Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unknown Virus


  • This topic is locked This topic is locked
23 replies to this topic

#1 lol999

lol999

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Texas, USA
  • Local time:11:33 PM

Posted 16 October 2008 - 08:02 PM

I was requested to enter a HijackThis log here. My situation is that I can't open executables files except for Internet Explorer and Microsoft Office. I have to rename files to EXCEL.exe to run them. I have used MalwareBytes Anti-Malware. With no succes of removing it, except that it allowed me to use Task Manager.

The following link is the topic I originally posted in:
http://www.bleepingcomputer.com/forums/t/174646/restricted-access/

HIJACKTHIS LOG:
==============================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:55:00 PM, on 10/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\excel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {CC08F073-6F7D-462B-91C8-F9FAFF3FC14C} - C:\WINDOWS\system32\mlljg.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [vjag] C:\WINDOWS\system32\auto\vjag3.bat
O4 - HKLM\..\Run: [vjag2] C:\WINDOWS\system32\auto\vjag.vbs
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Microsoft Office Outlook 2007.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BBFD2D10-EC6E-4259-91D1-1E38C826E5E2} (Launcher Class) - http://app.gomtv.com/gomtv/gomtvx.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: cbxxutt - C:\WINDOWS\
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXlm server for PTC - Macrovision Corporation - C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 10534 bytes
==============================================

BC AdBot (Login to Remove)

 


m

#2 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:05:33 AM

Posted 17 October 2008 - 07:49 AM

Hi lol999,

Welcome to BC HijackThis forum and sorry for the delay. I am farbar. I am going to assist you with your problem.

Please refrain from making any changes to your system (updating Windows, installing applications, removing files, etc.) from now on as it might prolong handling your log and make the job for both of us more difficult.


Each time you rename a tool please inform me about that in your reply and give me feedback as detailed as possible.
  • Tell me:
    • If you have done anything since previous post.
    • If this is the only computer or you have another computer we can eventually use.
    • If you have a Windows installation CD. Not that we need it now, just in case.
  • Please set your system to show file extensions:
    • Click Start, open Computer, select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Uncheck: Hide file extensions for known file types
  • Please download the attached regexport2.bat and run it. Post the content of the log (Export.txt)it produces. If it did not run rename it to look.com and tell me if you needed to rename it.

  • Download Deckard's Association File Tool daft.exe and save it to your desktop.
    • Double click on it and click Run. (if it did not run rename it to asso.com and tell me if it was needed to rename it)
    • Click on the Scan button.
    • If it finds faulty file associations, they will appear in red beside a checkbox
    • Click Save Log and save daft.txt
    • Copy and paste the content of daft.txt to your reply.
  • Please visit URL=http://www.billsway.com/vbspage/.
    • Scroll down the page to "Registry Search Tool".
    • Download RegSrch.zip and extract it to your desktop.
    • Doubleclick RegSrch.vbs to run the program.
    • Copy/paste in the search window:
      DisableCMD
    • After the search is done a WordPad opens with a report.
    • Copy and paste the content of the report to your reply.
  • Please open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below (if present):

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {CC08F073-6F7D-462B-91C8-F9FAFF3FC14C} - C:\WINDOWS\system32\mlljg.dll (file missing)
    O4 - HKLM\..\Run: [vjag] C:\WINDOWS\system32\auto\vjag3.bat
    O4 - HKLM\..\Run: [vjag2] C:\WINDOWS\system32\auto\vjag.vbs
    O20 - Winlogon Notify: cbxxutt - C:\WINDOWS\


    Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis. Then reboot your computer.

  • Using Windows Explorer (right-click start > Explorer) navigate to the following folder:C"\Program Files\Malwarebyte' Anti-Malware
    • Locate the file mbam.exe and rename it to clear.com then double-click to run it.
    • Wait until it opens up.
    • Update it. When you get the message that it is updated successfully check under Update tab the Database version should read 1276.
    • Run a quick scan. Let it remove what it finds, let reboot if needed and copy/paste the log to your reply.
  • Please download OTViewIt by OldTimer.
    • Save it to your desktop.
    • Double click on the OTViewIt icon on your desktop.
    • Click the "Scan All Users" checkbox.
    • Set File age to 60 days.
    • Type in the Custom Scans section: hijackthisbackups
    • Click Run Scan button.
    • Two reports will open, copy and paste them to your reply:
    • OTViewIt.txt <-- Will be opened
    • Extra.txt <-- Will be minimized

Please copy/paste in your next reply:
  • Answer to the questions.
  • The content of Export.txt
  • The content of daft.txt
  • The log of MBAM.
  • Both the OTViewIt logs.
Edited: Forgot to attach the batch file.

Edited by farbar, 17 October 2008 - 08:12 AM.


#3 lol999

lol999
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Texas, USA
  • Local time:11:33 PM

Posted 17 October 2008 - 04:03 PM

Hi Farbar,

Thanks for the welcome.

Tell me:

  • If you have done anything since previous post.
  • If this is the only computer or you have another computer we can eventually use.
  • If you have a Windows installation CD. Not that we need it now, just in case.

  • I haven't uninstalled or installed anything since last post.
  • I do have access to other computers.
  • No, I don't have a Windows installation CD

  • Please set your system to show file extensions...

  • Done

  • Please download the attached regexport2.bat and run it. Post the content of the log (Export.txt)it produces. If it did not run rename it to look.com and tell me if you needed to rename it...

  • I had no luck opening this file, renamed to look.com and still no luck. It seems I can only open "excel.exe". However naming this file to that doesn't work.

  • Download Deckard's Association File Tool daft.exe and save it to your desktop...

  • I did run this scan, but as said previously I had to rename it to excel.exe. Naming it Asso.com didn't work nor running it as daft.exe. The log is the following:
=============================
DAFT Log saved on 2008-10-17 15:09:19
-----------------------------------------------------------------------
All associations okay!
=============================

  • Please visit URL=http://www.billsway.com/vbspage/...

  • Couldn't open the zip file, no matter how I renamed it.

  • Please open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below (if present):
  • O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
  • O2 - BHO: (no name) - {CC08F073-6F7D-462B-91C8-F9FAFF3FC14C} - C:\WINDOWS\system32\mlljg.dll (file missing)
  • O4 - HKLM\..\Run: [vjag] C:\WINDOWS\system32\auto\vjag3.bat
  • O4 - HKLM\..\Run: [vjag2] C:\WINDOWS\system32\auto\vjag.vbs
  • O20 - Winlogon Notify: cbxxutt - C:\WINDOWS\

  • Done

  • Using Windows Explorer (right-click start > Explorer) navigate to the following folder:C"\Program Files\Malwarebyte' Anti-Malware...

  • Once again I had to rename mbam.exe to excel.exe. Here is the log.
========================
Malwarebytes' Anti-Malware 1.28
Database version: 1276
Windows 5.1.2600 Service Pack 3

10/17/2008 3:27:16 PM
mbam-log-2008-10-17 (15-27-16).txt

Scan type: Quick Scan
Objects scanned: 77121
Time elapsed: 7 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
========================

  • Please download OTViewIt by OldTimer...

  • I renamed OTViewIt.exe to excel.exe, and ran the scan as told. Here are the logs:
========================
OTViewIt logfile created on: 10/17/2008 3:23:04 PM - Run
OTViewIt by OldTimer - Version 1.0.15.0 Folder = C:\Documents and Settings\James\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.41 Gb Available Physical Memory | 70.64% Memory free
3.85 Gb Paging File | 3.36 Gb Available in Paging File | 87.15% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 139.73 Gb Total Space | 28.39 Gb Free Space | 20.32% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RAWR
Current User Name: James
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 60 Days

========== Processes ==========

[2008/07/17 22:36:20 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
[2008/04/13 19:12:33 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
[2005/05/05 01:53:00 | 00,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
[2008/08/14 20:05:30 | 00,149,761 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
[2006/07/25 19:03:42 | 00,100,032 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
[2007/11/20 22:18:30 | 01,294,336 | ---- | M] (Macrovision Corporation) -- C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
[2007/11/20 22:18:30 | 01,294,336 | ---- | M] (Macrovision Corporation) -- C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
[2006/06/19 14:01:52 | 00,688,190 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\system32\lkcitdl.exe
[2006/07/25 17:28:02 | 00,045,056 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\system32\lkads.exe
[2006/07/25 17:28:10 | 00,057,344 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\system32\lktsrv.exe
[2005/07/27 12:53:00 | 00,536,576 | ---- | M] () -- C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe
[2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
[2005/10/14 05:51:45 | 28,768,528 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
[2005/08/11 19:21:16 | 00,864,256 | ---- | M] (The MathWorks Inc.) -- C:\Program Files\MATLAB71\bin\win32\MATLAB.exe
[2006/07/15 19:47:00 | 00,005,728 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\MAX\nimxs.exe
[2006/07/25 17:28:16 | 00,200,704 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
[2006/02/06 16:46:42 | 00,049,152 | ---- | M] (National Instruments Corp.) -- C:\WINDOWS\system32\nisvcloc.exe
[2006/07/25 17:36:40 | 00,696,320 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
[2007/01/08 09:33:26 | 00,118,784 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
[2004/09/29 13:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
[2008/04/24 01:04:00 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe
[2007/02/10 05:29:56 | 00,089,968 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
[2007/01/25 05:46:14 | 01,174,152 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
[2008/08/23 00:56:15 | 00,635,848 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2008/04/13 19:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
[2008/09/10 00:07:16 | 01,253,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\excel.exe
[2008/04/13 19:12:40 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
[2008/10/17 15:19:56 | 00,421,888 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\James\Desktop\excel.exe

========== (O23) Win32 Services ==========

[2005/05/05 01:53:00 | 00,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe -- (ACS [Auto | Running])
[2008/07/17 22:36:20 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler [Auto | Running])
[2008/08/14 20:05:30 | 00,149,761 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService [Auto | Running])
[2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2006/07/25 19:03:42 | 00,100,032 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler [Auto | Running])
[2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2007/11/20 22:18:30 | 01,294,336 | ---- | M] (Macrovision Corporation) -- C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe -- (FLEXlm server for PTC [Auto | Running])
[2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2006/07/25 19:03:42 | 02,119,360 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -- (LiveUpdate [On_Demand | Stopped])
[2006/06/19 14:01:52 | 00,688,190 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\system32\lkcitdl.exe -- (LkCitadelServer [Auto | Running])
[2006/07/25 17:28:02 | 00,045,056 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\system32\lkads.exe -- (lkClassAds [Auto | Running])
[2006/07/25 17:28:10 | 00,057,344 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\system32\lktsrv.exe -- (lkTimeSync [Auto | Running])
[2005/07/27 12:53:00 | 00,536,576 | ---- | M] () -- C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe -- (matlabserver [Auto | Running])
[2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
[2007/08/24 06:59:20 | 00,068,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
[2002/12/17 17:26:22 | 07,520,337 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR [On_Demand | Stopped])
[2005/10/14 05:51:45 | 28,768,528 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS [Auto | Running])
[2005/10/14 05:50:19 | 00,045,272 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper [Disabled | Stopped])
[2006/10/26 13:45:00 | 02,799,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80 [Disabled | Stopped])
[2006/07/15 19:47:00 | 00,005,728 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\MAX\nimxs.exe -- (mxssvr [Auto | Running])
[2006/07/25 17:28:16 | 00,200,704 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService [Auto | Running])
[2006/06/27 19:55:28 | 01,007,616 | ---- | M] (Macrovision Corporation) -- C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager [On_Demand | Stopped])
[2006/02/06 16:46:42 | 00,049,152 | ---- | M] (National Instruments Corp.) -- C:\WINDOWS\system32\nisvcloc.exe -- (niSvcLoc [Auto | Running])
[2006/07/25 17:36:40 | 00,696,320 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe -- (NITaggerService [Auto | Running])
[2007/01/08 09:33:26 | 00,118,784 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService [Auto | Running])
[2006/12/21 12:29:00 | 00,168,004 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Stopped])
[2007/08/24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
[2004/12/02 08:28:32 | 00,098,304 | ---- | M] (OPC Foundation) -- C:\WINDOWS\system32\Opcenum.exe -- (OpcEnum [On_Demand | Stopped])
[2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2004/09/29 13:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
[2008/04/24 01:04:00 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
[2007/11/06 15:22:26 | 00,092,792 | ---- | M] (CACE Technologies) -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd [On_Demand | Stopped])
[2002/12/17 17:23:30 | 00,311,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR [On_Demand | Stopped])
[2005/10/14 05:51:12 | 00,239,320 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Disabled | Stopped])
[2007/02/10 05:29:56 | 00,089,968 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [Auto | Running])
[2007/01/25 05:46:14 | 01,174,152 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC [Auto | Running])
[2007/01/19 13:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
[2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services ==========

[2008/04/20 01:55:27 | 00,017,801 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP [Auto | Running])
[2007/02/27 15:25:01 | 00,011,840 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys -- (avgio [System | Running])
[2008/05/30 13:35:04 | 00,052,032 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys -- (avgntflt [On_Demand | Running])
[2008/07/17 22:36:21 | 00,075,072 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb [System | Running])
[2007/12/08 04:32:45 | 00,141,824 | ---- | M] () -- C:\WINDOWS\catchme.exe -- (catchme [On_Demand | Stopped])
[2005/01/10 10:15:24 | 00,138,752 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k [On_Demand | Running])
[2006/07/27 10:00:00 | 00,004,096 | ---- | M] () -- C:\WINDOWS\System32\drivers\cvintdrv.sys -- (cvintdrv [Auto | Running])
[2007/09/27 06:52:16 | 00,007,168 | ---- | M] (MPlayer <http://svn.mplayerhq.hu/mplayer/trunk/vidix/dhahelperwin/>) -- C:\WINDOWS\system32\drivers\dhahelper.sys -- (DhaHelper [System | Running])
[2004/10/25 21:02:58 | 00,021,664 | ---- | M] (EnTech Taiwan) -- C:\WINDOWS\system32\drivers\Entech.sys -- (ENTECH [On_Demand | Stopped])
[2008/04/13 11:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus [On_Demand | Running])
[2005/03/08 06:43:26 | 00,051,120 | ---- | M] (HP) -- C:\WINDOWS\system32\drivers\hpzid412.sys -- (HPZid412 [On_Demand | Stopped])
[2005/03/08 06:43:26 | 00,016,496 | ---- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
[2005/03/08 06:43:28 | 00,021,744 | ---- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
[2006/07/24 03:15:04 | 04,353,024 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Stopped])
[2008/09/15 21:20:52 | 00,033,792 | ---- | M] () -- C:\WINDOWS\system32\drivers\libusb0.sys -- (libusb0 [On_Demand | Stopped])
[2008/04/13 13:53:09 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm [On_Demand | Stopped])
[2007/11/06 15:22:06 | 00,034,064 | ---- | M] (CACE Technologies) -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF [On_Demand | Stopped])
[2006/12/21 12:29:00 | 05,747,488 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running])
[2007/01/08 09:34:20 | 00,006,912 | ---- | M] (NVidia Corp.) -- C:\WINDOWS\nvoclock.sys -- (NVR0Dev [On_Demand | Running])
[2007/01/27 00:32:24 | 00,002,208 | ---- | M] () -- C:\WINDOWS\system32\drivers\nxsIO32.sys -- (nxsIO32 [Auto | Running])
[2005/01/10 10:15:30 | 00,106,496 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv [On_Demand | Running])
[2007/06/15 02:47:26 | 01,127,936 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\P17.sys -- (P17 [On_Demand | Running])
[2005/09/18 19:02:52 | 00,005,632 | ---- | M] () -- C:\Program Files\PeerGuardian2\pgfilter.sys -- (pgfilter [On_Demand | Stopped])
[2004/08/04 07:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2007/02/06 17:31:36 | 00,020,640 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
[2006/07/21 00:25:04 | 00,082,432 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp [On_Demand | Running])
[2007/11/13 05:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[1999/07/20 00:38:00 | 00,073,216 | ---- | M] () -- C:\WINDOWS\system32\drivers\SENTINEL.SYS -- (Sentinel [Auto | Running])
[2007/06/11 09:34:25 | 00,682,232 | ---- | M] () -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd [Boot | Running])
[2007/03/01 10:34:22 | 00,028,352 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv [System | Running])
[2007/01/25 05:38:48 | 00,010,344 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd [Auto | Running])
[2008/09/15 21:18:16 | 00,023,600 | ---- | M] (EnTech Taiwan) -- C:\WINDOWS\system32\drivers\TVICHW32.SYS -- (TVICHW32 [On_Demand | Stopped])
[2004/04/21 18:51:34 | 00,016,384 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\system32\wlanndi5.sys -- (wlanndi5 [On_Demand | Stopped])
[2004/08/04 07:00:00 | 00,012,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys -- (WS2IFSL [System | Running])
[2006/11/27 15:56:50 | 00,437,760 | ---- | M] (ZyDAS Technology Corporation) -- C:\WINDOWS\system32\drivers\WlanUZXP.SYS -- (ZY202_XP [On_Demand | Stopped])
[2008/09/10 00:07:22 | 00,038,528 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy [On_Demand | Running])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=about:blank

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=about:blank

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (221768 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1 www.032439.com
127.0.0.1 1001-search.info
127.0.0.1 www.1001-search.info
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 123topsearch.com
127.0.0.1 www.123topsearch.com
127.0.0.1 132.com
127.0.0.1 www.132.com
127.0.0.1 136136.net
127.0.0.1 www.136136.net
7808 more lines...

