Virtumonde Removal - JF - Info 8.2
**********
info.txt generated by RSIT.exe
**********
info.txt logfile of random's system information tool 1.05 2009-02-02 15:09:41
======Uninstall list======
-->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
-->C:\WINDOWS\System32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{410438A3-B591-4028-B70A-3CC0B33FBCD1}\Setup.exe" -l0x9 -L0x9anything
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
2Wire Wireless Client-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}\Setup.exe" -l0x9 -L0x9
Adobe Atmosphere Player for Acrobat and Adobe Reader-->C:\WINDOWS\atmoUn.exe
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.8-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
BCM V.92 56K Modem-->C:\WINDOWS\BCMSMU.exe quiet
Bejeweled Deluxe 1.6z-->C:\Program Files\Zone.Com Deluxe Games\Bejeweled\UnGins.exe "C:\Program Files\Zone.Com Deluxe Games\Bejeweled\install.log"
Belkin 54g USB Network Adapter-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Belkin\Belkin Wireless Network Utility\setup.exe" -l0x9
Bespelled Deluxe 1.01-->C:\Program Files\Zone.Com Deluxe Games\Bespelled Deluxe\PopUninstall.exe "C:\Program Files\Zone.Com Deluxe Games\Bespelled Deluxe\Install.log"
Catan (remove only)-->"C:\Program Files\Yahoo! Games\Catan\Uninstall.exe"
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Citrix Endpoint Analysis Client-->MsiExec.exe /I{1C582795-778E-4B5D-AE85-518450431F28}
Citrix Presentation Server Client - Web Only-->MsiExec.exe /X{23E8D2D6-F7C8-4A35-816C-6C914EE0A601}
Dell Digital Jukebox Driver-->C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
Dell Media Experience-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\setup.exe" -uninstall
Dell Solution Center-->MsiExec.exe /X{11F1920A-56A2-4642-B6E0-3B31A12C9288}
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter-->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DS21Patch-->MsiExec.exe /I{9B79DCB0-AAD7-456B-8D07-433C936FA24B}
DVDSentry-->MsiExec.exe /I{98DF85D9-96C0-4F57-A92E-C3539477EF5E}
Easy CD Creator 5 Basic-->MsiExec.exe /I{609F7AC8-C510-11D4-A788-009027ABA5D0}
EPSON Printer Software-->C:\Program Files\EPSON\PrinterDriverTemp\SCX7400\EPUPDATE.EXE /r
ERUNT 1.1j-->"C:\Program Files\ERUNT\unins000.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Intel(R) Extreme Graphics 2 Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
Intel(R) PRO Network Adapters and Drivers-->Prounstl.exe
Intel(R) PROSet-->MsiExec.exe /I{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}
Internet Explorer Default Page-->MsiExec.exe /I{35BDEFF1-A610-4956-A00D-15453C116395}
iTunes-->MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
Java(TM) 6 Update 10-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
LogViewer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5090856-6E87-4AE1-B6FE-DD4149CB097A}\Setup.exe" -l0x9
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Maxtor OneTouch-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{231F68F4-70E4-41A6-BEDA-7E7934169B54} /l1033
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Data Access Components KB870669-->C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Encarta Encyclopedia Standard 2004-->MsiExec.exe /I{04410044-9149-45C6-A806-F2BF9CFCE762}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 SR-1 Disc 2-->MsiExec.exe /I{00040409-78E1-11D2-B60F-006097C998E7}
Microsoft Office 2000 SR-1 Professional-->MsiExec.exe /I{00010409-78E1-11D2-B60F-006097C998E7}
Microsoft Project 2000-->MsiExec.exe /I{2DFE1608-BDCA-11D1-B7AE-00C04FB92F3D}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Modem Helper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
MSN Music Assistant-->rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,Uninstall
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
Retrospect Express HD 1.1-->MsiExec.exe /I{A4952AA3-FCBF-4D28-9DC4-A3935FDC5805}
Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Shockwave-->C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\Install.log
Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Sonic MyDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5E835305-63BB-4E55-BBB7-EEBBE67774DB}\setup.exe" -l0x9 -L0x9 /SMAINT
Sonic Update Manager-->MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
SoundTaxi 3.2.0-->"C:\Program Files\SoundTaxi\unins000.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
USB Storage Adapter FX (MXO)-->MXOun.exe MXOFX
Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WNW Five Language Dictionary v1.9-->C:\WINDOWS\uninst.exe -f"C:\Program Files\Accent\WNWFLD\DeIsL1.isu"
=====HijackThis Backups=====
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\jukihoda.dll",s (User 'NETWORK SERVICE')
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\jukihoda.dll",s
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\pazozezu.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\noyajego.dll",a
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: c:\windows\system32\lijeyehi.dll C:\WINDOWS\system32\behipaya.dll c:\windows\system32\modigege.dll c:\windows\system32\dukovolo.dll c:\windows\system32\noyajego.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: rundisk - C:\WINDOWS\msagent\rundisk.dll (file missing)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\noyajego.dll
O23 - Service: SoundMovieServer - SoundMovieServer - C:\WINDOWS\system32\snmvtsvc.exe
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\noyajego.dll
O4 - HKLM\..\RunOnce: [SpybotDeletingA4610] command /c del "c:\windows\system32\noyajego.dll_old"
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\noyajego.dll (file missing)
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\jukihoda.dll",s
O4 - HKLM\..\RunOnce: [SpybotDeletingC2487] cmd /c del "c:\windows\system32\noyajego.dll_old"
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\noyajego.dll (file missing)
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\noyajego.dll",a
