26/2008, 12:55:24] - A restart is needed.
[04/26/2008, 12:55:30] - Attempting to Restart via STOP error (Blue Screen!)
[04/26/2008, 13:03:31] - VirtumundoBeGone v1.5 ( "C:\Downloads\VirtumundoBeGone.exe" )
[04/26/2008, 13:03:33] - Detected System Information:
[04/26/2008, 13:03:33] - Windows Version: 5.1.2600, Service Pack 2
[04/26/2008, 13:03:34] - Current Username: Administrator (Admin)
[04/26/2008, 13:03:34] - Windows is in SAFE mode with Networking.
[04/26/2008, 13:03:34] - Searching for Browser Helper Objects:
[04/26/2008, 13:03:34] - BHO 1: {0CC0022A-2FB3-4F16-A4A3-07D542F4684A} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - No filename found. Continuing.
[04/26/2008, 13:03:34] - BHO 2: {15421B84-3488-49A7-AD18-CBF84A3EFAF6} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - No filename found. Continuing.
[04/26/2008, 13:03:34] - BHO 3: {20009189-C355-4439-BE70-AC9D3BAFC2D4} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - Checking for HKLM\...\Winlogon\Notify\qoMdEuUK
[04/26/2008, 13:03:34] - Key not found: HKLM\...\Winlogon\Notify\qoMdEuUK, continuing.
[04/26/2008, 13:03:34] - BHO 4: {30E9B0AE-C088-43AA-BF22-91D84126B5BB} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - Checking for HKLM\...\Winlogon\Notify\pmnlmnND
[04/26/2008, 13:03:34] - Key not found: HKLM\...\Winlogon\Notify\pmnlmnND, continuing.
[04/26/2008, 13:03:34] - BHO 5: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (BitComet Helper)
[04/26/2008, 13:03:34] - BHO 6: {4180BD5F-CD9F-4C87-9825-A27B839235EB} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - No filename found. Continuing.
[04/26/2008, 13:03:34] - BHO 7: {44B99BFA-AD0B-495F-B64F-D762D96451AA} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - No filename found. Continuing.
[04/26/2008, 13:03:34] - BHO 8: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[04/26/2008, 13:03:34] - BHO 9: {549B5CA7-4A86-11D7-A4DF-000874180BB3} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - No filename found. Continuing.
[04/26/2008, 13:03:34] - BHO 10: {6A68C21C-8144-44AE-B071-6A47C7ACD650} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - Checking for HKLM\...\Winlogon\Notify\pmnkkKaA
[04/26/2008, 13:03:34] - Key not found: HKLM\...\Winlogon\Notify\pmnkkKaA, continuing.
[04/26/2008, 13:03:34] - BHO 11: {801B1EE4-6C7D-4E6B-823C-462214EFD291} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - Checking for HKLM\...\Winlogon\Notify\qoMDSJcd
[04/26/2008, 13:03:34] - Key not found: HKLM\...\Winlogon\Notify\qoMDSJcd, continuing.
[04/26/2008, 13:03:34] - BHO 12: {907DA83F-6E32-4EE1-B6A2-8E22D89FE93D} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - Checking for HKLM\...\Winlogon\Notify\vtUkllmk
[04/26/2008, 13:03:34] - Key not found: HKLM\...\Winlogon\Notify\vtUkllmk, continuing.
[04/26/2008, 13:03:34] - BHO 13: {A22AB9FA-FC36-4ED5-91D9-435E02EAC345} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - Checking for HKLM\...\Winlogon\Notify\ssqoonMe
[04/26/2008, 13:03:34] - Key not found: HKLM\...\Winlogon\Notify\ssqoonMe, continuing.
[04/26/2008, 13:03:34] - BHO 14: {B02C5D38-E5A1-47DF-935C-67808783179A} ()
[04/26/2008, 13:03:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:34] - Checking for HKLM\...\Winlogon\Notify\byXOiGXp
[04/26/2008, 13:03:35] - Key not found: HKLM\...\Winlogon\Notify\byXOiGXp, continuing.
[04/26/2008, 13:03:35] - BHO 15: {c50df854-a4ac-4dcd-87b7-33228fa1f813} ()
[04/26/2008, 13:03:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:35] - Checking for HKLM\...\Winlogon\Notify\utcdobea
[04/26/2008, 13:03:35] - Key not found: HKLM\...\Winlogon\Notify\utcdobea, continuing.
[04/26/2008, 13:03:35] - BHO 16: {E147205A-E12F-457B-9AEC-6696977532D6} ()
[04/26/2008, 13:03:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:35] - Checking for HKLM\...\Winlogon\Notify\jkkiIBuu
[04/26/2008, 13:03:35] - Key not found: HKLM\...\Winlogon\Notify\jkkiIBuu, continuing.
[04/26/2008, 13:03:35] - BHO 17: {F50B3F5E-856E-4757-9BB1-B35D46CA7719} ()
[04/26/2008, 13:03:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:35] - No filename found. Continuing.
[04/26/2008, 13:03:35] - BHO 18: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} ()
[04/26/2008, 13:03:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:03:35] - No filename found. Continuing.
[04/26/2008, 13:03:35] - Finished Searching Browser Helper Objects
[04/26/2008, 13:03:35] - Finishing up...
[04/26/2008, 13:03:35] - Nothing found! Exiting...
