Thanks for looking at this. In the past I've managed to ferret these things out on my own but since bringing in my sister's HD into my machine as part of a re-OS I've been infected with one of the many things that were plaguing her (including Virtumonde). I also suspect a crack for some Palm sw I was trying out.
As stated above, I have been able to download and install MBAM and other spyware catchers but they won't launch. Google results and Yahoo results redirect to ad pages (or fake pages) and even addresses put directly into the address bar get redirected if related to spyware/malware/virus topics. This site was only accessible by hitting "STOP" before the page fully loads. I have read the Malware Removal Guide (BTW that's a stellar piece of work) but unfortunately I'm clueless when it comes to reading these logs. If someone can identify the problem as one of the beasties listed at the start of the Removal Guide I'll follow the recommended methods there. I'm sure you're all very busy
Your assistance is much appreciated...
Here's ROOTER.TXT
~~~~~~~~~~~~~~~
Microsoft Windows XP Professional (5.1.2600) Service Pack 2
A:\ [Removable] (Total:0 Mo/Free:0 Mo)
C:\ [Fixed] - NTFS - (Total:286173 Mo/Free:1719 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)
H:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
I:\ [Removable] (Total:0 Mo/Free:0 Mo)
X:\ [Fixed] - NTFS - (Total:476938 Mo/Free:2801 Mo)
Mon 04/13/2009| 1:38
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
---------- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
---------- C:\WINDOWS\system32\nvsvc32.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
---------- C:\WINDOWS\system32\wdfmgr.exe
---------- C:\Program Files\Canon\CAL\CALMAIN.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\WINDOWS\SOUNDMAN.EXE
---------- C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
---------- C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
---------- C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
---------- C:\Program Files\Java\jre6\bin\jusched.exe
---------- C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
---------- C:\Program Files\Nero\Nero 7\InCD\InCD.exe
---------- C:\WINDOWS\system32\RUNDLL32.EXE
---------- C:\WINDOWS\system32\dla\tfswctrl.exe
---------- C:\Program Files\Bret Taylor\Stickies\Stickies.exe
---------- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
---------- C:\Program Files\Palm\Hotsync.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\Java\jre6\bin\jucheck.exe
---------- C:\Program Files\Mozilla Firefox\firefox.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.227,85.255.112.166
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.227,85.255.112.166
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.227,85.255.112.166
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{ACDA1449-1CD4-4CB2-BB84-6B005881B2DC}]
NameServer REG_SZ 85.255.112.227,85.255.112.166
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{ACDA1449-1CD4-4CB2-BB84-6B005881B2DC}]
NameServer REG_SZ 85.255.112.227,85.255.112.166
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{ACDA1449-1CD4-4CB2-BB84-6B005881B2DC}]
NameServer REG_SZ 85.255.112.227,85.255.112.166
==> WAREOUT <==
----------------------\\ ROOTKIT !!
----------------------\\ Cracks & Keygens..
C:\DOCUME~1\Boris\Application Data\uTorrent\resco.explorer.palm.os.5.02.keygen.rar.torrent
C:\DOCUME~1\Boris\Desktop\All (15) Popcap Games With Keygens 2004.05.04.rar
C:\DOCUME~1\Boris\Desktop\Downers\Card Recovery + Crack.zip
C:\DOCUME~1\Boris\Desktop\Palm\resco.explorer.palm.os.5.02.keygen.rar
C:\DOCUME~1\Boris\Desktop\Syncbox\Astraware.Hexic.v1.02.XScale.WM2003.WM05.Cracked-COREPDA.rar
C:\DOCUME~1\Boris\Desktop\Syncbox\Bzzz crack-arm.exe
C:\DOCUME~1\Boris\Desktop\Torrent Downers\Corel WinDVD 9\Corel WinDVD 9\Keygen.exe
1 - "C:\Rooter$\Rooter_1.txt" - Mon 04/13/2009| 1:39
----------------------\\ Scan completed at 1:39
OTListIt logfile created on: 4/13/2009 1:42:25 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Boris\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 449.43 Mb Available Physical Memory | 43.91% Memory free
2.40 Gb Paging File | 2.02 Gb Available in Paging File | 84.15% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.47 Gb Total Space | 17.68 Gb Free Space | 6.33% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 465.76 Gb Total Space | 390.74 Gb Free Space | 83.89% Space Free | Partition Type: NTFS
Computer Name: CENTRAAL
Current User Name: Boris
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe (NVIDIA Corporation)
PRC - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\Bret Taylor\Stickies\Stickies.exe (Bret Taylor)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Boris\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (CCALib8 [Auto | Running]) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DefWatch [Auto | Running]) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (InCDsrv [Auto | Running]) -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NMIndexingService [On_Demand | Stopped]) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (Norton AntiVirus Server [Auto | Running]) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (UleadBurningHelper [Auto | Running]) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (61883 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\61883.sys (Microsoft Corporation)
DRV - (ALCXWDM [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (Avc [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\avc.sys (Microsoft Corporation)
DRV - (axwhisky [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\axwhisky.sys ( )
DRV - (axwskbus [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\axwskbus.sys ( )
DRV - (BrScnUsb [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (Cinemsup [System | Running]) -- C:\WINDOWS\System32\drivers\cinemsup.sys (Sonic Solutions)
DRV - (drvmcdb [Boot | Running]) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) -- C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (InCDfs [Disabled | Running]) -- C:\WINDOWS\system32\drivers\InCDFs.sys (Nero AG)