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\jukihoda.dll",s (User 'NETWORK SERVICE')
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\pazozezu.dll (file missing)
O4 - HKUS\S-1-5-19\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\jukihoda.dll",s (User 'LOCAL SERVICE')
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\pazozezu.dll (file missing)
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\jukihoda.dll",s
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\jukihoda.dll",s (User 'NETWORK SERVICE')
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\behipaya.dll c:\windows\system32\noyajego.dll
O4 - HKUS\S-1-5-19\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\jukihoda.dll",s (User 'LOCAL SERVICE')
O4 - HKLM\..\Run: [34b6b524] rundll32.exe "C:\WINDOWS\system32\kifupiza.dll",b
O20 - AppInit_DLLs: c:\windows\system32\muzupera.dll,C:\WINDOWS\system32\zajifali.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\lakutufo.dll
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\muzupera.dll",a
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\garopudu.dll",s (User 'NETWORK SERVICE')
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\muzupera.dll
O4 - HKUS\S-1-5-19\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\garopudu.dll",s (User 'LOCAL SERVICE')
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\garopudu.dll",s
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\garopudu.dll",s
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\lakutufo.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O20 - AppInit_DLLs: c:\windows\system32\muzupera.dll,C:\WINDOWS\system32\zajifali.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\muzupera.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\muzupera.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\garopudu.dll",s
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\muzupera.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\lakutufo.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\muzupera.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\muzupera.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\vobulofo.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s
O4 - HKUS\S-1-5-19\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'LOCAL SERVICE')
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O4 - HKLM\..\Run: [34b6b524] rundll32.exe "C:\WINDOWS\system32\fozisitu.dll",b
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'NETWORK SERVICE')
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) -
http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://picasaweb.google.com/s/v/42.20/uploader2.cab
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) -
http://zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\godojuje.dll c:\windows\system32\numagitu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab56649.cab
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\vobulofo.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\godojuje.dll
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'NETWORK SERVICE')
O20 - AppInit_DLLs: c:\windows\system32\numagitu.dll,C:\WINDOWS\system32\godojuje.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O4 - HKUS\S-1-5-19\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'LOCAL SERVICE')
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\vobulofo.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\vobulofo.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\vobulofo.dll
O20 - AppInit_DLLs: c:\windows\system32\numagitu.dll,C:\WINDOWS\system32\godojuje.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'NETWORK SERVICE')
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O20 - AppInit_DLLs: c:\windows\system32\numagitu.dll,C:\WINDOWS\system32\godojuje.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - (no file)
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'NETWORK SERVICE')
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\godojuje.dll c:\windows\system32\numagitu.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\vobulofo.dll (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\system32\godojuje.dll c:\windows\system32\numagitu.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\vobulofo.dll (file missing)
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'NETWORK SERVICE')
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\vobulofo.dll (file missing)
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'NETWORK SERVICE')
O20 - AppInit_DLLs: C:\WINDOWS\system32\godojuje.dll c:\windows\system32\numagitu.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\vobulofo.dll (file missing)
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'NETWORK SERVICE')
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKUS\S-1-5-19\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\japawisi.dll",s (User 'LOCAL SERVICE')
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\godojuje.dll c:\windows\system32\numagitu.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\numagitu.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\numagitu.dll",a
O4 - HKLM\..\Run: [34b6b524] rundll32.exe "C:\WINDOWS\system32\hozekopo.dll",b
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\dehokiju.dll",a
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\meseleru.dll",s
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\zawibavu.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\tatetimo.dll c:\windows\system32\dehokiju.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\dehokiju.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\dehokiju.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\dehokiju.dll",a
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\meseleru.dll",s
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\dehokiju.dll",a
