RootRepeal
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/17 03:49
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF7E5C000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8AB3000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PCI_PNP3182
Image Path: \Driver\PCI_PNP3182
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF75D4000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spdg.sys
Image Path: spdg.sys
Address: 0xF8455000 Size: 1052672 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: win32k.sys:1
Image Path: C:\WINDOWS\win32k.sys:1
Address: 0xF883F000 Size: 20480 File Visible: No Signed: -
Status: -
Name: win32k.sys:2
Image Path: C:\WINDOWS\win32k.sys:2
Address: 0xF8607000 Size: 61440 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "spdg.sys" at address 0xf84560e0
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spdg.sys" at address 0xf8474ca4
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spdg.sys" at address 0xf8475032
#: 119 Function Name: NtOpenKey
Status: Hooked by "spdg.sys" at address 0xf84560c0
#: 160 Function Name: NtQueryKey
Status: Hooked by "spdg.sys" at address 0xf847510a
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spdg.sys" at address 0xf8474f8a
#: 247 Function Name: NtSetValueKey
Status: Hooked by "spdg.sys" at address 0xf847519c
==EOF==
OTL.txt
OTL logfile created on: 10/17/2009 4:22:13 AM - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
509.98 Mb Total Physical Memory | 267.64 Mb Available Physical Memory | 52.48% Memory free
1.22 Gb Paging File | 1.05 Gb Available in Paging File | 86.08% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.70 Gb Total Space | 3.52 Gb Free Space | 6.67% Space Free | Partition Type: NTFS
Drive D: | 18.48 Gb Total Space | 8.31 Gb Free Space | 44.95% Space Free | Partition Type: NTFS
Drive E: | 487.84 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DANSROOM
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/10/17 04:20:17 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL2.exe
PRC - [2009/01/15 03:17:22 | 00,636,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
========== Win32 Services (SafeList) ==========
SRV - File not found -- -- (McSysmon [On_Demand | Stopped])
SRV - File not found -- -- (McShield [Unknown | Stopped])
SRV - [2009/10/17 00:34:12 | 00,065,536 | ---- | M] (TG Soft Sas www.tgsoft.it) -- C:\VeXpLite\viritsvc.exe -- (viritsvclite [Auto | Stopped])
SRV - [2009/06/05 13:39:14 | 00,541,992 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped])
SRV - [2009/06/05 11:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Stopped])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Stopped])
SRV - [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [Auto | Stopped])
SRV - [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$MSSMLBIZ [Auto | Stopped])
SRV - [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Auto | Stopped])
SRV - [2008/11/24 22:31:08 | 00,045,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper [Disabled | Stopped])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2007/08/24 04:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2007/03/07 15:47:46 | 00,076,848 | ---- | M] () -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService [On_Demand | Stopped])
SRV - [2007/01/04 17:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service [Auto | Stopped])
SRV - [2006/10/26 15:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/10/18 21:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2005/11/14 01:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2005/07/12 10:33:02 | 00,491,520 | ---- | M] () -- C:\WINDOWS\System32\dlcjcoms.exe -- (dlcj_device [On_Demand | Stopped])
SRV - [2003/12/17 14:59:48 | 00,143,360 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc [On_Demand | Stopped])
SRV - [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co...html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 03:01:32 | 00,000,000 | ---D | M]
O1 HOSTS File: (302562 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10430 more lines...
O2 - BHO: (C:\WINDOWS\system32\a1ulp4kbz.dll) - {A249BC15-23F2-42AD-F4E4-00AAC39C0004} - C:\WINDOWS\System32\a1ulp4kbz.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [Antivirus Pro 2010] C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe (;qkdfjfsdsgjsdg)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [calc] C:\WINDOWS\System32\calc.DLL (Microsoft)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DLCJCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.DLL ()
O4 - HKLM..\Run: [dlcjmon.exe] C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe (Dell)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] c:\dell\E-Center\gtb.exe File not found
O4 - HKLM..\Run: [ferayovep] C:\WINDOWS\System32\fuzuhefu.DLL ()
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] D:\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [MemoryCardManager] C:\Program Files\Dell Photo AIO Printer 964\memcard.exe ()
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VIRIT LITE MONITOR] C:\VeXpLite\MONLITE.EXE ()
O4 - HKLM..\Run: [winupdate.exe] C:\WINDOWS\System32\winupdate.exe File not found
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [Yjafosi8kdf98winmdkmnkmfnwe] C:\Documents and Settings\Administrator\Local Settings\Temp\winlogon.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\cats\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll File not found
O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll File not found
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll File not found
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll File not found
O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} http://simcity.ea.co...date/EARTPX.cab (EARTPatchX Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} http://simcity.ea.co...ty4PatcherX.cab (MaxisSimCity4PatcherX Control)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_08)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.245.129 167.206.245.130
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\windows\system32\ludiyofu.dll) - C:\WINDOWS\System32\ludiyofu.dll ()
O20 - AppInit_DLLs: (c:\DOCUME~1\ALLUSE~1\APPLIC~1\pudaveya\pudaveya.dll) - c:\Documents and Settings\All Users\Application Data\pudaveya\pudaveya.dll ()
O20 - AppInit_DLLs: (c:\DOCUME~1\ALLUSE~1\APPLIC~1\zuzofewe\zuzofewe.dll) - c:\Documents and Settings\All Users\Application Data\zuzofewe\zuzofewe.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\boruyani.dll) - C:\WINDOWS\System32\boruyani.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\sidehole.dll) - C:\WINDOWS\System32\sidehole.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\kumizodo.dll) - C:\WINDOWS\System32\kumizodo.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\yowirubu.dll) - C:\WINDOWS\System32\yowirubu.dll ()
O20 - AppInit_DLLs: (kusumiwi.dll) - C:\WINDOWS\System32\kusumiwi.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\varabefa.dll) - C:\WINDOWS\System32\varabefa.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\yefinuli.dll) - C:\WINDOWS\System32\yefinuli.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\nevokumo.dll) - C:\WINDOWS\System32\nevokumo.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\muyiseta.dll) - C:\WINDOWS\System32\muyiseta.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\vewuyati.dll) - C:\WINDOWS\System32\vewuyati.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\yenusapo.dll) - C:\WINDOWS\System32\yenusapo.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\fuzuhefu.dll) - C:\WINDOWS\System32\fuzuhefu.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: fibuhesuj - {a33a0337-c976-4a62-864c-114fba12bd99} - C:\WINDOWS\System32\fuzuhefu.dll ()
O21 - SSODL: figehoduh - {6df4f4ee-b1b2-41c0-b465-5f5e9646d610} - C:\WINDOWS\System32\yowirubu.dll ()
O21 - SSODL: goyolafim - {bb5cac16-d07c-4d67-9778-12d81a2047f8} - C:\WINDOWS\System32\yefinuli.dll ()
O21 - SSODL: gukodosoz - {f93458ef-0389-4013-9c80-0c84c50b4cc2} - CLSID or File not found.