DRV - (InCDPass [System | Running]) -- C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (incdrm [System | Running]) -- C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (MSDV [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\msdv.sys (Microsoft Corporation)
DRV - (ms_mpu401 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ASACPI.sys ()
DRV - (NAVAP [On_Demand | Running]) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navap.sys (Symantec Corporation)
DRV - (NAVAPEL [Auto | Running]) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS (Symantec Corporation)
DRV - (NAVENG [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090410.003\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090410.003\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvax [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (nvnforce [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (PalmUSBD [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (pcouffin [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sscdbhk5 [System | Running]) -- C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) -- C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (SymEvent [On_Demand | Running]) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (tfsnboio [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (usb_rndisx [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\usb8023x.sys (Microsoft Corporation)
DRV - (vcdrom [System | Running]) -- C:\WINDOWS\system32\VCdRom.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.goodsearch.com/"
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/11 23:55:18 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/28 23:02:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/28 23:02:08 | 00,000,000 | ---D | M]
[2008/07/09 19:17:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Boris\Application Data\mozilla\Extensions
[2008/07/09 19:17:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Boris\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/07/09 19:17:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Boris\Application Data\mozilla\Firefox\Profiles\htjz5xmr.default\extensions
[2009/04/09 01:21:21 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/03/28 23:02:08 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/08/05 00:13:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/12/11 23:55:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/03/28 23:02:04 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/28 23:02:04 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/09/27 03:34:33 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/09/27 03:34:33 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/09/27 03:34:33 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/14 09:37:34 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/09/27 03:34:33 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/09/27 03:34:33 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/09/27 03:34:33 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (767 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 q4master.idsoftware.com
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - Reg Error: Key error. File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun (Brother Industries, Ltd.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers File not found
O4 - HKLM..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot (Scansoft, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe (Symantec Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [Stickies] C:\Program Files\Bret Taylor\Stickies\Stickies.exe (Bret Taylor)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Boris\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.co.../sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.co...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.227,85.255.112.166
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{ACDA1449-1CD4-4CB2-BB84-6B005881B2DC}\\NameServer = 85.255.112.227,85.255.112.166
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{327e9c1a-cefe-11dd-b695-0013d4f77916}\Shell\AutoRun\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe
O33 - MountPoints2\{327e9c1a-cefe-11dd-b695-0013d4f77916}\Shell\open\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe
O33 - MountPoints2\{7e994ec2-4da2-11dd-b231-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{7e994ec2-4da2-11dd-b231-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7e994ec2-4da2-11dd-b231-806d6172696f}\Shell\AutoRun\command - "" = D:\ASUSACPI.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[4 C:\WINDOWS\*.tmp files]
[2009/04/13 01:40:11 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\DOCUME~1\Boris\Desktop\OTListIt2.exe
[2009/04/13 01:38:55 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/04/13 01:38:38 | 00,267,612 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Rooter.exe
[2009/04/13 01:36:01 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\DOCUME~1\Boris\Desktop\gooble.exe
[2009/04/13 01:34:07 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/13 01:34:07 | 00,000,696 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/13 01:34:05 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/13 01:34:04 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/13 01:34:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/13 01:33:29 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\DOCUME~1\Boris\Desktop\mbam-setup.exe
[2009/04/13 01:06:10 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\Boris\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/13 01:05:49 | 00,000,611 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\NTREGOPT.lnk
[2009/04/13 01:05:49 | 00,000,592 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\ERUNT.lnk
[2009/04/13 01:05:49 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/04/13 01:05:09 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\DOCUME~1\Boris\Desktop\erunt_setup.exe
[2009/04/13 01:02:42 | 00,021,504 | ---- | C] (Doug Knox) -- C:\DOCUME~1\Boris\Desktop\SysRestorePoint.exe