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\dehokiju.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\dehokiju.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\meseleru.dll",s
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\zawibavu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\petonuho.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\petonuho.dll
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\RETROS~1\RETROS~1.1\RetroExpress.exe /h
O20 - AppInit_DLLs: C:\WINDOWS\system32\tatetimo.dll c:\windows\system32\petonuho.dll
O4 - HKLM\..\Run: [34b6b524] rundll32.exe "C:\WINDOWS\system32\miperuwo.dll",b
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "C:\WINDOWS\system32\petonuho.dll",a
O2 - BHO: (no name) - {4aafb203-85e3-4d13-94c7-a91cebdfa541} - C:\WINDOWS\system32\zawibavu.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\tatetimo.dll",s (User 'NETWORK SERVICE')
O2 - BHO: (no name) - {68a4dd92-70c3-46bb-bfb2-e6356fa0e920} - C:\WINDOWS\system32\zawibavu.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\petonuho.dll",a
O2 - BHO: (no name) - {dad410d7-a405-40bb-b4f0-12640db0845b} - C:\WINDOWS\system32\zawibavu.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\tatetimo.dll",s
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\petonuho.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\petonuho.dll
O2 - BHO: (no name) - {dad410d7-a405-40bb-b4f0-12640db0845b} - C:\WINDOWS\system32\zawibavu.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\tatetimo.dll",s
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\petonuho.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\petonuho.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\petonuho.dll",a
O20 - AppInit_DLLs: c:\windows\system32\petonuho.dll,C:\WINDOWS\system32\tatetimo.dll,C:\WINDOWS\system32\zawibavu.dll
O2 - BHO: (no name) - {68a4dd92-70c3-46bb-bfb2-e6356fa0e920} - C:\WINDOWS\system32\zawibavu.dll
O2 - BHO: (no name) - {dad410d7-a405-40bb-b4f0-12640db0845b} - C:\WINDOWS\system32\zawibavu.dll
O2 - BHO: (no name) - {68a4dd92-70c3-46bb-bfb2-e6356fa0e920} - C:\WINDOWS\system32\zawibavu.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\tatetimo.dll",s
O2 - BHO: (no name) - {dad410d7-a405-40bb-b4f0-12640db0845b} - C:\WINDOWS\system32\zawibavu.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\tatetimo.dll",s (User 'NETWORK SERVICE')
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\goriwesi.dll
O4 - HKLM\..\Run: [34b6b524] rundll32.exe "C:\WINDOWS\system32\walumure.dll",b
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\goriwesi.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\zawibavu.dll c:\windows\system32\goriwesi.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\goriwesi.dll",a
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\goriwesi.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O20 - AppInit_DLLs: c:\windows\system32\goriwesi.dll,C:\WINDOWS\system32\zawibavu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\goriwesi.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\yogaguse.dll",s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O2 - BHO: (no name) - {2739d1ee-015e-49bb-bdc7-6af645f433fb} - C:\WINDOWS\system32\tatetimo.dll (file missing)
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "C:\WINDOWS\system32\hiresawo.dll",a
O2 - BHO: (no name) - {dad410d7-a405-40bb-b4f0-12640db0845b} - C:\WINDOWS\system32\zawibavu.dll (file missing)
O2 - BHO: {30bc6a48-437d-ac3a-e224-61ed269c48ac} - {ca84c962-de16-422e-a3ca-d73484a6cb03} - C:\WINDOWS\system32\ffylxp.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\yogaguse.dll",s (User 'NETWORK SERVICE')
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\hihidewa.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) -
http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) -
http://sympatico.zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) -
http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) -
http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hohunowi.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\webayodi.dll C:\WINDOWS\system32\demazabu.dll c:\windows\system32\hohunowi.dll ffylxp.dll c:\windows\system32\hiresawo.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hohunowi.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hohunowi.dll
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\hihidewa.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\yogaguse.dll",s
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\hiresawo.dll",a
O20 - AppInit_DLLs: C:\WINDOWS\system32\webayodi.dll c:\windows\system32\hiresawo.dll c:\windows\system32\hohunowi.dll,C:\WINDOWS\system32\demazabu.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hohunowi.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\yogaguse.dll",s (User 'NETWORK SERVICE')
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\hohunowi.dll",a
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\hihidewa.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\yogaguse.dll",s
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hohunowi.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hohunowi.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\demazabu.dll c:\windows\system32\hohunowi.dll c:\windows\system32\hiresawo.dll,C:\WINDOWS\system32\webayodi.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hiresawo.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\demazabu.dll c:\windows\system32\hiresawo.dll c:\windows\system32\hohunowi.dll,C:\WINDOWS\system32\webayodi.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\hiresawo.dll",a
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\yogaguse.dll",s
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\hihidewa.dll (file missing)
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\yogaguse.dll",s (User 'NETWORK SERVICE')
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hiresawo.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [34b6b524] rundll32.exe "C:\WINDOWS\system32\gezehewi.dll",b