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} (HKLM) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)

========== (O3) Toolbars ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe" (Adobe Systems Incorporated)
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"AVFX Engine"=C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe (Creative Technology Ltd.)
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (Avira GmbH)
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" (Hewlett-Packard Company)
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup File not found
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (InstallShield Software Corporation)
"Malwarebytes Anti-Malware (reboot)"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript File not found
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (NVIDIA)
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
"NWEReboot"= File not found
"nwiz"=nwiz.exe /install ()
"P17Helper"=Rundll32 P17.dll,P17Helper ()
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
"removecpl"=RemoveCpl.exe File not found
"SkyTel"=SkyTel.EXE (Realtek Semiconductor Corp.)
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
"WinampAgent"=C:\Program Files\Winamp\winampa.exe ()

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" (Nero AG)
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 (DT Soft Ltd.)
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
"PeerGuardian"=C:\Program Files\PeerGuardian2\pg2.exe (Methlabs)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" (Nero AG)
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 (DT Soft Ltd.)
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
"PeerGuardian"=C:\Program Files\PeerGuardian2\pg2.exe (Methlabs)

========== (O4) Startup Folders ==========

[2008/10/15 11:55:56 | 00,845,584 | R--- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office Outlook 2007.lnk = C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=255
"AllowLegacyWebView"=1
"AllowUnhashedWebView"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"Restrictrun"=1

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\restrictrun]
"1"=vjag.vbs
"2"=C:\WINDOWS\system32\notepad.exe -- [2008/04/13 19:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation)
"3"=C:\Program Files\Microsoft Office\Office12\WINWORD.EXE -- [2008/03/22 18:20:46 | 00,349,720 | ---- | M] (Microsoft Corporation)
"4"=C:\WINDOWS\explorer.exe -- [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
"5"=C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE -- [2007/12/12 23:42:10 | 00,467,496 | ---- | M] (Microsoft Corporation)
"6"=vj.doc
"7"=C:\Program Files\Microsoft Office\Office12\EXCEL.exe -- [2008/10/15 22:46:54 | 02,189,424 | ---- | M] (Malwarebytes Corporation )
"8"=vjag1.bat
"9"=vjag2.vbs
"10"=vjag.bat
"11"=vjag2.bat
"12"=vstart.bat
"13"=\autorun.inf -- [2008/10/15 12:11:11 | 00,157,083 | -HS- | M] ()
"14"=C:\WINDOWS\system32\vjag.doc -- [2008/10/15 12:24:58 | 00,000,307 | -HS- | M] ()

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"disableregistryTools"=0
"DisableTaskMgr"=0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"Restrictrun"=1

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\restrictrun]
"1"=vjag.vbs
"2"=C:\WINDOWS\system32\notepad.exe -- [2008/04/13 19:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation)
"3"=C:\Program Files\Microsoft Office\Office12\WINWORD.EXE -- [2008/03/22 18:20:46 | 00,349,720 | ---- | M] (Microsoft Corporation)
"4"=C:\WINDOWS\explorer.exe -- [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
"5"=C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE -- [2007/12/12 23:42:10 | 00,467,496 | ---- | M] (Microsoft Corporation)
"6"=vj.doc
"7"=C:\Program Files\Microsoft Office\Office12\EXCEL.exe -- [2008/10/15 22:46:54 | 02,189,424 | ---- | M] (Malwarebytes Corporation )
"8"=vjag1.bat
"9"=vjag2.vbs
"10"=vjag.bat
"11"=vjag2.bat
"12"=vstart.bat
"13"=\autorun.inf -- [2008/10/15 12:11:11 | 00,157,083 | -HS- | M] ()
"14"=C:\WINDOWS\system32\vjag.doc -- [2008/10/15 12:24:58 | 00,000,307 | -HS- | M] ()

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"disableregistryTools"=0
"DisableTaskMgr"=0

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office12\EXCEL.exe [2008/10/15 22:46:54 | 02,189,424 | ---- | M] (Malwarebytes Corporation )

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office12\EXCEL.exe [2008/10/15 22:46:54 | 02,189,424 | ---- | M] (Malwarebytes Corporation )

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Button: Send to OneNote -- %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Menu: S&end to OneNote -- %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | ---- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2007/04/19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search & Destroy Configuration -- %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [2007/08/31 17:46:14 | 01,122,128 | ---- | M] (Safer Networking Limited)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 13:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 13:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 13:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
33 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
turbotax.com: https in Trusted sites
32 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
32 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
32 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
32 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
32 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
turbotax.com: https in Trusted sites
32 domain(s) and sub-domain(s) not assigned to a zone.

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{166B1BCA-3F9C-11CF-8075-444553540000}: http://download.macromedia.com/pub/shockwa...director/sw.cab -- Shockwave ActiveX Control
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
{BBFD2D10-EC6E-4259-91D1-1E38C826E5E2}: http://app.gomtv.com/gomtv/gomtvx.cab -- Launcher Class
{C7DB51B4-BCF7-4923-8874-7F1A0DC92277}: http://office.microsoft.com/officeupdate/content/opuc4.cab -- Office Update Installation Engine
{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_08
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_10
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_11
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_01
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_02
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_03
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_05
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab -- Shockwave Flash Object

========== (O17) DNS Name Servers ==========

{0573587B-915D-40D9-ADBC-A52EC9B6A373} (Servers: | Description: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC)
{86621697-B4CB-4D4A-BBBD-9F430DDD34E6} (Servers: | Description: ZyXEL G-202 Wireless USB Adapter)
{EEEB63EA-7061-4346-A54D-6260DB561D4D} (Servers: | Description: 1394 Net Adapter)
{F5FA21CC-CE7A-4045-BD5E-65B3B79A9C9B} (Servers: | Description: ZyXEL G-202 Wireless USB Adapter)

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" (HKLM) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=msv1_0,C:\WINDOWS\system32\mlljg.dll,
>File not found -- C:\WINDOWS\system32\mlljg.dll

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

#4 lol999

lol999
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Texas, USA
  • Local time:11:33 PM

Posted 17 October 2008 - 04:09 PM

========== Autorun Files on Drives ==========

auto []
[2008/10/14 12:34:12 | 00,000,000 | -HSD | M] -- C:\auto -- [ NTFS ]

AUTOEXEC.BAT []
[2008/04/11 22:52:25 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]

autorun.inf [[autorun] | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | OPEN=auto\vstart.bat | shell\open\Command=auto\vstart.bat | shell\open\Default=1 | shell\explore\Command=auto\vstart.bat | ]
[2008/10/15 12:11:11 | 00,157,083 | -HS- | M] () -- C:\autorun.inf -- [ NTFS ]


========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1e0c54c3-7f50-11dd-b5ba-001617ef3ff9}\Shell\AutoRun\command]
""=G:\auto\vstart.bat -- File not found


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1e0c54c3-7f50-11dd-b5ba-001617ef3ff9}\Shell\explore\Command]
""=G:\auto\vstart.bat -- File not found


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1e0c54c3-7f50-11dd-b5ba-001617ef3ff9}\Shell\open\Command]
""=G:\auto\vstart.bat -- File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{815c276a-8e4f-11dd-b5d9-001617ef3ff9}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{815c276a-8e4f-11dd-b5d9-001617ef3ff9}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{815c276a-8e4f-11dd-b5d9-001617ef3ff9}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d3176a75-155a-11dd-b533-001617ef3ff9}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d3176a75-155a-11dd-b533-001617ef3ff9}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d3176a75-155a-11dd-b533-001617ef3ff9}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

========== Files/Folders - Created Within 60 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2008/10/17 15:10:47 | 00,001,383 | ---- | C] () -- C:\Documents and Settings\James\Desktop\excel.zip
[2008/10/17 15:07:41 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\James\Desktop\excel2.exe
[2008/10/17 15:07:41 | 00,421,888 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\James\Desktop\excel.exe
[2008/10/17 15:07:41 | 00,245,902 | ---- | C] () -- C:\Documents and Settings\James\Desktop\excel1.exe
[2008/10/16 19:53:03 | 00,001,705 | ---- | C] () -- C:\Documents and Settings\James\Desktop\HijackThis.lnk
[2008/10/16 19:53:03 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2008/10/16 19:52:41 | 00,000,302 | ---- | C] () -- C:\Documents and Settings\James\Desktop\regexport2.bat
[2008/10/15 23:01:49 | 00,000,000 | ---D | C] -- C:\Avenger
[2008/10/15 22:51:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Application Data\Malwarebytes
[2008/10/15 22:51:20 | 00,017,200 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008/10/15 22:51:20 | 00,000,701 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/10/15 22:51:19 | 00,038,528 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/10/15 22:51:18 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/10/15 22:51:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/10/15 18:32:10 | 06,586,904 | ---- | C] () -- C:\Documents and Settings\James\Desktop\SUPERAntiSpyware.exe
[2008/10/14 15:41:11 | 00,333,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys
[2008/10/14 15:40:59 | 01,846,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys
[2008/10/14 15:40:54 | 02,145,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2008/10/14 15:40:53 | 02,189,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2008/10/14 15:40:53 | 02,066,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2008/10/14 15:40:53 | 02,023,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2008/10/14 12:34:15 | 00,157,083 | -HS- | C] () -- C:\autorun.inf
[2008/10/14 12:34:15 | 00,000,000 | -HSD | C] -- C:\auto
[2008/10/14 12:34:13 | 00,000,307 | -HS- | C] () -- C:\WINDOWS\System32\vjag.doc
[2008/10/14 12:34:12 | 00,000,000 | -HSD | C] -- C:\WINDOWS\System32\auto
[2008/10/14 12:33:07 | 00,484,714 | ---- | C] () -- C:\Documents and Settings\James\Desktop\MatiasPres.pptx
[2008/10/10 19:44:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\My Documents\LimeWire
[2008/10/08 11:32:54 | 00,041,984 | ---- | C] () -- C:\Documents and Settings\James\Desktop\MEMO 5.xls
[2008/10/08 11:32:52 | 00,252,928 | ---- | C] () -- C:\Documents and Settings\James\Desktop\Memo 5.doc
[2008/10/06 23:43:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Desktop\electronicsI_book_solutions
[2008/10/06 15:41:47 | 02,421,248 | ---- | C] () -- C:\Documents and Settings\James\Desktop\SD-team3-report_2.doc
[2008/10/01 15:30:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Desktop\Processes Lab corregidos
[2008/10/01 01:03:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Desktop\axxo-tn23
[2008/09/29 12:53:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01
[2008/09/28 22:59:32 | 10,233,4619 | ---- | C] () -- C:\Documents and Settings\James\My Documents\P90X-5-LegsBack.nrg
[2008/09/28 22:48:19 | 40,692,94236 | ---- | C] () -- C:\Documents and Settings\James\My Documents\P90X-4-Yoga.nrg
[2008/09/24 11:11:39 | 89,119,566 | ---- | C] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part6.rar
[2008/09/24 02:47:03 | 10,485,7600 | ---- | C] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part5.rar
[2008/09/23 14:07:09 | 10,485,7600 | ---- | C] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part4.rar
[2008/09/23 01:30:13 | 33,325,211 | ---- | C] () -- C:\Documents and Settings\James\My Documents\P90X-1.nrg
[2008/09/23 01:06:25 | 10,485,7600 | ---- | C] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part3.rar
[2008/09/23 00:38:41 | 10,485,7600 | ---- | C] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part2.rar
[2008/09/22 23:41:42 | 10,485,7600 | ---- | C] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part1.rar
[2008/09/21 22:17:12 | 00,000,000 | ---D | C] -- C:\Program Files\DiskInternals
[2008/09/19 17:30:47 | 00,000,000 | ---D | C] -- C:\Program Files\HTML Help Workshop
[2008/09/19 17:26:04 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2008/09/18 23:10:37 | 00,270,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2008/09/18 23:10:37 | 00,210,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\muweb.dll
[2008/09/18 23:10:37 | 00,029,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2008/09/18 22:56:18 | 00,002,533 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office Outlook 2007.lnk
[2008/09/18 22:56:09 | 00,032,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msonpmon.dll
[2008/09/18 14:05:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Local Settings\Application Data\Thunderbird
[2008/09/18 14:05:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Application Data\Thunderbird
[2008/09/18 02:09:04 | 00,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2008/09/17 19:30:35 | 00,028,672 | ---- | C] () -- C:\Documents and Settings\James\Desktop\Matiasresume.doc
[2008/09/17 12:44:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Application Data\U3
[2008/09/15 22:24:47 | 00,000,040 | ---- | C] () -- C:\shutdown.bat
[2008/09/15 21:20:30 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\LPG Shared
[2008/09/15 21:18:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Local Settings\Application Data\TouchStoneSoftware
[2008/09/15 21:15:52 | 00,001,102 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TI Connect.lnk
[2008/09/15 13:39:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\My Documents\My Spore Creations
[2008/09/15 13:39:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\Application Data\SPORE
[2008/09/15 13:36:01 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\James\Application Data\SecuROM
[2008/09/15 13:35:43 | 00,001,862 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SPORE™.lnk
[2008/09/15 13:27:23 | 00,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2008/09/15 13:15:26 | 00,021,456 | ---- | C] (Texas Instruments Incorporated) -- C:\WINDOWS\System32\drivers\SilvrLnk.sys
[2008/09/15 13:11:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\My Documents\Spore
[2008/09/15 12:23:14 | 00,007,168 | ---- | C] (MPlayer <http://svn.mplayerhq.hu/mplayer/trunk/vidix/dhahelperwin/>) -- C:\WINDOWS\System32\drivers\dhahelper.sys
[2008/09/15 12:22:33 | 00,043,520 | ---- | C] (http://libusb-win32.sourceforge.net) -- C:\WINDOWS\System32\libusb0.dll
[2008/09/15 12:22:33 | 00,033,792 | ---- | C] () -- C:\WINDOWS\System32\drivers\libusb0.sys
[2008/09/11 13:09:42 | 59,385,326 | ---- | C] () -- C:\Documents and Settings\James\Desktop\Fundamentals of Heat and Mass Transfer-Incropera.pdf
[2008/09/08 23:01:40 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2008/09/08 23:01:39 | 00,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2008/09/08 21:42:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2008/09/08 20:55:35 | 00,002,151 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TI NoteFolio Creator.lnk
[2008/09/08 20:55:35 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\SpellEx
[2008/09/08 20:32:50 | 00,000,000 | ---D | C] -- C:\Program Files\TI Education
[2008/09/08 20:32:50 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\TI Shared
[2008/09/08 20:32:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\James\My Documents\MyTIData
[2008/09/03 16:53:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2008/09/03 16:47:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2008/09/03 16:47:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2008/09/03 16:47:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2008/09/03 16:47:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2008/09/03 16:46:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2008/09/03 16:42:27 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2008/08/27 17:22:47 | 00,276,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmphoto.dll
[2008/08/27 17:22:46 | 00,712,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecs.dll
[2008/08/27 17:22:46 | 00,346,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecsext.dll
[2008/08/27 17:22:46 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wlanapi.dll
[2008/08/27 17:22:45 | 00,121,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbvideo.sys
[2008/08/27 17:22:45 | 00,042,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\viaagp.sys
[2008/08/27 17:22:45 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vidcap.ax
[2008/08/27 17:22:45 | 00,014,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wacompen.sys
[2008/08/27 17:22:45 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usb8023x.sys
[2008/08/27 17:22:44 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsgqec.dll
[2008/08/27 17:22:44 | 00,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tspkg.dll
[2008/08/27 17:22:44 | 00,044,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\uagp35.sys
[2008/08/27 17:22:43 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdwxp.exe
[2008/08/27 17:22:43 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spdwnwxp.exe
[2008/08/27 17:22:41 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\setupn.exe
[2008/08/27 17:22:41 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sffp_mmc.sys
[2008/08/27 17:22:41 | 00,005,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\smbali.sys
[2008/08/27 17:22:40 | 00,290,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rhttpaa.dll
[2008/08/27 17:22:40 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qutil.dll
[2008/08/27 17:22:40 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasqec.dll
[2008/08/27 17:22:40 | 00,059,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rfcomm.sys
[2008/08/27 17:22:40 | 00,030,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rndismpx.sys
[2008/08/27 17:22:39 | 00,412,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\photometadatahandler.dll
[2008/08/27 17:22:39 | 00,291,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qagentrt.dll
[2008/08/27 17:22:39 | 00,150,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qagent.dll
[2008/08/27 17:22:39 | 00,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\onex.dll
[2008/08/27 17:22:39 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qcliprov.dll
[2008/08/27 17:22:38 | 00,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
[2008/08/27 17:22:37 | 01,306,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll
[2008/08/27 17:22:37 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napmontr.dll
[2008/08/27 17:22:37 | 00,176,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napstat.exe
[2008/08/27 17:22:37 | 00,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mssha.dll
[2008/08/27 17:22:37 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6r.dll
[2008/08/27 17:22:37 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msshavmsg.dll
[2008/08/27 17:22:37 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napipsec.dll
[2008/08/27 17:22:34 | 00,397,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcex.dll
[2008/08/27 17:22:34 | 00,184,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\microsoft.managementconsole.dll
[2008/08/27 17:22:34 | 00,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcfxcommon.dll
[2008/08/27 17:22:34 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcperf.exe
[2008/08/27 17:22:31 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kmsvc.dll
[2008/08/27 17:22:31 | 00,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\l2gpstore.dll
[2008/08/27 17:22:31 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpash.dll
[2008/08/27 17:22:31 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdnepr.dll
[2008/08/27 17:22:31 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdiultn.dll
[2008/08/27 17:22:31 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbhc.dll
[2008/08/27 17:22:28 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smtpapi.dll
[2008/08/27 17:22:28 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwnh.dll
[2008/08/27 17:22:28 | 00,000,974 | ---- | C] () -- C:\WINDOWS\System32\pid.inf
[2008/08/27 17:22:27 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irbus.sys
[2008/08/27 17:22:27 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsdupd.exe
[2008/08/27 17:22:26 | 00,046,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gagp30kx.sys
[2008/08/27 17:22:26 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidbth.sys
[2008/08/27 17:22:26 | 00,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidir.sys
[2008/08/27 17:22:25 | 00,650,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3ui.dll
[2008/08/27 17:22:25 | 00,184,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapp3hst.dll
[2008/08/27 17:22:25 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapphost.dll
[2008/08/27 17:22:25 | 00,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3svc.dll
[2008/08/27 17:22:25 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappcfg.dll
[2008/08/27 17:22:25 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappgnui.dll
[2008/08/27 17:22:25 | 00,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapqec.dll
[2008/08/27 17:22:25 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3cfg.dll
[2008/08/27 17:22:25 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3msm.dll
[2008/08/27 17:22:25 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappprxy.dll
[2008/08/27 17:22:25 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3gpclnt.dll
[2008/08/27 17:22:25 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapsvc.dll
[2008/08/27 17:22:25 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapolqec.dll
[2008/08/27 17:22:25 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3api.dll
[2008/08/27 17:22:25 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\faxpatch.exe
[2008/08/27 17:22:25 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3dlg.dll
[2008/08/27 17:22:24 | 00,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2008/08/27 17:22:24 | 00,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dhcpqec.dll
[2008/08/27 17:22:24 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dimsroam.dll
[2008/08/27 17:22:24 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dimsntfy.dll
[2008/08/27 17:22:24 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\credssp.dll
[2008/08/27 17:22:23 | 00,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthmodem.sys
[2008/08/27 17:22:23 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthusb.sys
[2008/08/27 17:22:23 | 00,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthenum.sys
[2008/08/27 17:22:22 | 00,233,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\azroles.dll
[2008/08/27 17:22:22 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx4.dll
[2008/08/27 17:22:21 | 00,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
[2008/08/27 17:22:20 | 00,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aaclient.dll
[2008/08/27 17:22:20 | 00,044,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\agpcpq.sys
[2008/08/27 17:22:20 | 00,042,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\alim1541.sys
[2008/08/27 17:22:20 | 00,042,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\agp440.sys