O21 - SSODL: gulesewik - {1d750f0e-9ca3-4fc3-bfc5-a54cc53c5536} - c:\Documents and Settings\All Users\Application Data\zuzofewe\zuzofewe.dll ()
O21 - SSODL: hepejezem - {2706bacb-a6bc-44a9-b0f9-411cf8c05a08} - C:\WINDOWS\System32\yenusapo.dll ()
O21 - SSODL: jawosubiv - {40eac9dd-de86-44d3-84af-96394fa25b76} - C:\WINDOWS\System32\kumizodo.dll ()
O21 - SSODL: jigolohef - {03c1d344-ea80-42ec-9082-e10ddee03130} - c:\Documents and Settings\All Users\Application Data\pudaveya\pudaveya.dll ()
O21 - SSODL: kederazij - {cacdd594-951d-4d58-975d-75bf64892c47} - c:\Documents and Settings\All Users\Application Data\zuzofewe\zuzofewe.dll ()
O21 - SSODL: kumusuvab - {6911a698-5649-4e71-bc82-dd448d69c45a} - C:\WINDOWS\System32\nevokumo.dll ()
O21 - SSODL: muyakadah - {dbb2d341-bbe8-441a-916a-80c70566c89c} - C:\WINDOWS\System32\varabefa.dll ()
O21 - SSODL: nividizum - {0627a1d9-1935-482b-a12e-482b405e1824} - C:\WINDOWS\System32\yenusapo.dll ()
O21 - SSODL: niwojebaj - {7fa5aafd-e751-4f3b-87d0-b589d2db206c} - CLSID or File not found.
O21 - SSODL: podarudor - {3b1276a1-7a92-4e29-99ae-20cd000cb439} - C:\WINDOWS\System32\vewuyati.dll ()
O21 - SSODL: ravasizop - {a823b1f0-2b4a-442a-817b-61cb9756f1d3} - C:\WINDOWS\System32\yenusapo.dll ()
O21 - SSODL: rihuguvup - {a3a060da-156e-4f2f-92a5-f1546770b799} - C:\WINDOWS\System32\varabefa.dll ()
O21 - SSODL: rirogovuf - {9b750ad2-b330-4797-bd9c-4136f62cd900} - C:\WINDOWS\System32\yenusapo.dll ()
O21 - SSODL: tomeramom - {44fda548-dcd4-4349-bd76-9624219f8bdd} - CLSID or File not found.
O21 - SSODL: tupegewew - {75ca0af1-a537-435d-850b-fe5bd6c6512b} - C:\WINDOWS\System32\yenusapo.dll ()
O21 - SSODL: vosirifoh - {833c647f-0ff7-496b-ad97-9aae98476c2d} - c:\Documents and Settings\All Users\Application Data\pudaveya\pudaveya.dll ()
O21 - SSODL: vowirakoh - {fbf035d2-1401-4b3a-8485-d1b56545c50c} - C:\WINDOWS\System32\sidehole.dll ()
O21 - SSODL: winujiveg - {410d9bda-5516-473b-8553-40b7cac531ef} - C:\WINDOWS\System32\muyiseta.dll ()
O21 - SSODL: wivoluved - {223f1e7e-1063-41c2-b90f-89de76b430d9} - C:\WINDOWS\System32\sidehole.dll ()
O21 - SSODL: wugemeyos - {7da4ec36-e4f1-4490-80f9-7ee6a238ae88} - C:\WINDOWS\System32\yefinuli.dll ()
O21 - SSODL: yodabofep - {baa0a898-66b7-48cd-a6d8-7719815d2f91} - c:\Documents and Settings\All Users\Application Data\zuzofewe\zuzofewe.dll ()
O21 - SSODL: zalujosez - {b0e28726-6d1e-4f31-ac1a-478d247ba1bb} - C:\WINDOWS\System32\yowirubu.dll ()
O22 - SharedTaskScheduler: {03c1d344-ea80-42ec-9082-e10ddee03130} - gahurihor - c:\Documents and Settings\All Users\Application Data\pudaveya\pudaveya.dll ()
O22 - SharedTaskScheduler: {0627a1d9-1935-482b-a12e-482b405e1824} - gahurihor - C:\WINDOWS\System32\yenusapo.dll ()
O22 - SharedTaskScheduler: {1d750f0e-9ca3-4fc3-bfc5-a54cc53c5536} - kupuhivus - c:\Documents and Settings\All Users\Application Data\zuzofewe\zuzofewe.dll ()
O22 - SharedTaskScheduler: {223f1e7e-1063-41c2-b90f-89de76b430d9} - gahurihor - C:\WINDOWS\System32\sidehole.dll ()
O22 - SharedTaskScheduler: {2706bacb-a6bc-44a9-b0f9-411cf8c05a08} - mujuzedij - C:\WINDOWS\System32\yenusapo.dll ()
O22 - SharedTaskScheduler: {3b1276a1-7a92-4e29-99ae-20cd000cb439} - jugezatag - C:\WINDOWS\System32\vewuyati.dll ()
O22 - SharedTaskScheduler: {40eac9dd-de86-44d3-84af-96394fa25b76} - tokatiluy - C:\WINDOWS\System32\kumizodo.dll ()
O22 - SharedTaskScheduler: {410d9bda-5516-473b-8553-40b7cac531ef} - gahurihor - C:\WINDOWS\System32\muyiseta.dll ()
O22 - SharedTaskScheduler: {44fda548-dcd4-4349-bd76-9624219f8bdd} - jugezatag - Reg Error: Value error. File not found
O22 - SharedTaskScheduler: {6911a698-5649-4e71-bc82-dd448d69c45a} - kupuhivus - C:\WINDOWS\System32\ludiyofu.dll ()
O22 - SharedTaskScheduler: {6df4f4ee-b1b2-41c0-b465-5f5e9646d610} - gahurihor - C:\WINDOWS\System32\yowirubu.dll ()
O22 - SharedTaskScheduler: {75ca0af1-a537-435d-850b-fe5bd6c6512b} - kupuhivus - C:\WINDOWS\System32\yenusapo.dll ()
O22 - SharedTaskScheduler: {7da4ec36-e4f1-4490-80f9-7ee6a238ae88} - kupuhivus - C:\WINDOWS\System32\yefinuli.dll ()
O22 - SharedTaskScheduler: {7fa5aafd-e751-4f3b-87d0-b589d2db206c} - gahurihor - Reg Error: Value error. File not found
O22 - SharedTaskScheduler: {833c647f-0ff7-496b-ad97-9aae98476c2d} - jugezatag - c:\Documents and Settings\All Users\Application Data\pudaveya\pudaveya.dll ()
O22 - SharedTaskScheduler: {9b750ad2-b330-4797-bd9c-4136f62cd900} - gahurihor - C:\WINDOWS\System32\yenusapo.dll ()
O22 - SharedTaskScheduler: {A249BC15-23F2-42AD-F4E4-00AAC39C0004} - iukjsf8w3jirojs9f8u3jruhsf78s3jijdif - C:\WINDOWS\System32\a1ulp4kbz.dll ()
O22 - SharedTaskScheduler: {a33a0337-c976-4a62-864c-114fba12bd99} - gahurihor - C:\WINDOWS\System32\fuzuhefu.dll ()
O22 - SharedTaskScheduler: {a3a060da-156e-4f2f-92a5-f1546770b799} - gahurihor - C:\WINDOWS\System32\varabefa.dll ()
O22 - SharedTaskScheduler: {a823b1f0-2b4a-442a-817b-61cb9756f1d3} - tokatiluy - C:\WINDOWS\System32\yenusapo.dll ()
O22 - SharedTaskScheduler: {b0e28726-6d1e-4f31-ac1a-478d247ba1bb} - tokatiluy - C:\WINDOWS\System32\yowirubu.dll ()
O22 - SharedTaskScheduler: {baa0a898-66b7-48cd-a6d8-7719815d2f91} - jugezatag - c:\Documents and Settings\All Users\Application Data\zuzofewe\zuzofewe.dll ()
O22 - SharedTaskScheduler: {bb5cac16-d07c-4d67-9778-12d81a2047f8} - jugezatag - C:\WINDOWS\System32\yefinuli.dll ()
O22 - SharedTaskScheduler: {cacdd594-951d-4d58-975d-75bf64892c47} - mujuzedij - c:\Documents and Settings\All Users\Application Data\zuzofewe\zuzofewe.dll ()
O22 - SharedTaskScheduler: {dbb2d341-bbe8-441a-916a-80c70566c89c} - kupuhivus - C:\WINDOWS\System32\varabefa.dll ()
O22 - SharedTaskScheduler: {f93458ef-0389-4013-9c80-0c84c50b4cc2} - kupuhivus - Reg Error: Value error. File not found