[2009/04/11 00:00:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/04/10 23:52:46 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009/04/10 21:26:17 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/04/10 21:26:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/10 09:47:32 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\Desktop\Palm
[2009/04/10 09:45:52 | 00,000,000 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Ad-AwareAE.exe
[2009/04/10 09:45:49 | 10,677,120 | ---- | C] (Lavasoft ) -- C:\DOCUME~1\Boris\Desktop\Ad-AwareAE.exe.part
[2009/04/10 09:43:49 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\DOCUME~1\Boris\Desktop\spybotsd162.exe
[2009/04/10 02:05:58 | 00,000,582 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\tdtetris.jad
[2009/04/10 02:00:12 | 00,006,414 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\corrhack.zip
[2009/04/10 01:55:08 | 00,044,616 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\vexed.zip
[2009/04/09 23:00:08 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gxvxcserv.sys
[2009/04/08 01:23:02 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/04/08 00:57:01 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\Desktop\Palm SW
[2009/04/07 22:31:16 | 00,016,640 | R--- | C] (PalmSource, Inc.) -- C:\WINDOWS\System32\drivers\PalmUSBD.sys
[2009/04/07 22:26:41 | 00,001,513 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
[2009/04/07 22:26:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Boris\Application Data\Arcsoft
[2009/04/07 22:26:27 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\My Documents\My Albums
[2009/04/07 22:26:08 | 00,001,478 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Palm Desktop.lnk
[2009/04/07 22:24:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Boris\Application Data\HotSync
[2009/04/07 22:24:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2009/04/07 22:24:21 | 00,000,000 | ---D | C] -- C:\Program Files\Palm
[2009/04/07 22:07:14 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\My Documents\Palm OS Desktop
[2009/04/03 08:09:10 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\Desktop\Rickle
[2009/04/03 07:57:03 | 00,000,384 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Shortcut to amboo.lnk
[2009/03/31 08:04:35 | 00,013,824 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Movie List.xls
[2009/03/27 08:03:36 | 03,702,784 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\cd080802.iso
[2009/03/22 10:35:57 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\Desktop\Nav8Client
[2009/03/18 18:42:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Boris\Local Settings\Application Data\WMTools Downloaded Files
[2009/03/17 21:52:20 | 00,000,000 | ---D | C] -- C:\Program Files\StoneHeads
[2009/03/17 21:52:14 | 00,000,196 | ---- | C] () -- C:\WINDOWS\STONEHDS.INI
[2009/03/14 22:43:29 | 01,138,688 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Memtest86_3.5.iso
[2009/03/11 07:55:20 | 00,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/11/15 00:49:55 | 00,000,316 | ---- | C] () -- C:\WINDOWS\game.ini
[2008/11/09 12:06:04 | 00,000,079 | ---- | C] () -- C:\WINDOWS\SW_Win2000X1.DLL
[2008/11/09 12:05:27 | 00,000,027 | ---- | C] () -- C:\WINDOWS\SW_Win2146X32.DLL
[2008/11/09 11:53:09 | 00,003,774 | ---- | C] () -- C:\WINDOWS\CX_SearchHistory.INI
[2008/11/09 11:53:03 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\CSVSpecialProcessing.dll
[2008/11/09 11:53:03 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\SARzilla.dll
[2008/11/09 11:53:03 | 00,098,304 | ---- | C] () -- C:\WINDOWS\System32\DVM.dll
[2008/11/09 11:53:03 | 00,000,530 | ---- | C] () -- C:\WINDOWS\System32\tx13_ic.ini
[2008/07/24 08:59:00 | 00,000,410 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2008/07/24 08:57:34 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\BROSNMP.DLL
[2008/07/24 08:57:27 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll
[2008/07/24 08:55:52 | 00,027,019 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2008/07/13 21:08:07 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/07/13 11:59:05 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/07/11 00:52:22 | 00,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2008/07/09 14:51:16 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2008/07/09 14:51:13 | 00,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2008/07/09 14:43:53 | 00,000,266 | R--- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
[2008/07/09 14:43:41 | 00,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/07/09 14:43:40 | 00,005,700 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/07/09 14:43:37 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/10/12 23:20:06 | 00,151,417 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2006/02/09 10:06:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/02/09 10:06:00 | 01,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/02/09 10:06:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/02/09 10:06:00 | 00,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/02/09 10:06:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/02/09 10:06:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2004/12/20 22:26:12 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/03 21:07:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004/08/03 21:07:00 | 00,000,573 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/03 21:07:00 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/12/19 02:00:00 | 00,013,387 | ---- | C] () -- C:\WINDOWS\System32\CinemSup.sys
[2003/07/02 17:41:42 | 00,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\axwhisky.sys
[2003/07/02 16:49:52 | 00,124,160 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\axwskbus.sys
[2003/04/26 01:16:00 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
[2002/03/04 10:16:34 | 00,110,592 | R--- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
[1999/01/22 14:46:56 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== Files - Modified Within 30 Days ==========
[2 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/04/13 01:40:11 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\DOCUME~1\Boris\Desktop\OTListIt2.exe