O2 - BHO: {19a553f5-242f-5998-a534-ca2290cf2403} - {3042fc09-22ac-435a-8995-f2425f355a91} - C:\WINDOWS\system32\nhbdmj.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'NETWORK SERVICE')
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\rerutemi.dll",a
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKUS\S-1-5-19\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'LOCAL SERVICE')
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\volefijo.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bufazuwa.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bufazuwa.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\demazabu.dll C:\WINDOWS\system32\pusukupu.dll nhbdmj.dll c:\windows\system32\sojomazi.dll c:\windows\system32\bufazuwa.dll c:\windows\system32\rerutemi.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\rerutemi.dll",a
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\volefijo.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sojomazi.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sojomazi.dll
O20 - AppInit_DLLs: c:\windows\system32\rerutemi.dll c:\windows\system32\sojomazi.dll c:\windows\system32\bufazuwa.dll,C:\WINDOWS\system32\pusukupu.dll
O20 - AppInit_DLLs: c:\windows\system32\rerutemi.dll c:\windows\system32\sojomazi.dll c:\windows\system32\bufazuwa.dll
O4 - HKUS\S-1-5-19\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'LOCAL SERVICE')
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\rerutemi.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'NETWORK SERVICE')
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\rerutemi.dll
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\volefijo.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'NETWORK SERVICE')
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\ketahope.dll",a
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\pusukupu.dll C:\WINDOWS\system32\demazabu.dll mskqmb.dll c:\windows\system32\ketahope.dll
O2 - BHO: {b8855a48-ad5a-863b-71a4-b1350bf741aa} - {aa147fb0-531b-4a17-b368-a5da84a5588b} - C:\WINDOWS\system32\mskqmb.dll (file missing)
O4 - HKUS\S-1-5-19\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'LOCAL SERVICE')
O4 - HKLM\..\Run: [34b6b524] rundll32.exe "C:\WINDOWS\system32\hafurive.dll",b
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\ketahope.dll",a
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\volefijo.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s
O20 - AppInit_DLLs: C:\WINDOWS\system32\demazabu.dll c:\windows\system32\ketahope.dll,C:\WINDOWS\system32\pusukupu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'NETWORK SERVICE')
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\volefijo.dll (file missing)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\ketahope.dll",a
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\demazabu.dll c:\windows\system32\ketahope.dll,C:\WINDOWS\system32\pusukupu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\demazabu.dll c:\windows\system32\ketahope.dll,C:\WINDOWS\system32\pusukupu.dll
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\volefijo.dll (file missing)
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\ketahope.dll",a
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'NETWORK SERVICE')
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'NETWORK SERVICE')
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\ketahope.dll",a
O2 - BHO: (no name) - {7b007856-d60e-48c5-9d66-34b8f6707519} - C:\WINDOWS\system32\demazabu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\volefijo.dll (file missing)
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\mijekozu.dll",s (User 'NETWORK SERVICE')
O2 - BHO: (no name) - {7b007856-d60e-48c5-9d66-34b8f6707519} - C:\WINDOWS\system32\demazabu.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\pusukupu.dll c:\windows\system32\ketahope.dll,C:\WINDOWS\system32\demazabu.dll
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\volefijo.dll (file missing)
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\ketahope.dll",a
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\pusukupu.dll",s
O2 - BHO: (no name) - {7b007856-d60e-48c5-9d66-34b8f6707519} - C:\WINDOWS\system32\pusukupu.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\pusukupu.dll",s (User 'NETWORK SERVICE')
O2 - BHO: (no name) - {4036c1d8-1f5a-418d-b068-d9c7ede3a9e6} - C:\WINDOWS\system32\volefijo.dll (file missing)
O2 - BHO: (no name) - {fced0176-4c2d-4601-82a0-fe889444e8df} - C:\WINDOWS\system32\demazabu.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\System32\shdocvw.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\ketahope.dll",a
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O20 - AppInit_DLLs: c:\windows\system32\ketahope.dll,C:\WINDOWS\system32\pusukupu.dll,C:\WINDOWS\system32\demazabu.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab56649.cab
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\System32\shdocvw.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\pusukupu.dll c:\windows\system32\ketahope.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\pusukupu.dll c:\windows\system32\ketahope.dll
O4 - HKUS\S-1-5-20\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\pusukupu.dll",s (User 'NETWORK SERVICE')
O2 - BHO: (no name) - {a05e4245-b426-4564-9c11-93c1e80eb34a} - C:\WINDOWS\system32\demazabu.dll
O4 - HKLM\..\Run: [hedohiruda] Rundll32.exe "C:\WINDOWS\system32\demazabu.dll",s
O2 - BHO: (no name) - {fced0176-4c2d-4601-82a0-fe889444e8df} - C:\WINDOWS\system32\demazabu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\ketahope.dll
O4 - HKLM\..\Run: [CPM378586b8] Rundll32.exe "c:\windows\system32\ketahope.dll",a
======Security center information======
AV: Avira AntiVir PersonalEdition (disabled)
System event log
Computer Name: LINUS
Event Code: 7036
Message: The Background Intelligent Transfer Service service entered the running state.