O22 - SharedTaskScheduler: {fbf035d2-1401-4b3a-8485-d1b56545c50c} - jugezatag - C:\WINDOWS\System32\sidehole.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/06/12 08:53:14 | 00,000,075 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\start.exe -- [2009/06/12 08:53:23 | 04,707,135 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/10/16 23:39:43 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{3ADA1185-35A8-4B4E-B36B-6392B1DA8C26}
[2009/10/09 03:34:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\71509729
[2009/10/10 03:34:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\gijeluhe
[2009/10/10 15:34:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\kayufema
[2009/10/16 23:30:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/10 15:34:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\pudaveya
[2009/10/10 15:34:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\rolibisu
[2009/10/10 03:34:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\yufatisi
[2009/10/10 03:34:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\zuzofewe
[2009/10/16 18:03:52 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Application Data
[2009/10/16 19:15:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Adobe
[2009/10/17 01:33:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\AVG8
[2009/10/16 18:03:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Identities
[2009/10/16 19:17:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Macromedia
[2009/10/16 23:30:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2009/10/16 18:03:53 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Administrator\Application Data\Microsoft
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Sun
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Symantec
[2009/10/16 18:03:52 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\BVRP Software
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Musicmatch
[2009/10/17 01:00:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\PackageAware
[2009/10/16 18:03:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Wildtangent
[2009/10/16 20:21:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2009/10/16 23:53:01 | 00,000,000 | ---D | C] -- C:\Program Files\AntivirusPro_2010
[2009/10/17 02:34:30 | 00,000,000 | ---D | C] -- C:\Program Files\cats
[2009/10/17 02:32:01 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/10/17 04:20:01 | 00,521,216 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL2.exe
[2009/10/17 03:35:22 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\Administrator\Desktop\RootRepeal.exe
[2009/10/17 02:34:32 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/17 02:34:30 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/10/17 02:32:43 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/10/17 02:30:51 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\Administrator\Desktop\SysRestorePoint.exe
[2009/10/17 00:06:09 | 00,000,000 | ---D | C] -- C:\VeXpLite
[2009/10/16 23:29:42 | 04,045,528 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator\Desktop\cats.exe
[2009/10/16 23:26:27 | 00,889,840 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Administrator\Desktop\avg_free_stb_all_8_37_cnet.exe
[2009/10/16 20:52:22 | 34,101,504 | ---- | C] (PC Tools ) -- C:\Documents and Settings\Administrator\Desktop\sdsetup.exe
[2009/10/16 18:03:52 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\My Documents\My Pictures
[2009/10/16 18:03:52 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\My Documents\My Music
========== Files - Modified Within 14 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/10/17 04:24:22 | 00,011,168 | -H-- | M] () -- C:\WINDOWS\System32\nezumuba
[2009/10/17 04:20:17 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL2.exe
[2009/10/17 03:57:52 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/17 03:56:58 | 00,000,000 | ---- | M] () -- C:\WINDOWS\win32k.sys
[2009/10/17 03:56:53 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/17 03:55:40 | 02,205,456 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2009/10/17 03:51:11 | 00,521,216 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/10/17 03:49:03 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\settings.dat
[2009/10/17 03:48:59 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\Administrator\Desktop\RootRepeal.exe
[2009/10/17 03:40:45 | 01,112,447 | -HS- | M] () -- C:\WINDOWS\System32\seyayewi.exe
[2009/10/17 03:40:43 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\fuzuhefu.dll
[2009/10/17 03:40:42 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\wepekigi.dll
[2009/10/17 02:46:32 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/17 02:38:26 | 00,271,872 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\cak.exe
[2009/10/17 02:34:35 | 00,000,582 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/17 02:32:02 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2009/10/17 02:32:02 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2009/10/17 02:31:07 | 00,075,424 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/10/17 02:30:58 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Documents and Settings\Administrator\Desktop\SysRestorePoint.exe
[2009/10/17 02:29:50 | 00,271,872 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\TFC.exe
[2009/10/17 01:33:11 | 00,889,840 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Administrator\Desktop\avg_free_stb_all_8_37_cnet.exe
[2009/10/17 01:22:23 | 00,000,478 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vir.IT eXplorer Lite.lnk
[2009/10/16 23:29:46 | 04,045,528 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator\Desktop\cats.exe
[2009/10/16 20:52:34 | 34,101,504 | ---- | M] (PC Tools ) -- C:\Documents and Settings\Administrator\Desktop\sdsetup.exe
[2009/10/16 20:15:22 | 00,002,528 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