[2009/04/13 01:38:38 | 00,267,612 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\Rooter.exe
[2009/04/13 01:36:01 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\DOCUME~1\Boris\Desktop\gooble.exe
[2009/04/13 01:34:07 | 00,000,696 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/13 01:33:35 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\DOCUME~1\Boris\Desktop\mbam-setup.exe
[2009/04/13 01:06:10 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\Boris\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/13 01:05:49 | 00,000,611 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\NTREGOPT.lnk
[2009/04/13 01:05:49 | 00,000,592 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\ERUNT.lnk
[2009/04/13 01:05:09 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\DOCUME~1\Boris\Desktop\erunt_setup.exe
[2009/04/13 01:02:42 | 00,021,504 | ---- | M] (Doug Knox) -- C:\DOCUME~1\Boris\Desktop\SysRestorePoint.exe
[2009/04/12 23:07:12 | 00,000,312 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2009/04/12 23:07:08 | 00,194,593 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/04/12 23:06:09 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/12 23:06:08 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/12 23:06:07 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/11 00:02:37 | 00,056,320 | ---- | M] () -- C:\Documents and Settings\Boris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/11 00:02:37 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/04/10 09:46:15 | 10,677,120 | ---- | M] (Lavasoft ) -- C:\DOCUME~1\Boris\Desktop\Ad-AwareAE.exe.part
[2009/04/10 09:45:52 | 00,000,000 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\Ad-AwareAE.exe
[2009/04/10 09:44:43 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\DOCUME~1\Boris\Desktop\spybotsd162.exe
[2009/04/10 02:05:58 | 00,000,582 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\tdtetris.jad
[2009/04/10 02:00:12 | 00,006,414 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\corrhack.zip
[2009/04/10 01:55:08 | 00,044,616 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\vexed.zip
[2009/04/09 23:00:08 | 00,035,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gxvxcserv.sys
[2009/04/08 01:10:41 | 00,234,368 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/07 22:34:22 | 00,068,920 | ---- | M] () -- C:\Documents and Settings\Boris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/07 22:26:41 | 00,001,513 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
[2009/04/07 22:26:08 | 00,001,478 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Palm Desktop.lnk
[2009/04/07 22:22:12 | 00,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2009/04/07 21:30:27 | 00,458,340 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/07 21:30:27 | 00,392,296 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/07 21:30:27 | 00,058,596 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/07 21:23:50 | 00,000,573 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/04/07 08:29:25 | 00,000,668 | ---- | M] () -- C:\Documents and Settings\Boris\Application Data\vso_ts_preview.xml
[2009/04/06 15:32:54 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/03 07:57:04 | 00,000,384 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\Shortcut to amboo.lnk
[2009/04/03 07:50:18 | 02,106,246 | -H-- | M] () -- C:\Documents and Settings\Boris\Local Settings\Application Data\IconCache.db
[2009/03/31 08:04:35 | 00,013,824 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\Movie List.xls
[2009/03/17 21:54:12 | 00,000,196 | ---- | M] () -- C:\WINDOWS\STONEHDS.INI
[2009/03/14 01:59:57 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
========== Alternate Data Streams ==========
@Alternate Data Stream - 304 bytes -> C:\DOCUME~1\Boris\Desktop\retrospect.jpg:SummaryInformation
@Alternate Data Stream - 304 bytes -> C:\DOCUME~1\Boris\Desktop\retrospect b.jpg:SummaryInformation
@Alternate Data Stream - 304 bytes -> C:\DOCUME~1\Boris\Desktop\Retropair A.jpg:SummaryInformation
@Alternate Data Stream - 304 bytes -> C:\DOCUME~1\Boris\Desktop\card 004.JPG:SummaryInformation
< End of report >
Here's OTListIT.TXT
~~~~~~~~~~~~~~~
OTListIt logfile created on: 4/13/2009 1:42:25 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Boris\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 449.43 Mb Available Physical Memory | 43.91% Memory free
2.40 Gb Paging File | 2.02 Gb Available in Paging File | 84.15% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.47 Gb Total Space | 17.68 Gb Free Space | 6.33% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 465.76 Gb Total Space | 390.74 Gb Free Space | 83.89% Space Free | Partition Type: NTFS
Computer Name: CENTRAAL
Current User Name: Boris
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe (NVIDIA Corporation)
PRC - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\Bret Taylor\Stickies\Stickies.exe (Bret Taylor)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Boris\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (CCALib8 [Auto | Running]) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DefWatch [Auto | Running]) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (InCDsrv [Auto | Running]) -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NMIndexingService [On_Demand | Stopped]) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (Norton AntiVirus Server [Auto | Running]) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (UleadBurningHelper [Auto | Running]) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (61883 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\61883.sys (Microsoft Corporation)
DRV - (ALCXWDM [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (Avc [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\avc.sys (Microsoft Corporation)
DRV - (axwhisky [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\axwhisky.sys ( )
DRV - (axwskbus [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\axwskbus.sys ( )
DRV - (BrScnUsb [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (Cinemsup [System | Running]) -- C:\WINDOWS\System32\drivers\cinemsup.sys (Sonic Solutions)