Record Number: 1610
Source Name: Service Control Manager
Time Written: 20080620031506.000000-420
Event Type: information
User:
Computer Name: LINUS
Event Code: 7035
Message: The Background Intelligent Transfer Service service was successfully sent a start control.
Record Number: 1609
Source Name: Service Control Manager
Time Written: 20080620031506.000000-420
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: LINUS
Event Code: 7036
Message: The iPod Service service entered the running state.
Record Number: 1608
Source Name: Service Control Manager
Time Written: 20080620031029.000000-420
Event Type: information
User:
Computer Name: LINUS
Event Code: 7035
Message: The iPod Service service was successfully sent a start control.
Record Number: 1607
Source Name: Service Control Manager
Time Written: 20080620031029.000000-420
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: LINUS
Event Code: 7036
Message: The Computer Browser service entered the stopped state.
Record Number: 1606
Source Name: Service Control Manager
Time Written: 20080620031013.000000-420
Event Type: information
User:
Application event log
Computer Name: D2R31441
Event Code: 1004
Message: Detection of product '{00010409-78E1-11D2-B60F-006097C998E7}', feature 'ProductNonBootFiles', component '{4A31E933-6F67-11D2-AAA2-00A0C90F57B0}' failed. The resource 'HKEY_CURRENT_USER\Software\ODBC\ODBC.INI\MS Access Database\' does not exist.
Record Number: 9382
Source Name: MsiInstaller
Time Written: 20071031205642.000000-420
Event Type: warning
User: LINUS\Bob
Computer Name: D2R31441
Event Code: 11729
Message: Product: Microsoft Office 2000 SR-1 Professional -- Configuration failed.
Record Number: 9381
Source Name: MsiInstaller
Time Written: 20071031205305.000000-420
Event Type: information
User: LINUS\Bob
Computer Name: D2R31441
Event Code: 1001
Message: Detection of product '{00010409-78E1-11D2-B60F-006097C998E7}', feature 'ProductNonBootFiles' failed during request for component '{7AB02DE0-B463-11D1-96C4-0080C728108A}'
Record Number: 9380
Source Name: MsiInstaller
Time Written: 20071031205302.000000-420
Event Type: warning
User: LINUS\Bob
Computer Name: D2R31441
Event Code: 1004
Message: Detection of product '{00010409-78E1-11D2-B60F-006097C998E7}', feature 'ProductNonBootFiles', component '{4A31E933-6F67-11D2-AAA2-00A0C90F57B0}' failed. The resource 'HKEY_CURRENT_USER\Software\ODBC\ODBC.INI\MS Access Database\' does not exist.
Record Number: 9379
Source Name: MsiInstaller
Time Written: 20071031205302.000000-420
Event Type: warning
User: LINUS\Bob
Computer Name: D2R31441
Event Code: 11729
Message: Product: Microsoft Office 2000 SR-1 Professional -- Configuration failed.
Record Number: 9378
Source Name: MsiInstaller
Time Written: 20071031205002.000000-420
Event Type: information
User: LINUS\Bob
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Common Files\Sonic Shared;C:\Program Files\Common Files\Adaptec Shared\System;C:\Program Files\QuickTime\QTSystem
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_04\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_04\lib\ext\QTJava.zip
-----------------EOF-----------------
**********
Phew. That's a lot of information.