[2009/10/16 17:52:31 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/16 17:45:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\AVR09.exe
[2009/10/16 17:45:44 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\winhelper.dll
[2009/10/16 17:35:32 | 00,000,831 | ---- | M] () -- C:\WINDOWS\System32\critical_warning.html
[2009/10/16 15:38:28 | 01,111,915 | -HS- | M] (Igor Pavlov) -- C:\WINDOWS\System32\ruvigesa.exe
[2009/10/16 15:38:19 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\yenusapo.dll
[2009/10/16 15:38:19 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\susesari.dll
[2009/10/16 03:38:05 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\lovosoja.dll
[2009/10/16 03:38:03 | 01,115,329 | -HS- | M] () -- C:\WINDOWS\System32\sepadima.exe
[2009/10/16 03:38:02 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\lonibeza.dll
[2009/10/15 15:37:48 | 01,114,795 | -HS- | M] (Igor Pavlov) -- C:\WINDOWS\System32\rudinubo.exe
[2009/10/15 15:37:45 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\vewuyati.dll
[2009/10/15 15:37:44 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\wufajojo.dll
[2009/10/15 03:37:31 | 01,112,325 | -HS- | M] () -- C:\WINDOWS\System32\leyikire.exe
[2009/10/15 03:37:29 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\muyiseta.dll
[2009/10/15 03:37:28 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\kumababe.dll
[2009/10/15 03:37:28 | 00,025,600 | -HS- | M] () -- C:\WINDOWS\System32\piyetuho.exe
[2009/10/14 15:37:15 | 01,114,220 | -HS- | M] (Igor Pavlov) -- C:\WINDOWS\System32\wetohuyo.exe
[2009/10/14 15:37:13 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\nevokumo.dll
[2009/10/14 15:37:12 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\rovezuda.dll
[2009/10/14 03:36:57 | 01,011,604 | -HS- | M] () -- C:\WINDOWS\System32\sokajuji.exe
[2009/10/14 03:36:56 | 00,091,648 | -HS- | M] () -- C:\WINDOWS\System32\yefinuli.dll
[2009/10/14 03:36:55 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\yodogugo.dll
[2009/10/13 15:36:41 | 01,011,606 | -HS- | M] (Igor Pavlov) -- C:\WINDOWS\System32\yomajufe.exe
[2009/10/13 15:36:38 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\varabefa.dll
[2009/10/13 15:36:37 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\nonawava.dll
[2009/10/13 03:37:04 | 00,053,248 | -HS- | M] () -- C:\WINDOWS\System32\vozufehi.dll
[2009/10/13 03:36:36 | 01,011,312 | -HS- | M] () -- C:\WINDOWS\System32\muhimese.exe
[2009/10/13 03:36:34 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\yowirubu.dll
[2009/10/13 03:36:34 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\zizemehe.dll
[2009/10/12 15:36:41 | 00,052,736 | -HS- | M] () -- C:\WINDOWS\System32\busatehe.dll
[2009/10/12 15:36:16 | 01,011,387 | -HS- | M] (Igor Pavlov) -- C:\WINDOWS\System32\pomefeya.exe
[2009/10/12 15:36:11 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\kumizodo.dll
[2009/10/12 15:36:11 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\biyamubu.dll
[2009/10/12 03:35:54 | 01,011,503 | -HS- | M] () -- C:\WINDOWS\System32\wabuyoje.exe
[2009/10/12 03:35:52 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\fuzanamu.dll
[2009/10/12 03:35:52 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\dogebuwe.dll
[2009/10/11 15:35:36 | 01,011,449 | -HS- | M] (Igor Pavlov) -- C:\WINDOWS\System32\vuheluji.exe
[2009/10/11 15:35:35 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\sidehole.dll
[2009/10/11 15:35:32 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\yiwuhiso.dll
[2009/10/11 03:35:16 | 01,011,147 | -HS- | M] () -- C:\WINDOWS\System32\zajeyema.exe
[2009/10/11 03:35:15 | 00,091,648 | -HS- | M] () -- C:\WINDOWS\System32\boruyani.dll
[2009/10/11 03:35:12 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\lofuvika.dll
[2009/10/09 15:34:48 | 00,052,224 | -HS- | M] () -- C:\WINDOWS\System32\pahupotu.dll
[2009/10/09 15:34:22 | 01,011,259 | -HS- | M] (Igor Pavlov) -- C:\WINDOWS\System32\nopasisi.exe
[2009/10/09 15:34:16 | 00,090,624 | -HS- | M] () -- C:\WINDOWS\System32\ludiyofu.dll
[2009/10/09 15:34:15 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\royifego.dll
[2009/10/09 03:34:19 | 00,052,736 | -HS- | M] () -- C:\WINDOWS\System32\yekotafo.dll
[2009/10/09 03:33:54 | 01,050,147 | -HS- | M] () -- C:\WINDOWS\System32\disolada.exe
[2009/10/09 03:33:52 | 01,011,251 | -HS- | M] () -- C:\WINDOWS\System32\fuzoyalu.exe
[2009/10/09 03:33:52 | 00,091,136 | -HS- | M] () -- C:\WINDOWS\System32\waziroto.dll
[2009/10/09 03:33:50 | 00,194,056 | -HS- | M] () -- C:\WINDOWS\System32\kiyiromu.exe
[2009/10/09 03:33:50 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\vogekomu.dll
[2009/10/09 03:33:49 | 00,028,160 | -HS- | M] () -- C:\WINDOWS\System32\nejejuhi.dll
[2009/10/08 20:38:06 | 00,019,930 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\ukaxikote._sy
[2009/10/08 20:38:06 | 00,018,894 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\fyponowota.sys
[2009/10/08 20:38:06 | 00,018,745 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\isololebyh._dl
[2009/10/08 20:38:06 | 00,017,052 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\pywabugesi.inf
[2009/10/08 20:38:06 | 00,016,479 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\amofodety.reg
[2009/10/08 20:38:06 | 00,014,355 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\kyqate.db
[2009/10/08 20:38:06 | 00,012,839 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\acyb.db
[2009/10/08 20:38:06 | 00,011,831 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\gizuz.db
[2009/10/08 20:38:05 | 00,018,375 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\pozopawyp.exe
[2009/10/07 15:32:07 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\jehuzuru.dll
[2009/10/06 09:37:03 | 00,091,136 | ---- | M] () -- C:\WINDOWS\System32\kolakade.dll
[2009/10/06 09:35:38 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\yedawawo.dll