DRV - (drvmcdb [Boot | Running]) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) -- C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (InCDfs [Disabled | Running]) -- C:\WINDOWS\system32\drivers\InCDFs.sys (Nero AG)
DRV - (InCDPass [System | Running]) -- C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (incdrm [System | Running]) -- C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (MSDV [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\msdv.sys (Microsoft Corporation)
DRV - (ms_mpu401 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ASACPI.sys ()
DRV - (NAVAP [On_Demand | Running]) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navap.sys (Symantec Corporation)
DRV - (NAVAPEL [Auto | Running]) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS (Symantec Corporation)
DRV - (NAVENG [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090410.003\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090410.003\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvax [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (nvnforce [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (PalmUSBD [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (pcouffin [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sscdbhk5 [System | Running]) -- C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) -- C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (SymEvent [On_Demand | Running]) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (tfsnboio [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (usb_rndisx [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\usb8023x.sys (Microsoft Corporation)
DRV - (vcdrom [System | Running]) -- C:\WINDOWS\system32\VCdRom.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.goodsearch.com/"
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/11 23:55:18 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/28 23:02:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/28 23:02:08 | 00,000,000 | ---D | M]
[2008/07/09 19:17:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Boris\Application Data\mozilla\Extensions
[2008/07/09 19:17:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Boris\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/07/09 19:17:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Boris\Application Data\mozilla\Firefox\Profiles\htjz5xmr.default\extensions
[2009/04/09 01:21:21 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/03/28 23:02:08 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/08/05 00:13:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/12/11 23:55:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/03/28 23:02:04 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/28 23:02:04 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/09/27 03:34:33 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/09/27 03:34:33 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/09/27 03:34:33 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/14 09:37:34 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/09/27 03:34:33 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/09/27 03:34:33 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/09/27 03:34:33 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (767 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 q4master.idsoftware.com
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - Reg Error: Key error. File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun (Brother Industries, Ltd.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers File not found
O4 - HKLM..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot (Scansoft, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe (Symantec Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [Stickies] C:\Program Files\Bret Taylor\Stickies\Stickies.exe (Bret Taylor)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Boris\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.co.../sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.co...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.227,85.255.112.166
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{ACDA1449-1CD4-4CB2-BB84-6B005881B2DC}\\NameServer = 85.255.112.227,85.255.112.166
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{327e9c1a-cefe-11dd-b695-0013d4f77916}\Shell\AutoRun\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe
O33 - MountPoints2\{327e9c1a-cefe-11dd-b695-0013d4f77916}\Shell\open\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe
O33 - MountPoints2\{7e994ec2-4da2-11dd-b231-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{7e994ec2-4da2-11dd-b231-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7e994ec2-4da2-11dd-b231-806d6172696f}\Shell\AutoRun\command - "" = D:\ASUSACPI.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[4 C:\WINDOWS\*.tmp files]
[2009/04/13 01:40:11 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\DOCUME~1\Boris\Desktop\OTListIt2.exe
[2009/04/13 01:38:55 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/04/13 01:38:38 | 00,267,612 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Rooter.exe
[2009/04/13 01:36:01 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\DOCUME~1\Boris\Desktop\gooble.exe
[2009/04/13 01:34:07 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/13 01:34:07 | 00,000,696 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/13 01:34:05 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/13 01:34:04 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/13 01:34:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/13 01:33:29 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\DOCUME~1\Boris\Desktop\mbam-setup.exe
[2009/04/13 01:06:10 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\Boris\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/13 01:05:49 | 00,000,611 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\NTREGOPT.lnk
[2009/04/13 01:05:49 | 00,000,592 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\ERUNT.lnk
[2009/04/13 01:05:49 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/04/13 01:05:09 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\DOCUME~1\Boris\Desktop\erunt_setup.exe