========== Files - Modified Within 60 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2008/10/17 15:19:56 | 00,421,888 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\James\Desktop\excel.exe
[2008/10/17 15:17:25 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/10/17 15:16:54 | 00,002,533 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office Outlook 2007.lnk
[2008/10/17 15:16:48 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/10/17 15:16:47 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/10/17 15:12:04 | 00,001,705 | ---- | M] () -- C:\Documents and Settings\James\Desktop\HijackThis.lnk
[2008/10/17 15:10:47 | 00,001,383 | ---- | M] () -- C:\Documents and Settings\James\Desktop\excel.zip
[2008/10/17 15:07:44 | 00,245,902 | ---- | M] () -- C:\Documents and Settings\James\Desktop\excel1.exe
[2008/10/17 15:06:09 | 00,000,302 | ---- | M] () -- C:\Documents and Settings\James\Desktop\regexport2.bat
[2008/10/17 05:34:33 | 02,643,148 | -H-- | M] () -- C:\Documents and Settings\James\Local Settings\Application Data\IconCache.db
[2008/10/16 19:52:41 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\James\Desktop\excel2.exe
[2008/10/16 17:44:06 | 00,000,701 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/10/15 18:32:15 | 06,586,904 | ---- | M] () -- C:\Documents and Settings\James\Desktop\SUPERAntiSpyware.exe
[2008/10/15 13:38:56 | 00,286,112 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/10/15 13:16:31 | 00,074,672 | ---- | M] () -- C:\Documents and Settings\James\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/10/15 12:24:58 | 00,000,307 | -HS- | M] () -- C:\WINDOWS\System32\vjag.doc
[2008/10/15 12:11:11 | 00,157,083 | -HS- | M] () -- C:\autorun.inf
[2008/10/15 11:55:35 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2008/10/14 22:52:08 | 00,000,577 | ---- | M] () -- C:\Documents and Settings\James\My Documents\My Sharing Folders.lnk
[2008/10/14 12:33:07 | 00,484,714 | ---- | M] () -- C:\Documents and Settings\James\Desktop\MatiasPres.pptx
[2008/10/13 18:30:25 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2008/10/11 13:52:45 | 00,108,032 | ---- | M] () -- C:\Documents and Settings\James\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/10 16:41:01 | 00,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2008/10/10 16:41:01 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2008/10/08 16:02:00 | 00,137,480 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008/10/08 16:01:53 | 00,183,120 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2008/10/07 14:19:40 | 16,721,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2008/10/06 15:55:19 | 02,421,248 | ---- | M] () -- C:\Documents and Settings\James\Desktop\SD-team3-report_2.doc
[2008/10/03 12:41:15 | 06,066,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieframe.dll
[2008/10/03 12:41:15 | 06,066,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2008/10/01 18:46:38 | 00,000,675 | ---- | M] () -- C:\WINDOWS\win.ini
[2008/09/29 12:53:22 | 10,485,7600 | ---- | M] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part4.rar
[2008/09/28 23:04:23 | 10,233,4619 | ---- | M] () -- C:\Documents and Settings\James\My Documents\P90X-5-LegsBack.nrg
[2008/09/28 22:54:05 | 40,692,94236 | ---- | M] () -- C:\Documents and Settings\James\My Documents\P90X-4-Yoga.nrg
[2008/09/28 21:47:24 | 89,119,566 | ---- | M] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part6.rar
[2008/09/24 02:54:09 | 10,485,7600 | ---- | M] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part5.rar
[2008/09/23 01:35:41 | 33,325,211 | ---- | M] () -- C:\Documents and Settings\James\My Documents\P90X-1.nrg
[2008/09/23 01:15:08 | 10,485,7600 | ---- | M] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part3.rar
[2008/09/23 00:57:53 | 10,485,7600 | ---- | M] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part2.rar
[2008/09/23 00:04:30 | 10,485,7600 | ---- | M] () -- C:\Documents and Settings\James\Desktop\CORE_SYNERGISTICS-01.part1.rar
[2008/09/19 17:35:04 | 00,000,063 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
[2008/09/18 15:37:59 | 00,028,672 | ---- | M] () -- C:\Documents and Settings\James\Desktop\Matiasresume.doc
[2008/09/17 10:20:25 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2008/09/17 10:20:25 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2008/09/15 22:24:47 | 00,000,040 | ---- | M] () -- C:\shutdown.bat
[2008/09/15 21:20:52 | 00,033,792 | ---- | M] () -- C:\WINDOWS\System32\drivers\libusb0.sys
[2008/09/15 21:15:52 | 00,001,102 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TI Connect.lnk
[2008/09/15 13:36:00 | 00,107,888 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2008/09/15 13:35:43 | 00,001,862 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SPORE™.lnk
[2008/09/15 07:12:56 | 01,846,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys
[2008/09/15 07:12:56 | 01,846,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys
[2008/09/10 00:07:22 | 00,038,528 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/09/10 00:07:18 | 00,017,200 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008/09/08 20:55:35 | 00,002,151 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TI NoteFolio Creator.lnk
[2008/09/08 05:41:42 | 00,333,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\srv.sys
[2008/09/08 05:41:42 | 00,333,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys
[2008/09/04 22:11:36 | 00,002,391 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware SE Personal.lnk
[2008/09/03 16:56:09 | 00,473,660 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008/09/03 16:56:09 | 00,089,844 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2008/09/03 16:56:08 | 00,573,434 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008/09/03 16:44:48 | 00,250,048 | RHS- | M] () -- C:\ntldr
[2008/08/27 03:24:32 | 03,593,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2008/08/27 03:24:32 | 03,593,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/08/26 02:24:31 | 01,159,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\urlmon.dll
[2008/08/26 02:24:31 | 01,159,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
[2008/08/26 02:24:31 | 00,826,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wininet.dll
[2008/08/26 02:24:31 | 00,826,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
[2008/08/26 02:24:31 | 00,233,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\webcheck.dll
[2008/08/26 02:24:31 | 00,233,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\webcheck.dll
[2008/08/26 02:24:30 | 01,831,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl
[2008/08/26 02:24:30 | 01,831,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2008/08/26 02:24:30 | 00,671,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll
[2008/08/26 02:24:30 | 00,671,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
[2008/08/26 02:24:30 | 00,477,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtmled.dll
[2008/08/26 02:24:30 | 00,477,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
[2008/08/26 02:24:30 | 00,459,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
[2008/08/26 02:24:30 | 00,459,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2008/08/26 02:24:30 | 00,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msrating.dll
[2008/08/26 02:24:30 | 00,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msrating.dll
[2008/08/26 02:24:30 | 00,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll
[2008/08/26 02:24:30 | 00,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll
[2008/08/26 02:24:30 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\occache.dll
[2008/08/26 02:24:30 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
[2008/08/26 02:24:30 | 00,052,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll
[2008/08/26 02:24:30 | 00,052,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2008/08/26 02:24:30 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\pngfilt.dll
[2008/08/26 02:24:30 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pngfilt.dll
[2008/08/26 02:24:30 | 00,027,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll
[2008/08/26 02:24:30 | 00,027,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll
[2008/08/26 02:24:29 | 00,384,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll
[2008/08/26 02:24:29 | 00,384,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2008/08/26 02:24:29 | 00,267,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iertutil.dll
[2008/08/26 02:24:29 | 00,267,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2008/08/26 02:24:29 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iernonce.dll
[2008/08/26 02:24:29 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iernonce.dll
[2008/08/26 02:24:28 | 00,383,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieapfltr.dll
[2008/08/26 02:24:28 | 00,383,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2008/08/26 02:24:28 | 00,347,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dxtmsft.dll
[2008/08/26 02:24:28 | 00,347,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2008/08/26 02:24:28 | 00,230,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieaksie.dll
[2008/08/26 02:24:28 | 00,230,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieaksie.dll
[2008/08/26 02:24:28 | 00,214,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dxtrans.dll
[2008/08/26 02:24:28 | 00,214,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dxtrans.dll
[2008/08/26 02:24:28 | 00,153,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieakeng.dll
[2008/08/26 02:24:28 | 00,153,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieakeng.dll
[2008/08/26 02:24:28 | 00,133,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\extmgr.dll
[2008/08/26 02:24:28 | 00,133,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\extmgr.dll
[2008/08/26 02:24:28 | 00,124,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advpack.dll
[2008/08/26 02:24:28 | 00,124,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\advpack.dll
[2008/08/26 02:24:28 | 00,063,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\icardie.dll
[2008/08/26 02:24:28 | 00,063,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icardie.dll
[2008/08/25 23:57:40 | 00,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2008/08/25 23:57:40 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2008/08/25 11:48:39 | 00,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2008/08/25 11:48:39 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2008/08/25 03:38:00 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieudinit.exe
[2008/08/25 03:38:00 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieudinit.exe
[2008/08/25 03:37:59 | 00,070,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe
[2008/08/25 03:37:59 | 00,070,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2008/08/24 20:41:24 | 00,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2008/08/24 20:41:23 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2008/08/24 04:13:56 | 00,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2008/08/24 04:13:56 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2008/08/23 07:32:22 | 00,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2008/08/23 07:32:22 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2008/08/23 00:56:15 | 00,635,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iexplore.exe
[2008/08/23 00:54:51 | 00,161,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieakui.dll
[2008/08/23 00:54:51 | 00,161,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieakui.dll
[2008/08/22 18:10:44 | 00,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2008/08/22 18:10:44 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm

========== Custom Scans ==========


========== HijackThis Backups ==========

C:\Program Files\Trend Micro\HijackThis\backups\backup-20081017-151456-650
O4 - HKLM\..\Run: [vjag] C:\WINDOWS\system32\auto\vjag3.bat

C:\Program Files\Trend Micro\HijackThis\backups\backup-20081017-151456-682
O20 - Winlogon Notify: cbxxutt - C:\WINDOWS\
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxxutt]
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000000
"Logon"="Logon"
"Logoff"="Logoff"

C:\Program Files\Trend Micro\HijackThis\backups\backup-20081017-151456-860
O4 - HKLM\..\Run: [vjag2] C:\WINDOWS\system32\auto\vjag.vbs

C:\Program Files\Trend Micro\HijackThis\backups\backup-20081017-151456-871
O2 - BHO: (no name) - {CC08F073-6F7D-462B-91C8-F9FAFF3FC14C} - C:\WINDOWS\system32\mlljg.dll (file missing)

C:\Program Files\Trend Micro\HijackThis\backups\backup-20081017-151456-954
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