[2009/10/06 09:35:37 | 00,002,713 | -HS- | M] () -- C:\WINDOWS\System32\demiweso.exe
[2009/10/05 21:45:28 | 00,028,160 | ---- | M] () -- C:\WINDOWS\System32\dunohipo.dll
[2009/10/05 21:36:07 | 01,047,587 | -HS- | M] () -- C:\WINDOWS\System32\rokalodu.exe
[2009/10/05 21:35:49 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\donoheju.dll
[2009/10/05 21:35:49 | 00,028,160 | -HS- | M] () -- C:\WINDOWS\System32\givemeku.dll
[2009/10/05 19:56:12 | 00,166,400 | ---- | M] () -- C:\WINDOWS\System32\_scui.cpl
[2009/10/04 00:18:41 | 00,000,046 | ---- | M] () -- C:\p2hhr.bat
[2009/10/04 00:14:58 | 00,039,936 | ---- | M] () -- C:\anlqrvl.exe
[2009/10/04 00:14:55 | 00,189,841 | ---- | M] () -- C:\hufa.exe
[2009/10/04 00:14:53 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\a1ulp4kbz.dll
[2009/10/04 00:14:51 | 00,051,200 | ---- | M] () -- C:\ehrrg.exe
[2009/10/04 00:14:47 | 00,043,520 | ---- | M] () -- C:\vsoq.exe
[2009/10/04 00:14:47 | 00,019,456 | ---- | M] () -- C:\erupquii.exe
[2009/10/04 00:14:46 | 00,005,632 | ---- | M] () -- C:\efbcmkj.exe
[2009/10/04 00:13:39 | 00,340,992 | ---- | M] () -- C:\WINDOWS\System32\~.exe
========== Files - No Company Name ==========
[2009/10/17 03:51:02 | 00,521,216 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/10/17 03:49:03 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\settings.dat
[2009/10/17 02:38:23 | 00,271,872 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\cak.exe
[2009/10/17 02:34:35 | 00,000,582 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/17 02:32:02 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2009/10/17 02:32:02 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2009/10/17 02:31:07 | 00,075,424 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/10/17 02:29:50 | 00,271,872 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\TFC.exe
[2009/10/17 00:06:44 | 00,000,478 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Vir.IT eXplorer Lite.lnk
[2009/10/16 20:15:22 | 00,002,528 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
[2009/10/16 18:04:02 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Administrator\Application Data\desktop.ini
[2009/10/16 18:03:57 | 02,205,456 | -H-- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2009/10/08 20:38:06 | 00,019,930 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ukaxikote._sy
[2009/10/08 20:38:06 | 00,018,894 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\fyponowota.sys
[2009/10/08 20:38:06 | 00,018,745 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\isololebyh._dl
[2009/10/08 20:38:06 | 00,017,052 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\pywabugesi.inf
[2009/10/08 20:38:06 | 00,016,479 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\amofodety.reg
[2009/10/08 20:38:06 | 00,014,355 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\kyqate.db
[2009/10/08 20:38:06 | 00,012,839 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\acyb.db
[2009/10/08 20:38:06 | 00,011,831 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\gizuz.db
[2009/10/08 20:38:05 | 00,018,375 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\pozopawyp.exe
[2009/10/06 09:35:38 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\yedawawo.dll
[2009/10/06 09:35:37 | 00,002,713 | -HS- | C] () -- C:\WINDOWS\System32\demiweso.exe
[2009/10/06 09:28:20 | 00,091,136 | ---- | C] () -- C:\WINDOWS\System32\kolakade.dll
[2009/10/05 21:36:07 | 01,047,587 | -HS- | C] () -- C:\WINDOWS\System32\rokalodu.exe
[2009/10/05 21:35:49 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\donoheju.dll
[2009/10/05 21:35:49 | 00,028,160 | -HS- | C] () -- C:\WINDOWS\System32\givemeku.dll
[2009/10/05 21:30:05 | 00,028,160 | ---- | C] () -- C:\WINDOWS\System32\dunohipo.dll
[2009/10/05 19:56:11 | 00,166,400 | ---- | C] () -- C:\WINDOWS\System32\_scui.cpl
[2009/10/04 00:19:21 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\AVR09.exe
[2009/10/04 00:19:20 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\winhelper.dll
[2009/10/04 00:18:41 | 00,000,046 | ---- | C] () -- C:\p2hhr.bat
[2009/10/04 00:17:15 | 00,000,831 | ---- | C] () -- C:\WINDOWS\System32\critical_warning.html
[2009/10/04 00:15:13 | 00,000,000 | ---- | C] () -- C:\WINDOWS\win32k.sys
[2009/10/04 00:14:56 | 00,039,936 | ---- | C] () -- C:\anlqrvl.exe
[2009/10/04 00:14:53 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\a1ulp4kbz.dll
[2009/10/04 00:14:50 | 00,051,200 | ---- | C] () -- C:\ehrrg.exe
[2009/10/04 00:14:46 | 00,189,841 | ---- | C] () -- C:\hufa.exe
[2009/10/04 00:14:46 | 00,043,520 | ---- | C] () -- C:\vsoq.exe
[2009/10/04 00:14:46 | 00,019,456 | ---- | C] () -- C:\erupquii.exe
[2009/10/04 00:14:46 | 00,005,632 | ---- | C] () -- C:\efbcmkj.exe
[2009/10/04 00:13:38 | 00,340,992 | ---- | C] () -- C:\WINDOWS\System32\~.exe
[2009/07/17 03:40:42 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\fuzuhefu.dll
[2009/07/17 03:40:42 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\wepekigi.dll
[2009/07/16 15:38:18 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\yenusapo.dll
[2009/07/16 15:38:18 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\susesari.dll
[2009/07/16 03:38:00 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\lonibeza.dll
[2009/07/16 03:38:00 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\lovosoja.dll
[2009/07/15 15:37:43 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\vewuyati.dll
[2009/07/15 15:37:43 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\wufajojo.dll
[2009/07/15 03:37:28 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\muyiseta.dll
[2009/07/15 03:37:28 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\kumababe.dll
[2009/07/14 15:37:12 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\nevokumo.dll