[2009/04/13 01:02:42 | 00,021,504 | ---- | C] (Doug Knox) -- C:\DOCUME~1\Boris\Desktop\SysRestorePoint.exe
[2009/04/11 00:00:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/04/10 23:52:46 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009/04/10 21:26:17 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/04/10 21:26:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/10 09:47:32 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\Desktop\Palm
[2009/04/10 09:45:52 | 00,000,000 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Ad-AwareAE.exe
[2009/04/10 09:45:49 | 10,677,120 | ---- | C] (Lavasoft ) -- C:\DOCUME~1\Boris\Desktop\Ad-AwareAE.exe.part
[2009/04/10 09:43:49 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\DOCUME~1\Boris\Desktop\spybotsd162.exe
[2009/04/10 02:05:58 | 00,000,582 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\tdtetris.jad
[2009/04/10 02:00:12 | 00,006,414 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\corrhack.zip
[2009/04/10 01:55:08 | 00,044,616 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\vexed.zip
[2009/04/09 23:00:08 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gxvxcserv.sys
[2009/04/08 01:23:02 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/04/08 00:57:01 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\Desktop\Palm SW
[2009/04/07 22:31:16 | 00,016,640 | R--- | C] (PalmSource, Inc.) -- C:\WINDOWS\System32\drivers\PalmUSBD.sys
[2009/04/07 22:26:41 | 00,001,513 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
[2009/04/07 22:26:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Boris\Application Data\Arcsoft
[2009/04/07 22:26:27 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\My Documents\My Albums
[2009/04/07 22:26:08 | 00,001,478 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Palm Desktop.lnk
[2009/04/07 22:24:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Boris\Application Data\HotSync
[2009/04/07 22:24:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2009/04/07 22:24:21 | 00,000,000 | ---D | C] -- C:\Program Files\Palm
[2009/04/07 22:07:14 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\My Documents\Palm OS Desktop
[2009/04/03 08:09:10 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\Desktop\Rickle
[2009/04/03 07:57:03 | 00,000,384 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Shortcut to amboo.lnk
[2009/03/31 08:04:35 | 00,013,824 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Movie List.xls
[2009/03/27 08:03:36 | 03,702,784 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\cd080802.iso
[2009/03/22 10:35:57 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Boris\Desktop\Nav8Client
[2009/03/18 18:42:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Boris\Local Settings\Application Data\WMTools Downloaded Files
[2009/03/17 21:52:20 | 00,000,000 | ---D | C] -- C:\Program Files\StoneHeads
[2009/03/17 21:52:14 | 00,000,196 | ---- | C] () -- C:\WINDOWS\STONEHDS.INI
[2009/03/14 22:43:29 | 01,138,688 | ---- | C] () -- C:\DOCUME~1\Boris\Desktop\Memtest86_3.5.iso
[2009/03/11 07:55:20 | 00,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/11/15 00:49:55 | 00,000,316 | ---- | C] () -- C:\WINDOWS\game.ini
[2008/11/09 12:06:04 | 00,000,079 | ---- | C] () -- C:\WINDOWS\SW_Win2000X1.DLL
[2008/11/09 12:05:27 | 00,000,027 | ---- | C] () -- C:\WINDOWS\SW_Win2146X32.DLL
[2008/11/09 11:53:09 | 00,003,774 | ---- | C] () -- C:\WINDOWS\CX_SearchHistory.INI
[2008/11/09 11:53:03 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\CSVSpecialProcessing.dll
[2008/11/09 11:53:03 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\SARzilla.dll
[2008/11/09 11:53:03 | 00,098,304 | ---- | C] () -- C:\WINDOWS\System32\DVM.dll
[2008/11/09 11:53:03 | 00,000,530 | ---- | C] () -- C:\WINDOWS\System32\tx13_ic.ini
[2008/07/24 08:59:00 | 00,000,410 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2008/07/24 08:57:34 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\BROSNMP.DLL
[2008/07/24 08:57:27 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll
[2008/07/24 08:55:52 | 00,027,019 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2008/07/13 21:08:07 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/07/13 11:59:05 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/07/11 00:52:22 | 00,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2008/07/09 14:51:16 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2008/07/09 14:51:13 | 00,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2008/07/09 14:43:53 | 00,000,266 | R--- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
[2008/07/09 14:43:41 | 00,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/07/09 14:43:40 | 00,005,700 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/07/09 14:43:37 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/10/12 23:20:06 | 00,151,417 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2006/02/09 10:06:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/02/09 10:06:00 | 01,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/02/09 10:06:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/02/09 10:06:00 | 00,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/02/09 10:06:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/02/09 10:06:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2004/12/20 22:26:12 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/03 21:07:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004/08/03 21:07:00 | 00,000,573 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/03 21:07:00 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/12/19 02:00:00 | 00,013,387 | ---- | C] () -- C:\WINDOWS\System32\CinemSup.sys
[2003/07/02 17:41:42 | 00,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\axwhisky.sys
[2003/07/02 16:49:52 | 00,124,160 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\axwskbus.sys
[2003/04/26 01:16:00 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
[2002/03/04 10:16:34 | 00,110,592 | R--- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