[04/26/2008, 13:05:35] - VirtumundoBeGone v1.5 ( "C:\Downloads\VirtumundoBeGone.exe" )
[04/26/2008, 13:05:36] - Detected System Information:
[04/26/2008, 13:05:36] - Windows Version: 5.1.2600, Service Pack 2
[04/26/2008, 13:05:36] - Current Username: Administrator (Admin)
[04/26/2008, 13:05:36] - Windows is in SAFE mode with Networking.
[04/26/2008, 13:05:36] - Searching for Browser Helper Objects:
[04/26/2008, 13:05:36] - BHO 1: {0CC0022A-2FB3-4F16-A4A3-07D542F4684A} ()
[04/26/2008, 13:05:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:36] - No filename found. Continuing.
[04/26/2008, 13:05:36] - BHO 2: {15421B84-3488-49A7-AD18-CBF84A3EFAF6} ()
[04/26/2008, 13:05:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:36] - No filename found. Continuing.
[04/26/2008, 13:05:36] - BHO 3: {20009189-C355-4439-BE70-AC9D3BAFC2D4} ()
[04/26/2008, 13:05:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:36] - Checking for HKLM\...\Winlogon\Notify\qoMdEuUK
[04/26/2008, 13:05:36] - Key not found: HKLM\...\Winlogon\Notify\qoMdEuUK, continuing.
[04/26/2008, 13:05:36] - BHO 4: {30E9B0AE-C088-43AA-BF22-91D84126B5BB} ()
[04/26/2008, 13:05:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:36] - Checking for HKLM\...\Winlogon\Notify\pmnlmnND
[04/26/2008, 13:05:36] - Key not found: HKLM\...\Winlogon\Notify\pmnlmnND, continuing.
[04/26/2008, 13:05:36] - BHO 5: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (BitComet Helper)
[04/26/2008, 13:05:36] - BHO 6: {4180BD5F-CD9F-4C87-9825-A27B839235EB} ()
[04/26/2008, 13:05:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:36] - No filename found. Continuing.
[04/26/2008, 13:05:36] - BHO 7: {44B99BFA-AD0B-495F-B64F-D762D96451AA} ()
[04/26/2008, 13:05:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:36] - No filename found. Continuing.
[04/26/2008, 13:05:36] - BHO 8: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[04/26/2008, 13:05:36] - BHO 9: {549B5CA7-4A86-11D7-A4DF-000874180BB3} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - No filename found. Continuing.
[04/26/2008, 13:05:37] - BHO 10: {6A68C21C-8144-44AE-B071-6A47C7ACD650} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - Checking for HKLM\...\Winlogon\Notify\pmnkkKaA
[04/26/2008, 13:05:37] - Key not found: HKLM\...\Winlogon\Notify\pmnkkKaA, continuing.
[04/26/2008, 13:05:37] - BHO 11: {801B1EE4-6C7D-4E6B-823C-462214EFD291} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - Checking for HKLM\...\Winlogon\Notify\qoMDSJcd
[04/26/2008, 13:05:37] - Key not found: HKLM\...\Winlogon\Notify\qoMDSJcd, continuing.
[04/26/2008, 13:05:37] - BHO 12: {907DA83F-6E32-4EE1-B6A2-8E22D89FE93D} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - Checking for HKLM\...\Winlogon\Notify\vtUkllmk
[04/26/2008, 13:05:37] - Key not found: HKLM\...\Winlogon\Notify\vtUkllmk, continuing.
[04/26/2008, 13:05:37] - BHO 13: {A22AB9FA-FC36-4ED5-91D9-435E02EAC345} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - Checking for HKLM\...\Winlogon\Notify\ssqoonMe
[04/26/2008, 13:05:37] - Key not found: HKLM\...\Winlogon\Notify\ssqoonMe, continuing.
[04/26/2008, 13:05:37] - BHO 14: {B02C5D38-E5A1-47DF-935C-67808783179A} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - Checking for HKLM\...\Winlogon\Notify\byXOiGXp
[04/26/2008, 13:05:37] - Key not found: HKLM\...\Winlogon\Notify\byXOiGXp, continuing.
[04/26/2008, 13:05:37] - BHO 15: {c50df854-a4ac-4dcd-87b7-33228fa1f813} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - Checking for HKLM\...\Winlogon\Notify\utcdobea
[04/26/2008, 13:05:37] - Key not found: HKLM\...\Winlogon\Notify\utcdobea, continuing.
[04/26/2008, 13:05:37] - BHO 16: {E147205A-E12F-457B-9AEC-6696977532D6} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - Checking for HKLM\...\Winlogon\Notify\jkkiIBuu
[04/26/2008, 13:05:37] - Key not found: HKLM\...\Winlogon\Notify\jkkiIBuu, continuing.
[04/26/2008, 13:05:37] - BHO 17: {F50B3F5E-856E-4757-9BB1-B35D46CA7719} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - No filename found. Continuing.
[04/26/2008, 13:05:37] - BHO 18: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} ()
[04/26/2008, 13:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/26/2008, 13:05:37] - No filename found. Continuing.
[04/26/2008, 13:05:37] - Finished Searching Browser Helper Objects
[04/26/2008, 13:05:37] - Finishing up...
[04/26/2008, 13:05:37] - Nothing found! Exiting...