[2009/07/14 15:37:12 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\rovezuda.dll
[2009/07/14 03:36:54 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\yefinuli.dll
[2009/07/14 03:36:54 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\yodogugo.dll
[2009/07/13 15:36:37 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\varabefa.dll
[2009/07/13 15:36:37 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\nonawava.dll
[2009/07/13 03:37:18 | 00,053,248 | -HS- | C] () -- C:\WINDOWS\System32\nemupazu.dll
[2009/07/13 03:37:18 | 00,053,248 | -HS- | C] () -- C:\WINDOWS\System32\kusumiwi.dll
[2009/07/13 03:37:18 | 00,053,248 | -HS- | C] () -- C:\WINDOWS\System32\godidihu.dll
[2009/07/13 03:36:33 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\yowirubu.dll
[2009/07/13 03:36:33 | 00,053,248 | -HS- | C] () -- C:\WINDOWS\System32\vozufehi.dll
[2009/07/13 03:36:33 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\zizemehe.dll
[2009/07/12 15:36:10 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\kumizodo.dll
[2009/07/12 15:36:10 | 00,052,736 | -HS- | C] () -- C:\WINDOWS\System32\busatehe.dll
[2009/07/12 15:36:10 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\biyamubu.dll
[2009/07/12 03:35:51 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\fuzanamu.dll
[2009/07/12 03:35:51 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\dogebuwe.dll
[2009/07/11 15:35:31 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\sidehole.dll
[2009/07/11 15:35:31 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\yiwuhiso.dll
[2009/07/11 03:35:12 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\boruyani.dll
[2009/07/11 03:35:12 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\lofuvika.dll
[2009/07/09 15:34:12 | 00,090,624 | -HS- | C] () -- C:\WINDOWS\System32\ludiyofu.dll
[2009/07/09 15:34:12 | 00,052,224 | -HS- | C] () -- C:\WINDOWS\System32\pahupotu.dll
[2009/07/09 15:34:12 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\royifego.dll
[2009/07/09 03:33:49 | 00,091,136 | -HS- | C] () -- C:\WINDOWS\System32\waziroto.dll
[2009/07/09 03:33:48 | 00,052,736 | -HS- | C] () -- C:\WINDOWS\System32\yekotafo.dll
[2009/07/09 03:33:48 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\vogekomu.dll
[2009/07/09 03:33:48 | 00,028,160 | -HS- | C] () -- C:\WINDOWS\System32\nejejuhi.dll
[2009/07/07 15:32:06 | 00,090,624 | -HS- | C] () -- C:\WINDOWS\System32\yohofata.dll
[2009/07/07 15:32:06 | 00,053,248 | -HS- | C] () -- C:\WINDOWS\System32\rewutoha.dll
[2009/07/07 15:32:06 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\jehuzuru.dll
[2009/06/06 15:36:09 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/11/15 22:02:44 | 00,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/02/25 23:07:35 | 00,217,088 | ---- | C] () -- C:\WINDOWS\System32\libmySQL.dll
[2007/02/25 23:07:35 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\TrackerNET.dll
[2007/02/25 22:34:27 | 00,000,080 | ---- | C] () -- C:\WINDOWS\sierra.ini
[2007/01/07 19:24:28 | 00,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/12/24 05:26:11 | 00,000,180 | ---- | C] () -- C:\WINDOWS\sclock.ini
[2006/08/13 01:33:08 | 00,003,350 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/08/13 01:33:08 | 00,000,088 | RHS- | C] () -- C:\WINDOWS\System32\1F06666578.sys
[2006/08/12 21:52:41 | 00,000,034 | ---- | C] () -- C:\WINDOWS\AuthMgr.INI
[2006/08/11 17:21:21 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/08/09 15:41:39 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/08/09 15:31:51 | 00,000,224 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/08/09 15:25:11 | 00,712,704 | ---- | C] () -- C:\WINDOWS\System32\DellSystemRestore.dll
[2006/08/09 15:18:30 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/08/09 14:52:50 | 01,183,744 | ---- | C] () -- C:\WINDOWS\System32\dlcjserv.dll
[2006/08/09 14:52:50 | 01,122,304 | ---- | C] () -- C:\WINDOWS\System32\dlcjusb1.dll
[2006/08/09 14:52:50 | 00,770,048 | ---- | C] () -- C:\WINDOWS\System32\dlcjhbn3.dll
[2006/08/09 14:52:50 | 00,630,784 | ---- | C] () -- C:\WINDOWS\System32\dlcjpmui.dll
[2006/08/09 14:52:50 | 00,491,520 | ---- | C] () -- C:\WINDOWS\System32\dlcjlmpm.dll
[2006/08/09 14:52:50 | 00,430,080 | ---- | C] () -- C:\WINDOWS\System32\dlcjutil.dll
[2006/08/09 14:52:50 | 00,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlcjinsb.dll
[2006/08/09 14:52:50 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\dlcjprox.dll
[2006/08/09 14:52:50 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\dlcjins.dll
[2006/08/09 14:52:50 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\dlcjjswr.dll
[2006/08/09 14:52:50 | 00,114,688 | ---- | C] () -- C:\WINDOWS\System32\dlcjpplc.dll
[2006/08/09 14:52:50 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\dlcjinsr.dll
[2006/08/09 14:52:50 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlcjvs.dll
[2006/08/09 14:52:50 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\dlcjcur.dll
[2006/08/09 14:52:48 | 00,704,512 | ---- | C] () -- C:\WINDOWS\System32\dlcjcomc.dll
[2006/08/09 14:52:48 | 00,413,696 | ---- | C] () -- C:\WINDOWS\System32\dlcjcomm.dll
[2006/08/09 14:52:48 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\dlcjcub.dll
[2006/08/09 14:52:48 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\dlcjcu.dll
[2006/08/09 14:52:48 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\dlcjcfg.dll
[2006/08/09 14:52:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2006/08/09 14:51:56 | 00,000,392 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/04/05 10:34:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/08/02 15:16:00 | 00,000,618 | ---- | C] () -- C:\WINDOWS\System32\dlcjplc.ini