[1999/01/22 14:46:56 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== Files - Modified Within 30 Days ==========
[2 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/04/13 01:40:11 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\DOCUME~1\Boris\Desktop\OTListIt2.exe
[2009/04/13 01:38:38 | 00,267,612 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\Rooter.exe
[2009/04/13 01:36:01 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\DOCUME~1\Boris\Desktop\gooble.exe
[2009/04/13 01:34:07 | 00,000,696 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/13 01:33:35 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\DOCUME~1\Boris\Desktop\mbam-setup.exe
[2009/04/13 01:06:10 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\Boris\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/13 01:05:49 | 00,000,611 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\NTREGOPT.lnk
[2009/04/13 01:05:49 | 00,000,592 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\ERUNT.lnk
[2009/04/13 01:05:09 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\DOCUME~1\Boris\Desktop\erunt_setup.exe
[2009/04/13 01:02:42 | 00,021,504 | ---- | M] (Doug Knox) -- C:\DOCUME~1\Boris\Desktop\SysRestorePoint.exe
[2009/04/12 23:07:12 | 00,000,312 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2009/04/12 23:07:08 | 00,194,593 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/04/12 23:06:09 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/12 23:06:08 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/12 23:06:07 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/11 00:02:37 | 00,056,320 | ---- | M] () -- C:\Documents and Settings\Boris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/11 00:02:37 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/04/10 09:46:15 | 10,677,120 | ---- | M] (Lavasoft ) -- C:\DOCUME~1\Boris\Desktop\Ad-AwareAE.exe.part
[2009/04/10 09:45:52 | 00,000,000 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\Ad-AwareAE.exe
[2009/04/10 09:44:43 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\DOCUME~1\Boris\Desktop\spybotsd162.exe
[2009/04/10 02:05:58 | 00,000,582 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\tdtetris.jad
[2009/04/10 02:00:12 | 00,006,414 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\corrhack.zip
[2009/04/10 01:55:08 | 00,044,616 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\vexed.zip
[2009/04/09 23:00:08 | 00,035,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gxvxcserv.sys
[2009/04/08 01:10:41 | 00,234,368 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/07 22:34:22 | 00,068,920 | ---- | M] () -- C:\Documents and Settings\Boris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/07 22:26:41 | 00,001,513 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
[2009/04/07 22:26:08 | 00,001,478 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Palm Desktop.lnk
[2009/04/07 22:22:12 | 00,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2009/04/07 21:30:27 | 00,458,340 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/07 21:30:27 | 00,392,296 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/07 21:30:27 | 00,058,596 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/07 21:23:50 | 00,000,573 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/04/07 08:29:25 | 00,000,668 | ---- | M] () -- C:\Documents and Settings\Boris\Application Data\vso_ts_preview.xml
[2009/04/06 15:32:54 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/03 07:57:04 | 00,000,384 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\Shortcut to amboo.lnk
[2009/04/03 07:50:18 | 02,106,246 | -H-- | M] () -- C:\Documents and Settings\Boris\Local Settings\Application Data\IconCache.db
[2009/03/31 08:04:35 | 00,013,824 | ---- | M] () -- C:\DOCUME~1\Boris\Desktop\Movie List.xls
[2009/03/17 21:54:12 | 00,000,196 | ---- | M] () -- C:\WINDOWS\STONEHDS.INI
[2009/03/14 01:59:57 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
========== Alternate Data Streams ==========
@Alternate Data Stream - 304 bytes -> C:\DOCUME~1\Boris\Desktop\retrospect.jpg:SummaryInformation
@Alternate Data Stream - 304 bytes -> C:\DOCUME~1\Boris\Desktop\retrospect b.jpg:SummaryInformation
@Alternate Data Stream - 304 bytes -> C:\DOCUME~1\Boris\Desktop\Retropair A.jpg:SummaryInformation
@Alternate Data Stream - 304 bytes -> C:\DOCUME~1\Boris\Desktop\card 004.JPG:SummaryInformation
< End of report >
Here's Extras.txt
~~~~~~~~~~~~~~~
OTListIt Extras logfile created on: 4/13/2009 1:42:25 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Boris\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 449.43 Mb Available Physical Memory | 43.91% Memory free
2.40 Gb Paging File | 2.02 Gb Available in Paging File | 84.15% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.47 Gb Total Space | 17.68 Gb Free Space | 6.33% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 465.76 Gb Total Space | 390.74 Gb Free Space | 83.89% Space Free | Partition Type: NTFS
Computer Name: CENTRAAL
Current User Name: Boris
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent ()
D:\CDS\Nero\Installation\SetupX.exe:*:Enabled:Nero ProductSetup File not found
C:\Program Files\Wild Hare\Instinct\instinct.exe:*:Disabled:ds2main File not found
C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe:*:Disabled:BF1942 File not found
C:\Program Files\Mass Effect\Binaries\MassEffect.exe:*:Enabled:Mass Effect Game (BioWare)
C:\Program Files\Mass Effect\MassEffectLauncher.exe:*:Enabled:Mass Effect Launcher (BioWare)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\Corel\DVD9\WinDVD.exe:*:Disabled:WinDVD File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0A770EE2-905F-4DBD-8963-2E4F0FAFD66F}" = Stickies
"{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}" = Symantec AntiVirus Client
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1596098A-FCEC-48F0-B7C7-08A31B771033}" = Nero 7 Essentials
"{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Studio Deluxe Suite
"{26792CA7-D87A-4DBE-896B-C2F66B344511}" = Sonic CinePlayer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F262ADC-5AD2-48E5-A586-44315E04A9E2}" = Microsoft Picture It! Library 10