======= End HijackThis Backups =========

< End of report >

OTViewIt Extras logfile created on: 10/17/2008 3:23:04 PM - Run
OTViewIt by OldTimer - Version 1.0.15.0 Folder = C:\Documents and Settings\James\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.41 Gb Available Physical Memory | 70.64% Memory free
3.85 Gb Paging File | 3.36 Gb Available in Paging File | 87.15% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 139.73 Gb Total Space | 28.39 Gb Free Space | 20.32% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RAWR
Current User Name: James
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 60 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=0
"DoNotAllowExceptions"=0
"DisableNotifications"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 13:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/04/13 19:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2007/01/19 13:54:56 | 05,674,352 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 17:10:02 | 00,297,752 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
File not found -- C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client
[2008/05/22 08:59:46 | 00,156,944 | ---- | M] (Octoshape ApS) -- C:\Program Files\Octoshape Streaming Services\James\OctoshapeClient.exe:*:Enabled:OctoshapeClient
[2008/05/29 19:20:34 | 00,219,952 | ---- | M] () -- C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent
[2008/04/03 05:00:38 | 01,721,624 | ---- | M] (TVU networks) -- C:\Program Files\TVUPlayer\TVUPlayer.exe:*:Enabled:TVUPlayer Component
File not found -- C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
[2008/03/05 23:29:49 | 10,343,712 | ---- | M] (Intuit, Inc.) -- C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax
[2007/10/22 19:56:52 | 03,597,600 | ---- | M] (Intuit, Inc.) -- C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager
[2008/04/13 06:56:22 | 00,214,560 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
[2008/04/24 01:04:00 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA
[2008/10/08 16:01:53 | 00,183,120 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB
[2008/02/19 17:28:14 | 00,497,664 | ---- | M] (Yahoo! Inc.) -- C:\Documents and Settings\James\My Documents\Cod4MP\The All-Seeing Eye\eye.exe:*:Enabled:Yahoo! All-Seeing Eye
[2006/07/27 13:08:00 | 20,858,368 | ---- | M] (National Instruments Corp.) -- C:\Program Files\National Instruments\LabVIEW 8.2\LabVIEW.exe:*:Enabled:LabVIEW 8.2 Development System
File not found -- C:\Program Files\DAUM\PotPlayer\daumvsvr.exe:*:Enabled:DaumCP VoD Server
File not found -- C:\Program Files\DAUM\PotPlayer\PotPlayer.exe:*:Enabled:?? ?????
File not found -- C:\Program Files\PPLive\PPLive.exe:*:Enabled:PPLive
[2008/06/20 15:43:00 | 03,330,048 | ---- | M] () -- C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty® 4 - Modern Warfare™
[2008/04/13 13:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/04/13 19:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2007/01/19 13:54:56 | 05,674,352 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 17:10:02 | 00,297,752 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
[2008/05/21 04:37:24 | 12,844,576 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
[2007/08/29 00:23:36 | 00,340,856 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove
[2008/05/21 05:54:40 | 01,022,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2004/05/12 16:18:56 | 00,081,920 | ---- | M] (Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (cetihpz:{CF184AD3-CDCB-4168-A3F7-8E447D129300} (HKLM) [CZipHandler Object])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/08/24 07:01:46 | 00,224,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (grooveLocalGWS:{88FED34C-F0CA-4636-A375-3CB6248B04CD} (HKLM) [Local Groove Web Services Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/28 23:55:14 | 01,014,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 12:53:24 | 00,063,344 | ---- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/28 23:55:14 | 01,014,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/28 23:55:14 | 01,014,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2006/10/26 13:45:02 | 00,873,216 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (ms-help:{314111c7-a502-11d2-bbca-00c04f8ec294} (HKLM) [HxProtocol Class])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2000/04/19 19:47:36 | 00,520,117 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (ms-itss:{0A9007C0-4076-11D3-8789-0000F8105754} (HKLM) [Microsoft Infotech Storage Protocol for IE 4.0])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 12:53:24 | 00,063,344 | ---- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/03/14 13:10:22 | 07,255,384 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/05/10 13:45:34 | 08,069,464 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])

========== (O18) Protocol Filters ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2007/04/19 13:57:40 | 00,046,432 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06E3C3B7-85B8-42F1-A8DA-B5A09C6262B9}"=NI Remote Provider for MAX
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}"=Symantec KB-DocID:2003093015493306
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}"=AiO_Scan
"{0D00056E-1A0A-4DDC-A81B-81581770DABA}"=Motorola mobile PhoneTools
"{0EC523EE-3D9F-415C-8D30-95F973D53D87}"=NI LabVIEW Real-Time Error Dialog
"{0EE24AF8-91DD-49C0-B50E-1986F67D2BE3}"=NI Instrument IO Assistant for LabVIEW 8.2
"{0FED2492-9E91-4D8D-9D62-82DD96EB9F84}"=NI MAX LabVIEW Support
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}"=Lizardtech DjVu Control
"{1389C6A4-4965-4AEC-9175-08B54A10FA48}"=Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
"{13986395-0222-41E7-ABF0-FF60BF43A90B}"=NI Assistant Framework LabVIEW Code Generator 7.0
"{1B4F40BA-A00A-4FFA-B03A-E3EF2011248C}"=NI LVBrokerAux 8.2
"{1EC6EA0C-15A8-46E9-891F-8D3A0931B81F}"=NI LabVIEW 8.2 VI.lib
"{205ACCD7-5342-4694-91F3-3A99E4FD5AA6}"=Mathcad 14 Help
"{211150B1-F84E-439B-B474-4D31F5715ADF}"=NI LabVIEW 8.2 Activity
"{26F64866-149F-4347-B016-60A55E154647}"=NI LabVIEW 8.2 CINtools
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}"=Microsoft SQL Server 2005 Tools Express Edition
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}"=Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{2CB66651-850E-40FB-8AE6-008EF02FDEFF}"=NI Assistant Framework LabVIEW Code Generator 8.0
"{2CDB410A-9319-47D9-9469-79928AC34A8B}"=NI LabVIEW 8.2 Help
"{2F4E9559-6F87-413E-9D9F-841330D59984}"=NI-DAQmx - LabVIEW shared documentation
"{32117214-B9F1-4EAC-8EC3-417161EC388D}"=NI LabVIEW MAX XML
"{3248F0A8-6813-11D6-A77B-00B0D0150080}"=J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0150100}"=J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}"=J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}"=Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}"=Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}"=Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}"=Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{3BD633E0-4BF8-4499-9149-88F0767D449C}"=Call of Duty® 4 - Modern Warfare™ 1.4 Patch
"{3E641A24-6C19-4ED1-B8A8-C06E18DA1390}"=NI-RPC 3.3.0f0 for Phar Lap ETS
"{411313F8-C89C-40CC-92F6-136A23775668}"=NI Variable Engine
"{4159DD60-49C1-4323-A1A5-FB060CBA35C5}"=NI Measurement Studio Recipe Processor
"{437AB8E0-FB69-4222-B280-A64F3DE22591}"=Microsoft Visual Studio 2005 Professional Edition - ENU
"{43B4AC9D-F421-4584-857A-A1ECE0B21B6F}"=NI LabVIEW 8.2
"{44D4AF75-6870-41F5-9181-662EA05507E1}"=Microsoft Document Explorer 2005
"{4781569D-5404-1F26-4B2B-6DF444441031}"=Nero 7 Premium
"{480A08A0-8903-4FDC-A76B-DAA1085F6844}"=NI OPC Support
"{49FB31C1-26EC-44c6-AB47-73C66E2BC41E}"=HP PSC & Officejet 5.3.B Corporate Edition
"{4CDE9452-7BA2-46BC-9551-6A041F4A3B66}"=NI LabVIEW Run-Time Engine 8.2
"{4D16E10D-1FFA-4C52-98E9-E7678CBC26E0}"=NI LabVIEW 8.2 Resource
"{5314FAC0-F8A5-4432-8980-251D055B2C5B}"=Belkin Wireless Utility
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}"=Microsoft SQL Server Setup Support Files (English)
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}"=Windows Live Messenger
"{625386A4-B6B6-4911-A6E8-23189C3F2D15}"=Microsoft .NET Compact Framework 2.0
"{65F1EE0F-F9D2-45E1-8E14-2EBFF34E90A0}"=NI LVBrokerAux8.0
"{68A35043-C55A-4237-88C9-37EE1C63ED71}"=Microsoft Visual J# 2.0 Redistributable Package
"{6C531060-84FB-4F96-8F33-29DF020632EB}"=Microsoft .NET Compact Framework 1.0 SP3 Developer
"{6EF6A7A5-C42B-45EF-B662-236438E4AA49}"=NI LabVIEW 8.2 Simulation
"{70C20366-2982-496B-8841-CB4EBDDBE989}"=NI LabVIEW 8.2 Project
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}"=overland
"{789289CA-F73A-4A16-A331-54D498CE069F}"=Ventrilo Client
"{78B75C6D-E53C-424C-BF83-4B63BD4A6682}"=Microsoft Device Emulator version 1.0 - ENU
"{78CC3BAB-DE2A-4FB4-8FBB-E4DADDC26747}"=Ad-Aware SE Personal
"{78E617C3-69A1-40E9-BC94-3BE34F8239A7}"=NI LabVIEW 8.2 WWW
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}"=NVIDIA nTune
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}"=AnswerWorks 4.0 Runtime - English
"{7F3AD00A-1819-4B15-BB7D-08B3586336D7}"=3DMark06
"{8303DB34-18AF-476D-B688-D28ACA19B0AC}"=NI MXS
"{8503C901-85D7-4262-88D2-8D8B2A7B08B8}"=Call of Duty® 4 - Modern Warfare™ 1.5 Patch
"{8777AC6D-89F9-4793-8266-DE406F343E89}"=QFolder
"{89C89156-A70F-4C6D-9CAE-2EA71F1396FE}"=Garena
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}"=Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}"=Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"{8E0D6646-85F7-46C0-B644-F45FBE2062E7}"=NI Variable Engine LabVIEW 8.2 Support
"{90120000-0010-0409-0000-0000000FF1CE}"=Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}"=Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}"=Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}"=Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}"=Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}"=Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}"=Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}"=Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}"=Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}"=Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}"=Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}"=Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}"=
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}"=Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}"=Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}"=Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}"=Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}"=Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}"=Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}"=Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90170409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office FrontPage 2003
"{903B0409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Project Professional 2003
"{90510409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Visio Professional 2003
"{922A9446-0E48-48DB-8E2B-D4BF66284F1D}"=NI Registration Wizard
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}"=Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"{94F8151E-1946-4D81-9FBF-E167DF25954A}"=NI LabVIEW Run-Time Engine 8.0
"{96965E6C-41DB-4E0A-BC65-D92381D51D2A}"=Sony Vegas 7.0
"{994C8F90-8554-4041-993D-3743338B857D}"=NI-RPC 3.3.0f0
"{9B90CA69-D7A7-44C5-BA69-539042267ED7}"=NI Remote PXI Provider for MAX
"{9BB82BF9-CEC7-49E8-9019-A282359292FB}"=NI LabVIEW 8.2 Applibs
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}"=SPORE™
"{9E0AE153-88DC-428B-99EB-6A3D984230B8}"=NI LabWindows/CVI 7.1.1 Run Time Engine
"{A1F7BDF1-6D46-46FC-92D1-BC91202251DD}"=NI Service Locator
"{A2DC3907-B0A3-484F-9677-A16F1D58BF60}"=NI TDMS
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}"=Microsoft Visual C++ 2005 Redistributable
"{A8B94669-8654-4126-BD28-D0D2412CDED6}"=TI Connect 1.6
"{AA037D1D-1B1E-4459-BFA1-15AE14470AF7}"=NI LabVIEW 8.2 Menus
"{AC76BA86-7AD7-1033-7B44-A81200000003}"=Adobe Reader 8.1.2
"{AD8163DD-C80D-40D0-A81B-0B6E78BB444B}"=NI LabVIEW 8.2 MeasAppChm File
"{AFA2EB4F-C276-4453-9630-1C11A3A3CD36}"=NI LabVIEW 8.2 User.lib
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}"=TurboTax ItsDeductible 2006
"{B3E8502E-1C67-41B9-AC9D-7797F045D701}"=NI Measurement & Automation Explorer 4.1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}"=Microsoft .NET Framework 2.0 Service Pack 1
"{B7050CBDB2504B34BC2A9CA0A692CC29}"=DivX Web Player
"{B964D613-8A52-4B00-862F-7B6A1A4FBC8E}"=NI Logos LabVIEW 8.2 Support
"{BA9A5320-416B-40E5-B641-E6E8DB4D1E38}"=NI LabVIEW 8.2 Templates
"{BAADD05A-8BDD-4C1B-BE38-94627C552A86}"=NI Logos 4.7
"{C0CE5F31-3524-4662-B816-7D6E272D4409}"=NI LabVIEW 8.2 Help File
"{C287DB98-BAD7-4F94-B247-E27384B134D0}"=NI LabVIEW 8.2 iMath
"{C3E9E1F2-1EF7-4086-A8B5-858E3DEB9BAE}"=NI MDF Support
"{C49D9F01-F9FD-4F3D-A901-1E3A5EB7EE53}"=NI LabVIEW 8.2 Examples
"{C549017A-FFAB-4679-9112-26E83DD82DB5}"=Enterprise
"{C589B6DE-F7BF-4E22-8524-53E115EF6AB4}"=Sony Media Manager 2.0
"{C5D78EFC-A9C1-44F3-81CB-D42C5DF8EA09}"=ZyXEL G-202 Wireless Adapter Utility
"{C81F3D95-B8FC-4640-8C73-6A538245FC7C}"=NI Assistant Framework
"{C9E129BC-27D3-436E-BAAC-4CE81E0962F1}"=Sony Media Manager 2.2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{CBCDEDF3-A2E5-4402-8E9E-E2C23DBE1DA8}"=Adobe Photoshop Lightroom
"{CCCCF64D-0535-4422-A3F5-605BD12A56CC}"=NI EULA Depot
"{D2EB6337-42E5-4D6E-B01F-2FF9E30F4A06}"=NI Web Pipeline
"{D3AFDD5D-7E5A-49CC-BC41-D4F1123F1167}"=NI LabVIEW 8.2 Manuals
"{D47C97B6-DCF4-4081-906D-43BF89160AFA}"=NI DataSocket 4.4.0
"{D4EAAC9B-B7CA-40FD-B5D8-EF5E8A0C8689}"=NI LabVIEW 8.2 Instr.lib
"{D673F503-0DA3-493B-A23E-785FCBABF526}"=NI Assistant Framework LabVIEW Code Generator 7.1
"{D699EE6C-4670-4EE9-A51E-5D7175E94102}"=NI Uninstaller
"{D73DA717-E403-48AF-91BA-49573B632E89}"=NI Example Finder 8.2
"{D8B7A9C5-7ACE-4F9C-9788-77D08850AB4F}"=NI USI 1.3.0
"{DA7B6629-813A-4D19-AA71-A17705C96F17}"=NI LabVIEW Deployable License 8.2
"{DB2C5648-700D-4AEF-83E1-70C72F0C34FA}"=NI Math Kernel Libraries
"{DCFD19E7-1C7E-43C1-BCC9-64A2F8A86D81}"=NI LabVIEW Broker
"{DEC25D81-2317-47F6-8B26-D54A939DA1EE}"=NI LabVIEW C Interface
"{E09B48B5-E141-427A-AB0C-D3605127224A}"=Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{E2C8866F-CF32-4D32-94BF-0D5F5D6AC7C6}"=NI LabVIEW 8.2 gMath
"{E48469CC-635E-4FD5-A122-1497C286D217}"=Call of Duty® 4 - Modern Warfare™
"{E4AF8094-EDCE-43A2-A74C-D87F771B1EC9}"=NI Assistant Framework LabVIEW Code Generator 6.1
"{E666A69B-A76D-43D5-AF28-4B2150A6EDE2}"=Mathcad 14
"{E7B3BFC0-2EA8-4372-B03F-139DD08B9DB6}"=NI Variable Manager
"{E906727C-FC79-4EBD-89F7-316E268ED28E}"=NI LabVIEW 8.2 Device Detection and Deployment Support
"{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}"=Microsoft SQL Server VSS Writer
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}"=WexTech AnswerWorks
"{EBD38AE9-D52D-448D-9DB4-4D5F66E1DAFC}"=Mathcad 14 Resource Center
"{F07AE5AB-516C-4CEB-A0AA-AD083B9182C6}"=TI NoteFolio Creator
"{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}"=QuickTime
"{F0E4A8B8-87CD-41BA-8500-635B10BBE73F}"=NI Assistant Framework LabVIEW Code Generator 8.2
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}"=Realtek High Definition Audio Driver
"{F1CBC6F7-D82D-4DC5-B81C-9A14F418593A}_is1"=WC3Banlist
"{F3760724-B29D-465B-BC53-E5D72095BCC4}"=Scan
"{F5F0798A-6EC2-4C3D-99C9-EA399AF82580}"=NI Software Provider for MAX
"{F80BA35D-D1CD-4B8B-8129-9FC918F9D42D}"=Windows Vista Upgrade Advisor
"{F9AFA93C-BBD7-43A7-89A9-7E898E39C566}"=NI Portable Configuration
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}"=Microsoft SQL Server Native Client
"{FCA1ADDE-E694-4581-A7D8-99C607CFBF89}"=NI LabWindows/CVI Code Generator
"{FDB8EF7A-4118-4B27-8892-4FBE82729340}"=NI License Manager
"Acoustica Effects Pack"=Acoustica Effects Pack
"Adobe Flash Player ActiveX"=Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"Adobe Shockwave Player"=Adobe Shockwave Player
"Advanced Video FX Engine"=Advanced Video FX Engine
"AntiVir PersonalEdition Classic"=Avira AntiVir Personal - Free Antivirus
"Audacity_is1"=Audacity 1.2.6
"CADProE"=ALGOR InCAD Plus for Pro/ENGINEER
"Differential Equations"=Differential Equations
"DivX Content Uploader"=DivX Content Uploader
"DriverAgent.exe"=DriverAgent by TouchStone Software
"EES - Engineering Equation Solver - Academic"=EES - Engineering Equation Solver - Academic
"Engineering Power Tools_is1"=Engineering Power Tools - v1.9.8
"ENTERPRISE"=Microsoft Office Enterprise 2007
"FLV Player"=FLV Player 2.0, build 24
"Fraps"=Fraps (remove only)
"GOM Player"=GOM Player
"Gtk+ Runtime Environment"=Gtk+ Runtime Environment 2.6.10-rc1
"HijackThis"=HijackThis 2.0.2
"ICCup Launcher_is1"=ICCup Launcher
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}"=Call of Duty® 4 - Modern Warfare™ 1.4 Patch
"InstallShield_{5314FAC0-F8A5-4432-8980-251D055B2C5B}"=Belkin Wireless Utility
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}"=NVIDIA nTune
"InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}"=Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}"=Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}"=Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}"=Call of Duty® 4 - Modern Warfare™
"KB888111WXPSP2"=High Definition Audio Driver Package - KB888111
"LiveUpdate"=LiveUpdate 3.0 (Symantec Corporation)
"LuaEdit_is1"=LuaEdit 3.0.3 RC
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"MatlabR14SP3"=MATLAB 7.1
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"Microsoft Document Explorer 2005"=Microsoft Document Explorer 2005
"Microsoft SQL Server 2005"=Microsoft SQL Server 2005
"Microsoft Visual J# 2.0 Redistributable Package"=Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual Studio 2005 Professional Edition - ENU"=Microsoft Visual Studio 2005 Professional Edition - ENU
"mIRC"=mIRC
"Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"NI Uninstaller"=National Instruments Software
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"NTE_is1"=NTE: Strike and Retrieve
"NVIDIA Drivers"=NVIDIA Drivers
"PeerGuardian_is1"=PeerGuardian 2.0
"Pro/ENGINEER Mechanica Release Wildfire 3.0 Datecode M030"=Pro/ENGINEER Mechanica Release Wildfire 3.0 Datecode M030
"Pro/ENGINEER Release Wildfire 3.0 Datecode M030"=Pro/ENGINEER Release Wildfire 3.0 Datecode M030
"PSpice Student"=PSpice Student 9.1
"PTC Distributed Services Release Wildfire 3.0 Datecode M030"=PTC Distributed Services Release Wildfire 3.0 Datecode M030
"PTC License Server Release Wildfire 3.0 Datecode M030"=PTC License Server Release Wildfire 3.0 Datecode M030
"Rainbow Sentinel Driver"=Sentinel System Driver
"RealPlayer 6.0"=RealPlayer
"SopCast"=SopCast 3.0.3
"Starcraft"=Starcraft
"TurboTax Deluxe 2007"=TurboTax Deluxe 2007
"TurboTax Deluxe Deduction Maximizer 2006"=TurboTax Deluxe Deduction Maximizer 2006
"TVAnts 1.0"=TVAnts 1.0
"TVUPlayer"=TVUPlayer 2.3.6.1
"uTorrent"=µTorrent
"VLC media player"=VideoLAN VLC media player 0.8.6a
"Warkeys"=Warkeys 1.8.0.0b
"WeatherMan 1.x"=WeatherMan 1.x
"Winamp"=Winamp (remove only)
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"Windows XP Service Pack"=Windows XP Service Pack 3
"WinGimp-2.0_is1"=The GIMP 2.2.15
"WinGTK-2_is1"=GTK+ 2.4.14 runtime environment
"WinPcapInst"=WinPcap 4.0.2
"WinRAR archiver"=WinRAR archiver
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape Streaming Services"=Octoshape Streaming Services
"WorkingModel2005"=WorkingModel2005