[2004/08/10 14:12:05 | 00,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 13:57:41 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2004/08/10 13:51:28 | 00,000,603 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/10 13:51:26 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2004/08/10 13:51:06 | 00,061,952 | ---- | C] () -- C:\WINDOWS\System32\eventlog.dll
[2003/01/07 16:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/13 16:46:46 | 00,053,248 | R--- | C] () -- C:\WINDOWS\System32\zlib.dll
[2002/02/27 17:50:00 | 00,197,120 | ---- | C] () -- C:\WINDOWS\System32\patchw32.dll
========== LOP Check ==========
[2009/10/17 01:39:34 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Administrator\Application Data
[2009/10/17 01:46:30 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/03/13 18:26:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/10/17 00:07:15 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{3ADA1185-35A8-4B4E-B36B-6392B1DA8C26}
[2009/06/18 02:51:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/10/09 03:34:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\71509729
[2006/08/09 15:16:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/06/06 18:25:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2008/02/13 16:51:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell
[2009/10/10 03:34:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\gijeluhe
[2009/10/10 15:34:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kayufema
[2009/10/10 15:34:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pudaveya
[2009/07/29 20:55:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2009/10/10 15:34:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rolibisu
[2004/08/10 14:13:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2009/03/18 03:08:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2008/02/13 16:53:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/10/16 23:21:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/11/13 02:53:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/06/09 23:40:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/10/10 03:34:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\yufatisi
[2009/10/10 03:34:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\zuzofewe
[2009/10/16 17:52:31 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 06:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2004/08/10 13:51:06 | 00,000,004 | -HS- | M] () -- C:\WINDOWS\Tasks\FOLDER.TSX
[2009/10/17 02:46:32 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2009/10/04 00:14:58 | 00,039,936 | ---- | M] () -- C:\anlqrvl.exe
[2009/10/04 00:14:46 | 00,005,632 | ---- | M] () -- C:\efbcmkj.exe
[2009/10/04 00:14:51 | 00,051,200 | ---- | M] () -- C:\ehrrg.exe
[2009/10/04 00:14:47 | 00,019,456 | ---- | M] () -- C:\erupquii.exe
[2009/10/04 00:14:55 | 00,189,841 | ---- | M] () -- C:\hufa.exe
[2005/10/31 11:56:00 | 00,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe
[2009/10/04 00:14:56 | 00,161,280 | ---- | M] (Microsoft Corporation) -- C:\vgvluqbu.exe
[2009/10/04 00:14:47 | 00,043,520 | ---- | M] () -- C:\vsoq.exe
< %systemroot%\system32\eventlog.dll >
[2008/04/13 20:11:53 | 00,061,952 | ---- | M] () -- C:\WINDOWS\system32\eventlog.dll
< %systemroot%\system32\scecli.dll >
[2008/04/13 20:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\netlogon.dll >
< %systemroot%\system32\cngaudit.dll >
< %systemroot%\system32\sceclt.dll >
< %systemroot%\ntelogon.dll >
< %systemroot%\system32\logevent.dll >
[2008/04/13 20:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\logevent.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >
Extra.txt
OTL Extras logfile created on: 10/17/2009 4:22:13 AM - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
509.98 Mb Total Physical Memory | 267.64 Mb Available Physical Memory | 52.48% Memory free
1.22 Gb Paging File | 1.05 Gb Available in Paging File | 86.08% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.70 Gb Total Space | 3.52 Gb Free Space | 6.67% Space Free | Partition Type: NTFS
Drive D: | 18.48 Gb Total Space | 8.31 Gb Free Space | 44.95% Space Free | Partition Type: NTFS
Drive E: | 487.84 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DANSROOM
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL -- File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- File not found
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Documents and Settings\All Users\Documents\LimeWire\LimeWire.exe" = C:\Documents and Settings\All Users\Documents\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
"C:\Program Files\Sierra On-Line\SIGSPat.exe" = C:\Program Files\Sierra On-Line\SIGSPat.exe:*:Enabled:SIGSPat -- (Havas Interactive)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- (America Online, Inc.)
"C:\Program Files\Steam\steamapps\nightwalker420\counter-strike\hl.exe" = C:\Program Files\Steam\steamapps\nightwalker420\counter-strike\hl.exe:*:Enabled:Half-Life Launcher -- (Valve)
"C:\Program Files\Azureus\Azureus.exe" = C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus -- File not found
"C:\Program Files\BitLord\BitLord.exe" = C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord -- File not found
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer -- (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- File not found
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"D:\iTunes\iTunes.exe" = D:\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer -- (Microsoft Corporation)
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" = C:\Program Files\Common Files\Real\Update_OB\realsched.exe:*:Enabled:realsched -- (RealNetworks, Inc.)
"C:\Documents and Settings\Dan Lennon\Local Settings\Temp\avp.exe" = C:\Documents and Settings\Dan Lennon\Local Settings\Temp\avp.exe:*:Enabled:avp -- File not found
"C:\Program Files\iPod\bin\iPodService.exe" = C:\Program Files\iPod\bin\iPodService.exe:*:Enabled:iPodService -- (Apple Inc.)