"{42756145-9997-4D28-809B-8756BFD00106}" = Microsoft Photo Premium 10
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4F1DA6BF-3614-48A1-9970-9E90F646789E}" = Ulead VideoStudio 8.0
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.1.2.34
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{8809BF72-C693-44B6-8B2A-B689A00059D5}" = Eudora
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{95C42225-F0E2-4480-AD65-560D854F252E}" = Palm Desktop by ACCESS
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BB47D7EA-7EF1-475C-9C14-AF5B8FCA45E2}" = Condemned - Criminal Origins
"{D1B01DC9-CBAF-45F9-A387-7D00C11B630E}" = Microsoft Games for Windows - LIVE Redistributable
"{D7A6C517-11F2-419F-B5BB-27772B939698}" = NvMixer
"{D83BD5E2-5AF4-49F6-B5C1-484A9760E73D}" = Brother MFL-Pro Suite
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E9F81423-211E-46B6-9AE0-38568BC5CF6F}" = Alcohol 120%
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"ACDSee 32" = ACDSee 32
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Convert XLS_is1" = Convert XLS
"CSCLIB" = Canon Camera Support Core Library
"DVD Shrink_is1" = DVD Shrink 3.2
"EOS Utility" = Canon Utilities EOS Utility
"ERUNT_is1" = ERUNT 1.1j
"Forte Agent" = Forté Agent
"GameBox Classics" = GameBox Classics
"Glary Utilities_is1" = Glary Utilities 2.7.268
"Handmark® Tetris 2 for Pocket PC" = Handmark® Tetris 2 for Pocket PC
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"LimeWire" = LimeWire 4.18.8
"LiveUpdate" = LiveUpdate 1.80 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MatrixEngine 1.0" = MatrixEngine
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mihov Blank Screen" = Mihov Blank Screen 1.3 (remove only)
"Mihov Image Resizer" = Mihov Image Resizer 1.1 (remove only)
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"PhotoStitch" = Canon Utilities PhotoStitch
"PictureItPrem_v10" = Microsoft Photo Premium 10
"PocketSuspendFX" = PocketSuspendFX
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SystemRequirementsLab" = System Requirements Lab
"Tweak UI 2.10" = Tweak UI
"VLC media player" = VideoLAN VLC media player 0.8.6h
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR archiver
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"Zuma Deluxe 1.0" = Zuma Deluxe 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
"WinDirStat" = WinDirStat 1.1.2
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/3/2009 9:58:43 AM | Computer Name = CENTRAAL | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: W32.Virut.CF in File: F:\System Volume Information\_restore{F70FD2AA-EC40-4AE9-B5B7-6564DAB007DF}\RP306\A0032719.exe
by: Realtime Protection scan. Action: Delete succeeded : Access denied
Error - 4/3/2009 10:58:43 AM | Computer Name = CENTRAAL | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: W32.Virut.CF in File: F:\System Volume Information\_restore{F70FD2AA-EC40-4AE9-B5B7-6564DAB007DF}\RP306\A0032720.exe
by: Realtime Protection scan. Action: Delete succeeded : Access denied
Error - 4/3/2009 11:58:43 AM | Computer Name = CENTRAAL | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: W32.Virut.CF in File: F:\System Volume Information\_restore{F70FD2AA-EC40-4AE9-B5B7-6564DAB007DF}\RP306\A0032721.exe
by: Realtime Protection scan. Action: Delete succeeded : Access denied
Error - 4/3/2009 12:58:43 PM | Computer Name = CENTRAAL | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: W32.Virut.CF in File: F:\System Volume Information\_restore{F70FD2AA-EC40-4AE9-B5B7-6564DAB007DF}\RP306\A0032722.exe
by: Realtime Protection scan. Action: Delete succeeded : Access denied
Error - 4/3/2009 1:58:43 PM | Computer Name = CENTRAAL | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: W32.Virut.CF in File: F:\System Volume Information\_restore{F70FD2AA-EC40-4AE9-B5B7-6564DAB007DF}\RP306\A0032723.exe
by: Realtime Protection scan. Action: Delete succeeded : Access denied
Error - 4/7/2009 10:38:52 PM | Computer Name = CENTRAAL | Source = Application Error | ID = 1000
Description = Faulting application outlook.exe, version 9.0.0.2416, faulting module
outllib.dll, version 9.0.0.3821, fault address 0x00078081.
Error - 4/10/2009 9:25:26 PM | Computer Name = CENTRAAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: A connection with the server could not be established
Error - 4/10/2009 9:25:27 PM | Computer Name = CENTRAAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/10/2009 11:53:28 PM | Computer Name = CENTRAAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: A connection with the server could not be established
Error - 4/10/2009 11:53:28 PM | Computer Name = CENTRAAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
[ System Events ]
Error - 4/11/2009 12:01:30 AM | Computer Name = CENTRAAL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 4/11/2009 12:04:34 AM | Computer Name = CENTRAAL | Source = Service Control Manager | ID = 7031
Description = The DCOM Server Process Launcher service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in 60000
milliseconds: Reboot the machine.
Error - 4/11/2009 12:04:34 AM | Computer Name = CENTRAAL | Source = Service Control Manager | ID = 7034
Description = The Terminal Services service terminated unexpectedly. It has done
this 1 time(s).
Error - 4/11/2009 12:04:45 AM | Computer Name = CENTRAAL | Source = Service Control Manager | ID = 7031
Description = The Remote Procedure Call (RPC) service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in 60000
milliseconds: Reboot the machine.
Error - 4/11/2009 12:06:59 AM | Computer Name = CENTRAAL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 4/11/2009 12:08:15 AM | Computer Name = CENTRAAL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Cinemsup Fips Processor
Error - 4/11/2009 12:15:52 AM | Computer Name = CENTRAAL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 4/11/2009 12:20:36 AM | Computer Name = CENTRAAL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 4/11/2009 12:20:41 AM | Computer Name = CENTRAAL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 4/12/2009 11:07:45 PM | Computer Name = CENTRAAL | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
< End of report >