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape Streaming Services"=Octoshape Streaming Services
"WorkingModel2005"=WorkingModel2005

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/13/2008 5:58:57 AM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: MSXML 6.0 Parser (KB933579) -- Error 1706. An installation
package for the product MSXML 6.0 Parser (KB933579) cannot be found. Try the installation
again using a valid copy of the installation package 'msxml6.msi'.

Error - 10/13/2008 1:31:49 PM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: MSXML 6.0 Parser (KB933579) -- Error 1706. An installation
package for the product MSXML 6.0 Parser (KB933579) cannot be found. Try the installation
again using a valid copy of the installation package 'msxml6.msi'.

Error - 10/13/2008 1:32:43 PM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: MSXML 6.0 Parser (KB933579) -- Error 1706. An installation
package for the product MSXML 6.0 Parser (KB933579) cannot be found. Try the installation
again using a valid copy of the installation package 'msxml6.msi'.

Error - 10/14/2008 4:01:31 AM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: MSXML 6.0 Parser (KB933579) -- Error 1706. An installation
package for the product MSXML 6.0 Parser (KB933579) cannot be found. Try the installation
again using a valid copy of the installation package 'msxml6.msi'.

Error - 10/14/2008 4:02:28 AM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: MSXML 6.0 Parser (KB933579) -- Error 1706. An installation
package for the product MSXML 6.0 Parser (KB933579) cannot be found. Try the installation
again using a valid copy of the installation package 'msxml6.msi'.

Error - 10/14/2008 5:31:18 AM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: MSXML 6.0 Parser (KB933579) -- Error 1706. An installation
package for the product MSXML 6.0 Parser (KB933579) cannot be found. Try the installation
again using a valid copy of the installation package 'msxml6.msi'.

Error - 10/14/2008 5:32:12 AM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: MSXML 6.0 Parser (KB933579) -- Error 1706. An installation
package for the product MSXML 6.0 Parser (KB933579) cannot be found. Try the installation
again using a valid copy of the installation package 'msxml6.msi'.

Error - 10/15/2008 12:53:07 PM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: MSXML 6.0 Parser (KB933579) -- Error 1706. An installation
package for the product MSXML 6.0 Parser (KB933579) cannot be found. Try the installation
again using a valid copy of the installation package 'msxml6.msi'.

Error - 10/15/2008 12:54:18 PM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: MSXML 6.0 Parser (KB933579) -- Error 1706. An installation
package for the product MSXML 6.0 Parser (KB933579) cannot be found. Try the installation
again using a valid copy of the installation package 'msxml6.msi'.

Error - 10/16/2008 12:25:33 AM | Computer Name = RAWR | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office Project Professional 2003 -- Error 1706.
Setup cannot find the required files. Check your connection to the network, or
CD-ROM drive. For other potential solutions to this problem, see C:\Program Files\Microsoft
Office\OFFICE11\1033\SETUP.CHM.

[ System Events ]
Error - 10/11/2008 8:42:27 PM | Computer Name = RAWR | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft SQL Server 2005 Express Edition Service Pack 2
(KB 921896).

Error - 10/13/2008 4:02:54 AM | Computer Name = RAWR | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft SQL Server 2005 Express Edition Service Pack 2
(KB 921896).

Error - 10/13/2008 5:59:06 AM | Computer Name = RAWR | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft SQL Server 2005 Express Edition Service Pack 2
(KB 921896).

Error - 10/13/2008 1:32:51 PM | Computer Name = RAWR | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft SQL Server 2005 Express Edition Service Pack 2
(KB 921896).

Error - 10/14/2008 4:02:49 AM | Computer Name = RAWR | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft SQL Server 2005 Express Edition Service Pack 2
(KB 921896).

Error - 10/14/2008 5:32:21 AM | Computer Name = RAWR | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft SQL Server 2005 Express Edition Service Pack 2
(KB 921896).

Error - 10/15/2008 12:54:31 PM | Computer Name = RAWR | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft SQL Server 2005 Express Edition Service Pack 2
(KB 921896).

Error - 10/16/2008 12:02:19 AM | Computer Name = RAWR | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.

Error - 10/16/2008 2:30:06 AM | Computer Name = RAWR | Source = Service Control Manager | ID = 7034
Description = The PnkBstrA service terminated unexpectedly. It has done this 1
time(s).

Error - 10/17/2008 4:17:09 PM | Computer Name = RAWR | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).


< End of report >

#5 lol999

lol999
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Texas, USA
  • Local time:11:33 PM

Posted 17 October 2008 - 04:15 PM

Really quick just wanted to explain the next piece of a log in OTViewIt

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\restrictrun]
"1"=vjag.vbs
"2"=C:\WINDOWS\system32\notepad.exe -- [2008/04/13 19:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation)
"3"=C:\Program Files\Microsoft Office\Office12\WINWORD.EXE -- [2008/03/22 18:20:46 | 00,349,720 | ---- | M] (Microsoft Corporation)
"4"=C:\WINDOWS\explorer.exe -- [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
"5"=C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE -- [2007/12/12 23:42:10 | 00,467,496 | ---- | M] (Microsoft Corporation)
"6"=vj.doc
"7"=C:\Program Files\Microsoft Office\Office12\EXCEL.exe -- [2008/10/15 22:46:54 | 02,189,424 | ---- | M] (Malwarebytes Corporation )


I thought to open an .exe file I had to put it in Office folder and naming it to excel.exe, this is not the case I can rename any file from any folder to excel.exe and run it. However with other extensions I have no luck.

Edited by lol999, 17 October 2008 - 04:16 PM.


#6 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:05:33 AM

Posted 17 October 2008 - 06:28 PM

You have done a great job. The information you provide is very much helping to have a clear idea about what is going on. :thumbsup:


Your log(s) show that you are using so called peer-to-peer or file-sharing programs (in your case µTorrent). These programs allow to share files between users as the name(s) suggest. In today's world the cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."


Removal Instructions
  • If you have a flash drive or external storage media it might be infected. Don't use it right now on any computer. We will clean them later on. Tell me if you have those media.

  • You have still some Norton services on your computer. They look the leftovers of an incomplete uninstall. Tell me if you are using Norton/symantec product.

  • Backup Your Registry with ERUNT
    • Please use the following link and scroll down to ERUNT and download it.
      http://aumha.org/freeware/freeware.php
    • Download the version with the Installer:
    • Use the setup program to install ERUNT on your computer.
    • Accept the default installation folder.
    • A popup window will ask you if you want to create an ERUNT entry in the start up folder. Click "No".
    • At the next window uncheck Show documentation.
    • Click Finish.
    • The program lunches and asks to make a backup of the registry. Click OK.
    • Accept the default folder by clicking OK. (c:\Windows\ERDNT\date).
    • Note the date and click OK. Please post the date in your reply.
    Note: To be able to install and then run it you may rename it.
    Note: to restore your registry, go to the installation folder and start ERUNT.exe

  • Now our first concern is to be able to return the system to normal then go on with the cleaning:
    • Please download the attached file to your desktop.
    • Locate regfix.reg on the desktop and double-click on it and confirm.
    • A window pops up asking if you are sure to add the file to the registry. Click Yes.
    • You get another window popup saying that regfix.reg successfully added to the registry.
    Note: You have to turn off any registry protector software you have in order the changes to be taken place.

  • Tell me how it went and if you are able to run exe files without renaming them.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
    • Double click on RSIT.exe to run RSIT.
    • Set the list of Files/Folders created to 3 Months.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

      Note:The logs will be created in this folder: C:\rsit

Edited by farbar, 21 October 2008 - 07:17 PM.


#7 lol999

lol999
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Texas, USA
  • Local time:11:33 PM

Posted 17 October 2008 - 07:23 PM

  • If you have a flash drive or external storage media it might be infected. Don't use it right now on any computer. We will clean them later on. Tell me if you have those media.

    • I do have an external hard drive, and several flash drives.

  • You have still some Norton services on your computer. They look the leftovers of an incomplete uninstall. Tell me if you are using Norton/symantec product...

    • I previously did have Norton, but I'm no longer using Norton/Symantec.

  • Backup Your Registry with ERUNT...

    • Done
    • Date:10-17-2008

  • Now our first concern is to be able to return the system to normal then go on with the cleaning...

    • I couldn't run regfix.reg, "Restricted Access". However I can open regedit.exe if I rename it excel.exe. Could I possibly open regedit by renaming it and then importing the regfix.reg?

  • Tell me how it went and if you are able to run exe files without renaming them...

    • Still can't run any files without renaming them to "excel.exe". There are others that work such as POWERPNT.exe and WINWORD.EXE. However, these were already working previously.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop...