"C:\Program Files\McAfee.com\Agent\mcupdate.exe" = C:\Program Files\McAfee.com\Agent\mcupdate.exe:*:Enabled:McUpdate -- File not found
"C:\Program Files\McAfee\MSM\McSmtFwk.exe" = C:\Program Files\McAfee\MSM\McSmtFwk.exe:*:Enabled:McSmtFwk -- File not found
"C:\Documents and Settings\Dan Lennon\Local Settings\Temp\user.exe" = C:\Documents and Settings\Dan Lennon\Local Settings\Temp\user.exe:*:Enabled:user -- File not found
"C:\Documents and Settings\Dan Lennon\Local Settings\Temp\1774599388.exe" = C:\Documents and Settings\Dan Lennon\Local Settings\Temp\1774599388.exe:*:Enabled:1774599388 -- File not found
"C:\Documents and Settings\Dan Lennon\Local Settings\Temp\914784718.exe" = C:\Documents and Settings\Dan Lennon\Local Settings\Temp\914784718.exe:*:Enabled:914784718 -- File not found
"C:\Documents and Settings\Dan Lennon\Local Settings\Temp\debug.exe" = C:\Documents and Settings\Dan Lennon\Local Settings\Temp\debug.exe:*:Enabled:debug -- File not found
"C:\WINDOWS\system32\logon.scr" = C:\WINDOWS\system32\logon.scr:*:Enabled:logon -- (Microsoft Corporation)
"C:\Documents and Settings\Dan Lennon\Local Settings\Temp\3192422870.exe" = C:\Documents and Settings\Dan Lennon\Local Settings\Temp\3192422870.exe:*:Enabled:3192422870 -- File not found
"C:\Documents and Settings\Dan Lennon\Local Settings\Temp\csrss.exe" = C:\Documents and Settings\Dan Lennon\Local Settings\Temp\csrss.exe:*:Enabled:csrss -- File not found
"C:\Documents and Settings\Dan Lennon\Application Data\6398915029\6398915029.exe" = C:\Documents and Settings\Dan Lennon\Application Data\6398915029\6398915029.exe:*:Enabled:6398915029 -- File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0C2AF762-0565-4C91-9F55-B8B53BB82A38}" = Microsoft Office Accounting 2008 Equifax Addin
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F5BC8D3-3741-4542-AF00-51202A9FD357}" = VirIT eXplorer Lite
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD
"{270940EA-C235-40D9-B2AE-2D450356DF8E}" = Microsoft Office Accounting 2008
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{3248F0A8-6813-11D6-A77B-00B0D0150080}" = J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{427EDD3F-D12A-4DE5-9A36-AC4DE8EBC981}" = ActiveSpeed
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{5BF2B19D-9C79-492A-8969-F059F06A627F}" = Print to Fax
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{689E0AB3-50B2-4E5A-9DCE-6DA9F5BE1314}" = BlackBerry® Media Sync
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{8689A5F3-BEEC-407D-A6EB-B79F636229A3}" = Media Center Alarm Clock
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B06CC379-BA38-4572-9539-CDB0C544AA1E}" = BlackBerry Desktop Software 5.0
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}" = Microsoft Office Accounting 2008 PayPal Addin
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BF311797-7DE8-4770-B16A-6475434E03FB}" = 964plc32
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Search Assist
"{E33EAB77-A36A-4FBF-BB15-2BBF74C7A796}" = iPhoneBrowser
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}" = Microsoft Office Accounting 2008 Fixed Asset Manager
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"26D2C2C3-CF14-4ED7-B1FC-0BE64AFBA3B3" = Polar Bowler
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_6" = AIM 6
"Alarm_is1" = Alarm 2.0.1
"AntivirusPro_2010" = Antivirus Pro 2010
"AOL Instant Messenger" = AOL Instant Messenger
"BlackBerry_{B06CC379-BA38-4572-9539-CDB0C544AA1E}" = BlackBerry Desktop Software 5.0
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"CopySafe Plugin" = CopySafe Plugin
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Photo AIO Printer 964" = Dell Photo AIO Printer 964
"ERUNT_is1" = ERUNT 1.1j
"GM LS2 Interface_is1" = GM LS2 Interface 1.0.2.0
"Half-Life: Counter-Strike" = Half-Life: Counter-Strike
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8 Release Candidate 1
"LimeWire" = LimeWire PRO 4.14.10
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Office Accounting 2008" = Microsoft Office Accounting 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PokerStars" = PokerStars
"PROR" = Microsoft Office Professional 2007 Trial
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"Security Task Manager" = Security Task Manager 1.7h
"Steam" = Steam
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TweakNow RegCleaner Standard_is1" = TweakNow RegCleaner Standard
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"VirIT eXplorer Lite" = VirIT eXplorer Lite
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WildTangent CDA" = WildTangent Web Driver
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"winscp3_is1" = WinSCP 4.2.2 beta
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/16/2009 7:11:57 PM | Computer Name = DANSROOM | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 10/16/2009 7:12:03 PM | Computer Name = DANSROOM | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 10/16/2009 7:12:03 PM | Computer Name = DANSROOM | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 10/16/2009 7:46:16 PM | Computer Name = DANSROOM | Source = McLogEvent | ID = 5051
Description =
Error - 10/16/2009 7:46:16 PM | Computer Name = DANSROOM | Source = McLogEvent | ID = 5019
Description =
Error - 10/16/2009 8:51:51 PM | Computer Name = DANSROOM | Source = pctsSvc.exe | ID = 0
Description =
Error - 10/16/2009 11:52:19 PM | Computer Name = DANSROOM | Source = McLogEvent | ID = 5051
Description =
Error - 10/17/2009 12:08:15 AM | Computer Name = DANSROOM | Source = MsiInstaller | ID = 11719
Description = Product: VirIT eXplorer Lite -- Error 1719. The Windows Installer
Service could not be accessed. This can occur if you are running Windows in safe
mode, or if the Windows Installer is not correctly installed. Contact your support
personnel for assistance.
Error - 10/17/2009 1:22:17 AM | Computer Name = DANSROOM | Source = MsiInstaller | ID = 11321
Description = Product: VirIT eXplorer Lite -- Error 1321. The Installer has insufficient
privileges to modify this file: C:\VeXpLite\MONLITE.exe.
Error - 10/17/2009 1:22:22 AM | Computer Name = DANSROOM | Source = MsiInstaller | ID = 11321
Description = Product: VirIT eXplorer Lite -- Error 1321. The Installer has insufficient
privileges to modify this file: C:\VeXpLite\viritexp.exe.
[ System Events ]
Error - 10/17/2009 3:55:07 AM | Computer Name = DANSROOM | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 10/17/2009 3:55:10 AM | Computer Name = DANSROOM | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 10/17/2009 3:55:43 AM | Computer Name = DANSROOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 10/17/2009 3:57:47 AM | Computer Name = DANSROOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 10/17/2009 3:58:07 AM | Computer Name = DANSROOM | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm mfehidk
Error - 10/17/2009 4:20:01 AM | Computer Name = DANSROOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 10/17/2009 4:22:34 AM | Computer Name = DANSROOM | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 10/17/2009 4:22:37 AM | Computer Name = DANSROOM | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 10/17/2009 4:22:39 AM | Computer Name = DANSROOM | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 10/17/2009 4:22:43 AM | Computer Name = DANSROOM | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
< End of report >