  • Once again had to rename the executable file to excel.exe to open it. The logs are in the following posts. Something worth mentioning is that when running the RSIT scan, it wanted to open HiJackThis, but the access to that program was restricted. Thanks in advance for your help and time.

info.txt logfile of random's system information tool 1.04 2008-10-17 19:13:03

======Uninstall list======

-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {926CC8AE-8414-43DF-8EB4-CF26D9C3C663}
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x9
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent-->"C:\Program Files\uTorrent\uninstall.exe"
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
3DMark06-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F3AD00A-1819-4B15-BB7D-08B3586336D7}\setup.exe" -l0x9 -removeonly
Acoustica Effects Pack-->C:\PROGRA~1\ACOUST~2\UNWISE.EXE C:\PROGRA~1\ACOUST~2\INSTALL.LOG
Ad-Aware SE Personal-->MsiExec.exe /X{78CC3BAB-DE2A-4FB4-8FBB-E4DADDC26747}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop Lightroom-->MsiExec.exe /I{CBCDEDF3-A2E5-4402-8E9E-E2C23DBE1DA8}
Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Advanced Video FX Engine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x9 /remove
ALGOR InCAD Plus for Pro/ENGINEER-->"C:\Program Files\ALGOR\addins\CADProE.exe" /U "C:\Program Files\ALGOR"
AnswerWorks 4.0 Runtime - English-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}\setup.exe" -l0x9 -removeonly
Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
Belkin Wireless Utility-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{5314FAC0-F8A5-4432-8980-251D055B2C5B}
Call of Duty® 4 - Modern Warfare™ 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409
Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch-->C:\Program Files\InstallShield Installation Information\{8503C901-85D7-4262-88D2-8D8B2A7B08B8}\setup.exe -runfromtemp -l0x0409
Call of Duty® 4 - Modern Warfare™ 1.6 Patch-->C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409
Call of Duty® 4 - Modern Warfare™ 1.7 Patch-->C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409
Call of Duty® 4 - Modern Warfare™-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x0409
Differential Equations-->"C:\Program Files\Differential Equations\Uninstall_Differential Equations\Uninstall Differential Equations.exe"
DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DriverAgent by TouchStone Software-->RunDll32.exe advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove
EES - Engineering Equation Solver - Academic-->C:\EES_AV\UNWISE.EXE C:\EES_AV\INSTALL.LOG
Engineering Power Tools - v1.9.8-->"C:\Program Files\Engineering Power Tools - v1.9.8\unins000.exe"
ERUNT 1.1j-->"C:\Program Files\ERUNT\unins000.exe"
FLV Player 2.0, build 24-->C:\Program Files\FLV Player\uninst.exe
Fraps (remove only)-->"C:\Program Files\Fraps\uninstall.exe"
Garena-->C:\Program Files\InstallShield Installation Information\{89C89156-A70F-4C6D-9CAE-2EA71F1396FE}\setup.exe -runfromtemp -l0x0009 -removeonly
GOM Player-->"C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
GTK+ 2.4.14 runtime environment-->"C:\Program Files\Common Files\GTK\2.0\unins000.exe"
Gtk+ Runtime Environment 2.6.10-rc1-->C:\Program Files\Common Files\GTK\2.0\uninst.exe
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP PSC & Officejet 5.3.B Corporate Edition-->"C:\Program Files\HP\Digital Imaging\{49FB31C1-26EC-44c6-AB47-73C66E2BC41E}\setup\hpzscr01.exe" -datfile hposcr07.dat
ICCup Launcher-->"C:\Program Files\ICCup\Launcher\unins000.exe"
J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 8-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150080}
Java™ 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java™ SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
LiveUpdate 3.0 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lizardtech DjVu Control-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{105CFC7C-6992-11D5-BD9D-000102C10FD8}\Setup.exe" -l0x9
LuaEdit 3.0.3 RC-->"C:\Program Files\LuaEdit\unins000.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Mathcad 14 Help-->MsiExec.exe /I{205ACCD7-5342-4694-91F3-3A99E4FD5AA6}
Mathcad 14 Resource Center-->MsiExec.exe /I{EBD38AE9-D52D-448D-9DB4-4D5F66E1DAFC}
Mathcad 14-->MsiExec.exe /I{E666A69B-A76D-43D5-AF28-4B2150A6EDE2}
MATLAB 7.1-->C:\Program Files\MATLAB71\uninstall\uninstall.exe C:\Program Files\MATLAB71\
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Device Emulator version 1.0 - ENU-->MsiExec.exe /X{78B75C6D-E53C-424C-BF83-4B63BD4A6682}
Microsoft Document Explorer 2005-->C:\Program Files\Common Files\Microsoft Shared\Help 8\Microsoft Document Explorer 2005\install.exe
Microsoft Document Explorer 2005-->MsiExec.exe /X{44D4AF75-6870-41F5-9181-662EA05507E1}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office FrontPage 2003-->MsiExec.exe /I{90170409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Project Professional 2003-->MsiExec.exe /I{903B0409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Visio Professional 2003-->MsiExec.exe /I{90510409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)-->MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
Microsoft SQL Server 2005 Mobile [ENU] Developer Tools-->MsiExec.exe /X{1389C6A4-4965-4AEC-9175-08B54A10FA48}
Microsoft SQL Server 2005 Tools Express Edition-->MsiExec.exe /I{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}
Microsoft SQL Server 2005-->"c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)-->MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
Microsoft SQL Server Native Client-->MsiExec.exe /I{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}
Microsoft SQL Server Setup Support Files (English)-->MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
Microsoft SQL Server VSS Writer-->MsiExec.exe /I{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual J# 2.0 Redistributable Package-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft Visual J# 2.0 Redistributable Package\install.exe
Microsoft Visual Studio 2005 Professional Edition - ENU-->C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual Studio 2005 Professional Edition - ENU\setup.exe
mIRC-->"C:\Program Files\mIRC\mirc.exe" -uninstall
Motorola mobile PhoneTools-->MsiExec.exe /I{0D00056E-1A0A-4DDC-A81B-81581770DABA}
Mozilla Firefox (3.0.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
National Instruments Software-->"C:\Program Files\National Instruments\Shared\NIUninstaller\uninst.exe"
Nero 7 Premium-->MsiExec.exe /I{4781569D-5404-1F26-4B2B-6DF444441031}
NI EULA Depot-->MsiExec.exe /I{CCCCF64D-0535-4422-A3F5-605BD12A56CC}
NI MDF Support-->MsiExec.exe /I{C3E9E1F2-1EF7-4086-A8B5-858E3DEB9BAE}
NTE: Strike and Retrieve-->"C:\Program Files\NTE\Strike and Retrieve\unins000.exe"
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
NVIDIA nTune-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF} /l1033
overland-->MsiExec.exe /I{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}
PeerGuardian 2.0-->"C:\Program Files\PeerGuardian2\unins000.exe"
Pro/ENGINEER Mechanica Release Wildfire 3.0 Datecode M030-->"C:\Program Files\mechWildfire 3.0\uninstall\i486_nt\obj\psuninst.exe" "C:\Program Files\mechWildfire 3.0\uninstall\instlog.txt"
Pro/ENGINEER Release Wildfire 3.0 Datecode M030-->"C:\Program Files\proeWildfire 3.0\uninstall\i486_nt\obj\psuninst.exe" "C:\Program Files\proeWildfire 3.0\uninstall\instlog.txt"
PSpice Student 9.1-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\OrCAD_Demo\DeIsL1.isu"
PTC Distributed Services Release Wildfire 3.0 Datecode M030-->"C:\Program Files\ptc_distributed_services\uninstall\i486_nt\obj\psuninst.exe" "C:\Program Files\ptc_distributed_services\uninstall\instlog.txt"
PTC License Server Release Wildfire 3.0 Datecode M030-->"C:\Program Files\flexnet\uninstall\i486_nt\obj\psuninst.exe" "C:\Program Files\flexnet\uninstall\instlog.txt"
QuickTime-->MsiExec.exe /I{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for 2007 Microsoft Office System (KB955936)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1D94099C-2BBA-440E-BD5E-093BBDF8F028}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft Office Excel 2007 (KB955470)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6E8637D8-10D6-4568-AA06-E2706F31685E}
Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB951808)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office Word 2007 (KB950113)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
Security Update for Microsoft Visual Studio 2005 Professional Edition - ENU (KB925674)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {124D38C7-5BE5-4D4E-8D6D-9F10DC6B6D11} /package {437AB8E0-FB69-4222-B280-A64F3DE22591}
Security Update for Microsoft Visual Studio 2005 Professional Edition - ENU (KB937060)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {78DD9A0A-4AE1-46D0-B9A6-578EFCA47A3C} /package {437AB8E0-FB69-4222-B280-A64F3DE22591}
Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Sentinel System Driver-->C:\WINDOWS\SYSTEM32\RNBOSENT\SETUPX86.EXE /U /q
Sony Media Manager 2.0-->MsiExec.exe /X{C589B6DE-F7BF-4E22-8524-53E115EF6AB4}
Sony Media Manager 2.2-->MsiExec.exe /X{C9E129BC-27D3-436E-BAAC-4CE81E0962F1}
Sony Vegas 7.0-->MsiExec.exe /X{96965E6C-41DB-4E0A-BC65-D92381D51D2A}
SopCast 3.0.3-->C:\Program Files\SopCast\uninst.exe
SPORE™-->"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\SPORESetup.exe" -runfromtemp -l0x0009 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Starcraft-->C:\WINDOWS\SCunin.exe C:\WINDOWS\SCunin.dat
Symantec KB-DocID:2003093015493306-->MsiExec.exe /I{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}
The GIMP 2.2.15-->"C:\Program Files\GIMP-2.0\unins000.exe"
TI Connect 1.6-->MsiExec.exe /I{A8B94669-8654-4126-BD28-D0D2412CDED6}
TI NoteFolio Creator-->MsiExec.exe /I{F07AE5AB-516C-4CEB-A0AA-AD083B9182C6}
TurboTax Deluxe 2007-->C:\Program Files\TurboTax\Deluxe 2007\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2007\Uninstall.log" -NoGui
TurboTax Deluxe Deduction Maximizer 2006-->C:\Program Files\TurboTax\Deluxe 2006\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2006\Uninstall.log" -NoGui
TurboTax ItsDeductible 2006-->MsiExec.exe /X{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}
TVAnts 1.0-->C:\PROGRA~1\TVAnts\UNWISE.EXE C:\PROGRA~1\TVAnts\INSTALL.LOG
TVUPlayer 2.3.6.1-->C:\Program Files\TVUPlayer\uninst.exe
Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
Update for Office 2007 (KB946691)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb957258)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {E070CDA4-A8DD-47FA-89A0-F5DA5D5DDFF9}
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
VideoLAN VLC media player 0.8.6a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Warkeys 1.8.0.0b-->C:\Program Files\Warkeys\uninst.exe
WC3Banlist-->"C:\Program Files\WC3Banlist\unins000.exe"
WeatherMan 1.x-->C:\PROGRA~1\WEATHE~1\UNWISE.EXE C:\PROGRA~1\WEATHE~1\INSTALL.LOG
WexTech AnswerWorks-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}\SETUP.EXE" -l0x9 -eliminate
Winamp (remove only)-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Live Messenger-->MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Vista Upgrade Advisor-->MsiExec.exe /I{F80BA35D-D1CD-4B8B-8129-9FC918F9D42D}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinPcap 4.0.2-->C:\Program Files\WinPcap\uninstall.exe
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
ZyXEL G-202 Wireless Adapter Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C5D78EFC-A9C1-44F3-81CB-D42C5DF8EA09}\Setup.exe" -l0x9

=====HijackThis Backups=====

O4 - HKLM\..\Run: [vjag] C:\WINDOWS\system32\auto\vjag3.bat
O20 - Winlogon Notify: cbxxutt - C:\WINDOWS\
O4 - HKLM\..\Run: [vjag2] C:\WINDOWS\system32\auto\vjag.vbs
O2 - BHO: (no name) - {CC08F073-6F7D-462B-91C8-F9FAFF3FC14C} - C:\WINDOWS\system32\mlljg.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

======Hosts File======

127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1 www.032439.com

======Security center information======

AV: Avira AntiVir PersonalEdition Premium
AV: Avira AntiVir PersonalEdition

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%GTK_BASEPATH%\bin;%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;c:\program files\microsoft sql server\90\tools\binn\;c:\program files\quicktime\qtsystem\;c:\program files\microsoft sql server\80\tools\binn\;c:\program files\common files\gtk\2.0\bin;c:\program files\mechwildfire 3.0\bin;c:\program files\ptc_distributed_services\bin;c:\program files\flexnet\bin;c:\program files\proewildfire 3.0\bin;C:\Program Files\MATLAB71\bin\win32;;C:\Program Files\ALGOR
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"VS80COMNTOOLS"=C:\Program Files\Microsoft Visual Studio 8\Common7\Tools\
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip
"KMP_DUPLICATE_LIB_OK"=TRUE
"MKL_SERIAL"=YES
"PRO_COMM_MSG_EXE"=C:\Program Files\proeWildfire 3.0\i486_nt\obj\pro_comm_msg.exe
"PANGO_WIN32_NO_UNISCRIBE"=anything
"GTK_BASEPATH"=C:\PROGRA~1\COMMON~1\GTK\2.0

-----------------EOF-----------------

Logfile of random's system information tool 1.04 (written by random/random)
Run by James at 2008-10-17 19:12:50
Microsoft Windows XP Professional Service Pack 3
System drive C: has 29 GB (20%) free of 143 GB
Total RAM: 2047 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:55:00 PM, on 10/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\excel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {CC08F073-6F7D-462B-91C8-F9FAFF3FC14C} - C:\WINDOWS\system32\mlljg.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [vjag] C:\WINDOWS\system32\auto\vjag3.bat
O4 - HKLM\..\Run: [vjag2] C:\WINDOWS\system32\auto\vjag.vbs
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Microsoft Office Outlook 2007.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BBFD2D10-EC6E-4259-91D1-1E38C826E5E2} (Launcher Class) - http://app.gomtv.com/gomtv/gomtvx.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: cbxxutt - C:\WINDOWS\
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXlm server for PTC - Macrovision Corporation - C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 10534 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2007-08-31 1122128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-12-21 7774208]
"nwiz"=nwiz.exe /install []
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"NVIDIA nTune"=C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-01-08 81920]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"P17Helper"=Rundll32 P17.dll []
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2006-11-21 35328]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-12-21 81920]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe [2007-02-06 61440]
"HP Component Manager"=C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2004-05-12 241664]
"NWEReboot"= []
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-09-01 282624]
"AVFX Engine"=C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe [2006-06-09 24576]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-04-13 185896]
"removecpl"=RemoveCpl.exe []
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-07-17 266497]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup []
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-08-09 81920]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe /runcleanupscript []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2005-09-03 94208]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2007-04-03 165784]
"PeerGuardian"=C:\Program Files\PeerGuardian2\pg2.exe [2005-09-18 1421824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Octoshape Streaming Services]
C:\Program Files\Octoshape Streaming Services\James\OctoshapeClient.exe [2008-05-22 156944]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless Utility.lnk]
C:\PROGRA~1\Belkin\PCIF5D~1\WIRELE~1\BELKIN~1.EXE [2005-08-18 1388544]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Microsoft Office Outlook 2007.lnk - C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\mlljg.dll

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"Restrictrun"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"AllowLegacyWebView"=
"AllowUnhashedWebView"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client"
"C:\Program Files\Octoshape Streaming Services\James\OctoshapeClient.exe"="C:\Program Files\Octoshape Streaming Services\James\OctoshapeClient.exe:*:Enabled:OctoshapeClient"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\TVUPlayer\TVUPlayer.exe"="C:\Program Files\TVUPlayer\TVUPlayer.exe:*:Enabled:TVUPlayer Component"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Documents and Settings\James\My Documents\Cod4MP\The All-Seeing Eye\eye.exe"="C:\Documents and Settings\James\My Documents\Cod4MP\The All-Seeing Eye\eye.exe:*:Enabled:Yahoo! All-Seeing Eye"
"C:\Program Files\National Instruments\LabVIEW 8.2\LabVIEW.exe"="C:\Program Files\National Instruments\LabVIEW 8.2\LabVIEW.exe:*:Enabled:LabVIEW 8.2 Development System"
"C:\Program Files\DAUM\PotPlayer\daumvsvr.exe"="C:\Program Files\DAUM\PotPlayer\daumvsvr.exe:*:Enabled:DaumCP VoD Server"
"C:\Program Files\DAUM\PotPlayer\PotPlayer.exe"="C:\Program Files\DAUM\PotPlayer\PotPlayer.exe:*:Enabled:?? ?????"
"C:\Program Files\PPLive\PPLive.exe"="C:\Program Files\PPLive\PPLive.exe:*:Enabled:PPLive"
"C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty® 4 - Modern Warfare™ "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e0c54c3-7f50-11dd-b5ba-001617ef3ff9}]
shell\AutoRun\command - G:\auto\vstart.bat
shell\explore\command - G:\auto\vstart.bat
shell\open\command - G:\auto\vstart.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{815c276a-8e4f-11dd-b5d9-001617ef3ff9}]
shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3176a75-155a-11dd-b533-001617ef3ff9}]
shell\AutoRun\command - G:\LaunchU3.exe -a


======List of files/folders created in the last 3 months======

2008-10-17 19:12:50 ----D---- C:\rsit
2008-10-17 19:04:35 ----D---- C:\Program Files\ERUNT
2008-10-16 19:53:03 ----D---- C:\Program Files\Trend Micro
2008-10-15 23:01:49 ----D---- C:\Avenger
2008-10-15 23:01:49 ----A---- C:\avenger.txt
2008-10-15 22:51:21 ----D---- C:\Documents and Settings\James\Application Data\Malwarebytes
2008-10-15 22:51:18 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-15 22:51:18 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-15 12:24:58 ----A---- C:\WINDOWS\systed.txt
2008-10-15 12:23:27 ----A---- C:\WINDOWS\systec.txt
2008-10-15 11:55:37 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-10-15 11:55:33 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-10-15 11:55:29 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-10-15 11:55:08 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-10-15 11:54:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-10-15 11:51:10 ----A---- C:\WINDOWS\systeb.txt
2008-10-14 12:34:15 ----ASHD---- C:\auto
2008-10-14 12:34:13 ----A---- C:\WINDOWS\syste.txt
2008-10-14 12:34:12 ----ASHD---- C:\WINDOWS\system32\auto
2008-10-06 23:28:02 ----A---- C:\LOGF3.tmp
2008-09-24 10:57:03 ----A---- C:\WINDOWS\system32\tpaerr.txt
2008-09-21 22:17:12 ----D---- C:\Program Files\DiskInternals
2008-09-19 17:30:47 ----D---- C:\Program Files\HTML Help Workshop
2008-09-19 17:26:04 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-18 23:10:37 ----A---- C:\WINDOWS\system32\muweb.dll
2008-09-18 23:10:37 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2008-09-18 23:10:37 ----A---- C:\WINDOWS\system32\mucltui.dll
2008-09-18 22:56:09 ----A---- C:\WINDOWS\system32\msonpmon.dll
2008-09-18 14:05:20 ----D---- C:\Documents and Settings\James\Application Data\Thunderbird
2008-09-18 02:09:04 ----A---- C:\WINDOWS\system32\OGACheckControl.dll
2008-09-17 12:44:35 ----D---- C:\Documents and Settings\James\Application Data\U3
2008-09-15 22:24:47 ----A---- C:\shutdown.bat
2008-09-15 21:20:30 ----D---- C:\Program Files\Common Files\LPG Shared
2008-09-15 13:39:34 ----D---- C:\Documents and Settings\James\Application Data\SPORE
2008-09-15 13:36:01 ----RHD---- C:\Documents and Settings\James\Application Data\SecuROM
2008-09-15 13:27:23 ----D---- C:\Program Files\Electronic Arts
2008-09-15 12:22:33 ----A---- C:\WINDOWS\system32\libusb0.dll
2008-09-10 16:30:01 ----A---- C:\WINDOWS\system32\DEBUG_LOG.txt
2008-09-10 01:40:23 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-09-10 01:39:58 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-08 23:01:40 ----A---- C:\WINDOWS\system32\ptpusb.dll
2008-09-08 23:01:39 ----A---- C:\WINDOWS\system32\ptpusd.dll
2008-09-08 21:42:29 ----D---- C:\WINDOWS\system32\Adobe
2008-09-08 20:55:35 ----D---- C:\Program Files\Common Files\SpellEx
2008-09-08 20:32:50 ----D---- C:\Program Files\TI Education
2008-09-08 20:32:50 ----D---- C:\Program Files\Common Files\TI Shared
2008-09-04 11:24:13 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-09-03 16:53:57 ----D---- C:\WINDOWS\Prefetch
2008-09-03 16:50:41 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-09-03 16:50:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-09-03 16:50:32 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-09-03 16:50:28 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-09-03 16:50:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-09-03 16:50:20 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-09-03 16:50:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-09-03 16:50:11 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-09-03 16:50:07 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-09-03 16:50:02 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-09-03 16:47:57 ----D---- C:\WINDOWS\system32\scripting
2008-09-03 16:47:57 ----D---- C:\WINDOWS\system32\en
2008-09-03 16:47:57 ----D---- C:\WINDOWS\l2schemas
2008-09-03 16:47:56 ----D---- C:\WINDOWS\system32\bits
2008-09-03 16:46:28 ----D---- C:\WINDOWS\ServicePackFiles
2008-09-03 16:42:27 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-27 17:22:47 ----N---- C:\WINDOWS\system32\wmphoto.dll
2008-08-27 17:22:46 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-08-27 17:22:46 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-27 17:22:46 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-27 17:22:44 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-08-27 17:22:44 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-08-27 17:22:43 ----N---- C:\WINDOWS\system32\spupdwxp.exe
2008-08-27 17:22:43 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slserv.exe
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slrundll.exe
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slgen.dll
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slextspk.dll
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slcoinst.dll
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\setupn.exe
2008-08-27 17:22:41 ----N---- C:\WINDOWS\slrundll.exe
2008-08-27 17:22:40 ----N---- C:\WINDOWS\system32\s3gnb.dll
2008-08-27 17:22:40 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-27 17:22:40 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-08-27 17:22:40 ----N---- C:\WINDOWS\system32\qutil.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\qagent.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\onex.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\napstat.exe
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\mssha.dll
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-27 17:22:28 ----N---- C:\WINDOWS\system32\smtpapi.dll
2008-08-27 17:22:28 ----N---- C:\WINDOWS\system32\rwnh.dll
2008-08-27 17:22:27 ----N---- C:\WINDOWS\system32\comsdupd.exe
2008-08-27 17:22:26 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\faxpatch.exe
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-08-27 17:22:25 ----A---- C:\WINDOWS\003070_.tmp
2008-08-27 17:22:24 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-08-27 17:22:24 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-27 17:22:24 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-27 17:22:24 ----N---- C:\WINDOWS\system32\credssp.dll
2008-08-27 17:22:22 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-27 17:22:22 ----N---- C:\WINDOWS\system32\azroles.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati3duag.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2008-08-27 17:22:20 ----N---- C:\WINDOWS\system32\aaclient.dll
2008-08-16 09:57:40 ----D---- C:\Program Files\NTE
2008-08-15 03:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2008-08-15 03:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2008-08-15 03:02:11 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$
2008-08-15 03:02:07 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2008-08-15 03:01:04 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-08-15 03:00:58 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2008-08-15 03:00:34 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2008-08-07 18:02:19 ----D---- C:\Program Files\Microsoft Silverlight
2008-07-25 05:02:23 ----A---- C:\WINDOWS\system32\javaws.exe
2008-07-25 05:02:23 ----A---- C:\WINDOWS\system32\javaw.exe
2008-07-25 05:02:23 ----A---- C:\WINDOWS\system32\java.exe

======List of files/folders modified in the last 3 months======

2008-10-17 19:05:27 ----D---- C:\WINDOWS\erdnt
2008-10-17 19:04:35 ----RD---- C:\Program Files
2008-10-17 17:48:26 ----D---- C:\WINDOWS\TEMP
2008-10-17 16:37:11 ----D---- C:\WINDOWS\system32\CatRoot2
2008-10-17 15:15:31 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-10-17 15:02:36 ----D---- C:\WINDOWS
2008-10-17 15:01:06 ----D---- C:\WINDOWS\system32\Macromed
2008-10-17 05:21:52 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-10-17 05:21:51 ----HD---- C:\WINDOWS\inf
2008-10-16 17:43:23 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-15 23:25:33 ----SHD---- C:\WINDOWS\Installer
2008-10-15 23:25:33 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-10-15 23:25:33 ----HD---- C:\Config.Msi
2008-10-15 23:01:49 ----D---- C:\WINDOWS\system32\drivers
2008-10-15 23:00:11 ----D---- C:\WINDOWS\system32
2008-10-15 13:38:54 ----D---- C:\Program Files\Common Files
2008-10-15 13:21:15 ----D---- C:\Program Files\ALGOR
2008-10-15 13:20:00 ----D---- C:\WINDOWS\WinSxS
2008-10-15 13:14:52 ----D---- C:\Program Files\Gravity
2008-10-15 12:51:29 ----D---- C:\Program Files\LimeWire
2008-10-15 12:43:37 ----D---- C:\Program Files\MSN Messenger
2008-10-15 12:42:53 ----D---- C:\Program Files\DAUM
2008-10-15 12:02:40 ----D---- C:\Program Files\Mozilla Firefox
2008-10-15 11:55:57 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-15 11:55:38 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-10-15 11:55:36 ----HD---- C:\WINDOWS\$hf_mig$
2008-10-15 11:55:35 ----A---- C:\WINDOWS\imsins.BAK
2008-10-15 11:55:23 ----D---- C:\Program Files\Internet Explorer
2008-10-15 11:52:31 ----D---- C:\WINDOWS\Registration
2008-10-13 19:53:32 ----D---- C:\Documents and Settings\James\Application Data\Move Networks
2008-10-13 18:30:25 ----A---- C:\WINDOWS\NeroDigital.ini
2008-10-10 00:00:21 ----D---- C:\Program Files\PeerGuardian2
2008-10-08 16:01:53 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2008-10-07 14:19:40 ----A---- C:\WINDOWS\system32\MRT.exe
2008-10-06 15:35:39 ----SD---- C:\Documents and Settings\James\Application Data\Microsoft
2008-10-03 12:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
2008-10-01 18:46:38 ----A---- C:\WINDOWS\win.ini
2008-09-30 15:00:01 ----D---- C:\Documents and Settings\James\Application Data\uTorrent
2008-09-28 21:19:02 ----D---- C:\WINDOWS\Minidump
2008-09-24 11:13:13 ----D---- C:\Program Files\WeatherMan
2008-09-22 23:46:34 ----D---- C:\Documents and Settings\James\Application Data\dvdcss
2008-09-19 17:35:04 ----AC---- C:\WINDOWS\vbaddin.ini
2008-09-19 17:34:52 ----RSD---- C:\WINDOWS\assembly
2008-09-19 17:34:38 ----D---- C:\WINDOWS\Microsoft.NET
2008-09-19 17:30:47 ----D---- C:\Program Files\Common Files\Microsoft Shared
2008-09-18 23:08:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-18 23:01:27 ----D---- C:\WINDOWS\SHELLNEW
2008-09-18 23:00:15 ----D---- C:\Program Files\Microsoft Visual Studio 8
2008-09-18 22:56:02 ----D---- C:\WINDOWS\system32\config
2008-09-18 22:54:23 ----D---- C:\Program Files\Microsoft Works
2008-09-18 22:53:58 ----D---- C:\Program Files\Microsoft Office
2008-09-18 22:50:53 ----D---- C:\WINDOWS\Help
2008-09-18 14:05:21 ----D---- C:\Documents and Settings\James\Application Data\Mozilla
2008-09-17 10:20:25 ----SH---- C:\boot.ini
2008-09-17 10:20:25 ----A---- C:\WINDOWS\system.ini
2008-09-15 21:15:51 ----D---- C:\WINDOWS\twain_32
2008-09-15 16:59:36 ----SD---- C:\WINDOWS\Tasks
2008-09-15 13:36:00 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2008-09-15 13:20:46 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-11 12:12:03 ----D---- C:\Program Files\Adobe
2008-09-08 23:28:17 ----SHD---- C:\RECYCLER
2008-09-08 23:28:13 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-09-08 20:32:51 ----D---- C:\WINDOWS\system
2008-09-03 16:56:08 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-03 16:54:57 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-09-03 16:54:01 ----AC---- C:\WINDOWS\setuplog.txt
2008-09-03 16:53:43 ----D---- C:\WINDOWS\system32\Setup
2008-09-03 16:53:43 ----D---- C:\WINDOWS\ime
2008-09-03 16:53:43 ----D---- C:\WINDOWS\AppPatch
2008-09-03 16:53:42 ----D---- C:\WINDOWS\system32\wbem
2008-09-03 16:52:17 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-03 16:50:03 ----D---- C:\Program Files\Messenger
2008-09-03 16:48:06 ----D---- C:\WINDOWS\system32\inetsrv
2008-09-03 16:48:06 ----D---- C:\WINDOWS\network diagnostic
2008-09-03 16:47:57 ----D---- C:\WINDOWS\system32\usmt
2008-09-03 16:47:57 ----D---- C:\WINDOWS\system32\en-US
2008-09-03 16:47:56 ----D---- C:\WINDOWS\PeerNet
2008-09-03 16:47:56 ----D---- C:\Program Files\Movie Maker
2008-09-03 16:46:21 ----D---- C:\WINDOWS\system32\Restore
2008-09-03 16:46:21 ----D---- C:\WINDOWS\system32\npp
2008-09-03 16:46:21 ----D---- C:\WINDOWS\mui
2008-09-03 16:46:20 ----D---- C:\WINDOWS\msagent
2008-09-03 16:46:19 ----D---- C:\WINDOWS\srchasst
2008-09-03 16:46:18 ----D---- C:\WINDOWS\system32\Com
2008-09-03 16:46:18 ----D---- C:\Program Files\NetMeeting
2008-09-03 16:46:16 ----D---- C:\Program Files\Windows NT
2008-09-03 16:46:16 ----D---- C:\Program Files\Windows Media Player
2008-09-03 16:46:16 ----D---- C:\Program Files\Outlook Express
2008-09-03 16:46:14 ----D---- C:\Program Files\Common Files\System
2008-09-03 16:46:01 ----D---- C:\WINDOWS\system32\oobe
2008-09-03 16:44:00 ----D---- C:\WINDOWS\security
2008-09-03 16:43:57 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-09-03 16:42:25 ----D---- C:\WINDOWS\ehome
2008-08-27 17:13:08 ----D---- C:\WINDOWS\Debug
2008-08-27 03:24:32 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-08-26 02:24:31 ----A---- C:\WINDOWS\system32\wininet.dll
2008-08-26 02:24:31 ----A---- C:\WINDOWS\system32\webcheck.dll
2008-08-26 02:24:31 ----A---- C:\WINDOWS\system32\urlmon.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\url.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\pngfilt.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\occache.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\mstime.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\msrating.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\mshtmled.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\msfeeds.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\jsproxy.dll
2008-08-26 02:24:29 ----A---- C:\WINDOWS\system32\iertutil.dll
2008-08-26 02:24:29 ----A---- C:\WINDOWS\system32\iernonce.dll
2008-08-26 02:24:29 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\ieaksie.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\ieakeng.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\icardie.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\extmgr.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\dxtrans.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\advpack.dll
2008-08-25 03:38:00 ----A---- C:\WINDOWS\system32\ieudinit.exe
2008-08-25 03:37:59 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2008-08-23 00:54:51 ----A---- C:\WINDOWS\system32\ieakui.dll
2008-08-19 05:32:20 ----D---- C:\Program Files\uTorrent
2008-08-14 05:09:26 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 04:33:16 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-25 05:02:23 ----D---- C:\Program Files\Java
2008-07-18 22:10:48 ----A---- C:\WINDOWS\system32\cdm.dll
2008-07-18 22:10:42 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-07-18 22:10:40 ----A---- C:\WINDOWS\system32\wups2.dll
2008-07-18 22:10:24 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2008-07-18 22:10:20 ----A---- C:\WINDOWS\system32\wups.dll
2008-07-18 22:09:46 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-07-18 22:09:44 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-07-18 22:09:44 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-07-18 22:09:42 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-07-18 22:09:42 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2008-07-18 22:08:34 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2008-07-18 10:03:10 ----D---- C:\Program Files\WC3Banlist

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-07-17 75072]
R1 DhaHelper;DhaHelper; \??\C:\WINDOWS\system32\drivers\dhahelper.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-04-20 17801]
R2 cvintdrv;cvintdrv; C:\WINDOWS\system32\drivers\cvintdrv.sys [2006-07-27 4096]
R2 nxsIO32;NextSensor Kernel I/O Driver; \??\C:\WINDOWS\System32\DRIVERS\nxsIO32.sys []
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [1999-07-20 73216]
R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys []
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2005-01-10 138752]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-12-21 5747488]
R3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2005-01-10 106496]
R3 P17;SB Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys [2007-06-15 1127936]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-07-21 82432]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S3 ar5a9ty5;ar5a9ty5; C:\WINDOWS\system32\drivers\ar5a9ty5.sys []
S3 BLKWGD;Belkin Wireless G Desktop Card Service; C:\WINDOWS\system32\DRIVERS\BLKWGD.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\James\LOCALS~1\Temp\catchme.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-24 4353024]
S3 libusb0;LibUsb-Win32 - Kernel Driver 03/20/2007, 0.1.12.1; C:\WINDOWS\system32\DRIVERS\libusb0.sys [2008-09-15 33792]
S3 nm;Network Monitor Driver; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 pgfilter;pgfilter; \??\C:\Program Files\PeerGuardian2\pgfilter.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 TiglUsb;TiglUsb.sys TI-GRAPH / DIRECT LINK USB driver; C:\WINDOWS\System32\Drivers\TiglUsb.sys []
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 wlanndi5;wlanndi5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\wlanndi5.SYS []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZDCNDIS5;ZDCNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\ZDCndis5.SYS []
S3 ZY202_XP;ZyXEL 802.11g XG202 1211 Driver; C:\WINDOWS\system32\DRIVERS\WlanUZXP.sys [2006-11-27 437760]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Atheros Configuration Service; C:\WINDOWS\system32\acs.exe [2005-05-05 36864]
R2 AntiVirScheduler;Avira AntiVir Personal – Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-07-17 68865]
R2 AntiVirService;Avira AntiVir Personal – Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-08-14 149761]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-07-25 100032]
R2 FLEXlm server for PTC;FLEXlm server for PTC; C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe [2007-11-20 1294336]
R2 LkCitadelServer;Lookout Citadel Server; C:\WINDOWS\system32\lkcitdl.exe [2006-06-19 688190]
R2 lkClassAds;National Instruments PSP Server Locator; C:\WINDOWS\system32\lkads.exe [2006-07-25 45056]
R2 lkTimeSync;National Instruments Time Synchronization; C:\WINDOWS\system32\lktsrv.exe [2006-07-25 57344]
R2 matlabserver;MATLAB Server; C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe [2005-07-27 536576]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2005-10-14 28768528]
R2 mxssvr;NI Configuration Manager; C:\Program Files\National Instruments\MAX\nimxs.exe [2006-07-15 5728]
R2 NIDomainService;National Instruments Domain Service; C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe [2006-07-25 200704]
R2 niSvcLoc;NI Service Locator; C:\WINDOWS\system32\nisvcloc.exe [2006-02-06 49152]
R2 NITaggerService;National Instruments Variable Engine; C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe [2006-07-25 696320]
R2 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-01-08 118784]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-04-24 66872]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2007-02-10 89968]
R2 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2007-01-25 1174152]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-12-21 168004]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-07-25 2119360]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
S3 NILM License Manager;NILM License Manager; C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe [2006-06-27 1007616]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 OpcEnum;OpcEnum; C:\WINDOWS\system32\OpcEnum.exe [2004-12-02 98304]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2006-10-26 2799808]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2005-10-14 239320]

-----------------EOF-----------------

Edited by lol999, 17 October 2008 - 07:29 PM.


#8 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:05:33 AM

Posted 18 October 2008 - 04:34 AM

Thanks for the thorough feedback.

Please download the attached batch file. Run it without renaming. When you run it the command window flashes and the file itself is removed.

Edited by farbar, 21 October 2008 - 07:17 PM.


#9 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:05:33 AM

Posted 18 October 2008 - 08:22 AM

Adding to the last post since the patch file has the same name as the malware your Antivirus might block or remove it. To take care of that you should disable antivirus gaurd.

If you don't know how visit:
How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

#10 lol999

lol999
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Texas, USA
  • Local time:11:33 PM

Posted 18 October 2008 - 06:57 PM

Alright, I'll try all this once I get back to my apartment on Sunday night; right now I'm at home. Thanks once again for the help.

#11 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:05:33 AM

Posted 18 October 2008 - 07:27 PM

Take your time and you are welcome.

#12 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:05:33 AM

Posted 18 October 2008 - 08:17 PM

As an extra precaution please run (renamed) Erunt once more to make a fresh backup of the registry.

#13 lol999

lol999
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Texas, USA
  • Local time:11:33 PM

Posted 19 October 2008 - 08:35 PM

Alright just got back. Everything you posted was done in the following order.
  • As an extra precaution please run (renamed) Erunt once more to make a fresh backup of the registry.

    • Done
    • Date: 10-19-2008

  • Adding to the last post since the patch file has the same name as the malware your Antivirus might block or remove it. To take care of that you should disable antivirus gaurd.

    • I couldn't disable antivir since the system tray icon doesn't load, and I can't open it even with renaming. However it didn't affect the bat file from opening

  • Please download the attached batch file. Run it without renaming. When you run it the command window flashes and the file itself is removed.

    • Done
Haven't restarted or anything, but I currently can't open anything by simply renaming it to excel.exe.

Update: So I don't what that vjag.bat file did but it worked like a charm, I rebooted and now everything works just fine. All programs open without any renaming required.

Edited by lol999, 19 October 2008 - 10:28 PM.


#14 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:05:33 AM

Posted 20 October 2008 - 01:09 AM

Update: So I don't what that vjag.bat file did but it worked like a charm, I rebooted and now everything works just fine. All programs open without any renaming required.


Good news. This is a new type of malware, some antvirus just detect and remove some files but not repair the damage. We had to improvise to find out the cure.


We are going to disinfect all your flash drives and storage media. Please have them ready to be connected when instructed.
  • Please run Notepad (start > All Programs > Accessories > Notepad) and copy and paste the text in the code box into a new file:

    @ECHO OFF
    IF EXIST log.txt DEL log.txt
    ECHO Deleting files>>log.txt
    FOR %%g in (
    "C:\Documents and Settings\James\Desktop\MatiasPres.pptx"
    C:\WINDOWS\System32\vjag.doc
    C:\WINDOWS\system32\auto\vjag.vbs
    C:\WINDOWS\system32\auto\vjag3.bat) DO (
    IF EXIST %%g (
    ATTRIB -r -s -h %%g
    DEL %%g
    IF EXIST %%g (
    ECHO %%g not deleted>>log.txt
    ) ELSE (
    ECHO %%g deleted successfully>>log.txt)
    ) ELSE (
    ECHO %%g not found>>log.txt))
    >>log.txt (
    ECHO.
    ECHO Deleting folders)
    FOR %%I in (
    C:\auto
    C:\WINDOWS\System32\auto) DO (
    IF EXIST %%I (
    RD /S /Q %%I
    IF EXIST %%I (
    ECHO %%I not deleted>>log.txt
    ) ELSE (
    ECHO %%I deleted successfully>>log.txt)
    ) ELSE (
    ECHO %%I not found>>log.txt))
    START NOTEPAD.EXE log.txt
    • Select save in:desktop
    • Fill in File name: remove.bat
    • Save as type: All file types (*.*)
    • Click Save and close the Notepad.
    • Double-click remove.bat on the desktop.
    • Copy/paste the content of the log.txt which opens up.
  • We need to repair a security related registry value altered by the malware. Open a notepad (Start > Run and type in Notepad ) make sure the wordwrap under Format menu is not selected.
    Copy and paste the text in code box into it.

    REGEDIT4 
    
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
    • Save the file to the desktop as regfix.reg
    • Make sure the Save as type field says All files.
    • Locate regfix.reg on the desktop and double-click on it and confirm.
    • A window pops up asking if you are sure to add the file to the registry. Click Yes.
    • You get another window popup saying that regfix.reg successfully added to the registry.
    Note: You have to turn off any registry protector software you have in order the changes to be taken place.

  • Open notepad, make sure the wordwrap under format menu is not selected
    Copy and paste the text in the code box in it:

    if exist Export.txt del /q Export.txt
    regedit /e Export.txt "HKEY_USERS\S-1-5-21-602162358-823518204-725345543-1003"
    notepad Export.txt
    del look.bat
    • Go to the File menu at the top of the Notepad and select Save as.
    • Select save in: desktop
    • Fill in File name: look.bat
    • Save as type: All files.
    • Click save
    • Close the Notepad.
    • Locate and double-click look.bat on the desktop.
    • Notepad will open with some text in it. Copy and paste the contents (Export.txt) in your next reply. If the log is too long please attach it to the post.
  • To remove the Norton Antivirus leftovers please download and run the Norton Removal Tool.

    Warning: The Norton Removal Tool uninstalls all Norton 2008/2007/2006/2005/2004/2003 products and Norton 360 from your computer. If you use ACT! or WinFAX, back up those databases before you proceed.

  • Please read this carefully: http://www.zyxware.com/articles/2007/08/14...virus-infection

    Note: It is important to have autoplay feature turned off and not to open the thump drives by double clicking. Instead rightclick the drive and select Explore

    How do I turn off Autoplay in Windows XP for my external hard drive?
    • Open My Computer.
    • Right click on the drive letter assigned to your external drive.
    • Choose properties.
    • Click on the Autoplay tab.
    • Click the "Select an action to perform" option.
    • Choose "Take no action."
    • Click OK .
  • Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
    • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • Reboot your computer when done.
    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

  • To make sure there is no file with the name vstart.bat on your flash drives or any storage device with G drive letter (when the device is connected start > My computer, there the drive with letter G is the drive which should be checked) connect the drive with letter G.
    • Please make sure that you can view all system and hidden files. Instructions on how to do this can be found here:
      How to see hidden files in Windows
    • Right-click the drive G, select Explore and check the existence of vstart.bat, if present remove it.
  • Please download ATF Cleaner by Atribune & save it to your desktop.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main "Select Files to Delete" choose: Select All.
    • Click the Empty Selected button.
    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords, please click No at the prompt.
    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords, please click No at the prompt.
    • Click Exit on the Main menu to close the program.
    Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

  • In previous run of RSIT since the access to HJT was restricted it produced the old stored HJT log. For one moment I thought the infection was returned, but thanks to your feedback, checking the dates and comparing the logs my concern subsided. Please run RSIT again and post the log. It produces one log this time (log.txt).

Please copy/paste in your next reply:
  • The log.txt.
  • The Export.txt.
  • A fresh RSIT log.


#15 lol999

lol999
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Texas, USA
  • Local time:11:33 PM

Posted 20 October 2008 - 02:08 AM

  • Please run Notepad (start > All Programs > Accessories > Notepad) and copy and paste the text in the code box into a new file...

    • Done. Log is the following:
    ===================
    LOG.TXT
    Deleting files
    "C:\Documents and Settings\James\Desktop\MatiasPres.pptx" deleted successfully
    C:\WINDOWS\System32\vjag.doc deleted successfully
    C:\WINDOWS\system32\auto\vjag.vbs deleted successfully
    C:\WINDOWS\system32\auto\vjag3.bat deleted successfully

    Deleting folders
    C:\auto deleted successfully
    C:\WINDOWS\System32\auto deleted successfully
    ==================

  • We need to repair a security related registry value altered by the malware. Open a notepad (Start > Run and type in Notepad ) make sure the wordwrap under Format menu is not selected.

    • Done

  • Export.txt

    • The file is 23.8Mb and can't seem to attach it to this post. Should I just paste it in various posts?

  • To remove the Norton Antivirus leftovers please download and run the Norton Removal Tool.

    • I haven't done this step due to I have no clue what version of Norton I had. Is there anyway I can find out?

  • Please read this carefully: http://www.zyxware.com/articles/2007/08/14...virus-infection

    • Done

  • Please download Flash_Disinfector.exe by sUBs and save it to your desktop.

    • I cleaned my flash drive, but have yet to clean my room mate's have drive since he is not here at the moment.

  • To make sure there is no file with the name vstart.bat on your flash drives or any storage device with G drive letter (when the device is connected start > My computer, there the drive with letter G is the drive which should be checked) connect the drive with letter G.

    • I didn't find any vstart.bat on my flash drive. However I'm pretty sure it was my room mate's flash drive which is infected since he was the last one to use the computer. Also on thursday evening when I went to my class, the professor informed us of a virus that was on campus, which would do stuff to your computer if you autoran your flash drive. Although by that time he told us it was too late, I was already infected, and he didnt really explain what the virus did.

  • Please download ATF Cleaner by Atribune & save it to your desktop.

    • Done

  • In previous run of RSIT since the access to HJT was restricted it produced the old stored HJT log. For one moment I thought the infection was returned, but thanks to your feedback, checking the dates and comparing the logs my concern subsided. Please run RSIT again and post the log. It produces one log this time (log.txt).

  • Done. The log is the following
====================================
Logfile of random's system information tool 1.04 (written by random/random)
Run by James at 2008-10-20 01:54:31
Microsoft Windows XP Professional Service Pack 3
System drive C: has 29 GB (21%) free of 143 GB
Total RAM: 2047 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:54:35 AM, on 10/20/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\acs.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\James\Desktop\RSIT.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\James.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Microsoft Office Outlook 2007.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BBFD2D10-EC6E-4259-91D1-1E38C826E5E2} (Launcher Class) - http://app.gomtv.com/gomtv/gomtvx.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXlm server for PTC - Macrovision Corporation - C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 11083 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2007-08-31 1122128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-12-21 7774208]
"nwiz"=nwiz.exe /install []
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"NVIDIA nTune"=C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-01-08 81920]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"P17Helper"=Rundll32 P17.dll []
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2006-11-21 35328]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-12-21 81920]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe [2007-02-06 61440]
"HP Component Manager"=C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2004-05-12 241664]
"NWEReboot"= []
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-09-01 282624]
"AVFX Engine"=C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe [2006-06-09 24576]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-04-13 185896]
"removecpl"=RemoveCpl.exe []
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-07-17 266497]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup []
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-08-09 81920]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe /runcleanupscript []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2005-09-03 94208]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2007-04-03 165784]
"PeerGuardian"=C:\Program Files\PeerGuardian2\pg2.exe [2005-09-18 1421824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Octoshape Streaming Services]
C:\Program Files\Octoshape Streaming Services\James\OctoshapeClient.exe [2008-05-22 156944]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless Utility.lnk]
C:\PROGRA~1\Belkin\PCIF5D~1\WIRELE~1\BELKIN~1.EXE [2005-08-18 1388544]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Microsoft Office Outlook 2007.lnk - C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=36
"NoDriveAutoRun"=FFFFFFFF

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"AllowLegacyWebView"=
"AllowUnhashedWebView"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client"
"C:\Program Files\Octoshape Streaming Services\James\OctoshapeClient.exe"="C:\Program Files\Octoshape Streaming Services\James\OctoshapeClient.exe:*:Enabled:OctoshapeClient"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\TVUPlayer\TVUPlayer.exe"="C:\Program Files\TVUPlayer\TVUPlayer.exe:*:Enabled:TVUPlayer Component"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Documents and Settings\James\My Documents\Cod4MP\The All-Seeing Eye\eye.exe"="C:\Documents and Settings\James\My Documents\Cod4MP\The All-Seeing Eye\eye.exe:*:Enabled:Yahoo! All-Seeing Eye"
"C:\Program Files\National Instruments\LabVIEW 8.2\LabVIEW.exe"="C:\Program Files\National Instruments\LabVIEW 8.2\LabVIEW.exe:*:Enabled:LabVIEW 8.2 Development System"
"C:\Program Files\DAUM\PotPlayer\daumvsvr.exe"="C:\Program Files\DAUM\PotPlayer\daumvsvr.exe:*:Enabled:DaumCP VoD Server"
"C:\Program Files\DAUM\PotPlayer\PotPlayer.exe"="C:\Program Files\DAUM\PotPlayer\PotPlayer.exe:*:Enabled:?? ?????"
"C:\Program Files\PPLive\PPLive.exe"="C:\Program Files\PPLive\PPLive.exe:*:Enabled:PPLive"
"C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty® 4 - Modern Warfare™ "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{815c276a-8e4f-11dd-b5d9-001617ef3ff9}]
shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3176a75-155a-11dd-b533-001617ef3ff9}]
shell\AutoRun\command - G:\LaunchU3.exe -a


======List of files/folders created in the last 3 months======

2008-10-17 19:12:50 ----D---- C:\rsit
2008-10-17 19:04:35 ----D---- C:\Program Files\ERUNT
2008-10-16 19:53:03 ----D---- C:\Program Files\Trend Micro
2008-10-15 23:01:49 ----D---- C:\Avenger
2008-10-15 23:01:49 ----A---- C:\avenger.txt
2008-10-15 22:51:21 ----D---- C:\Documents and Settings\James\Application Data\Malwarebytes
2008-10-15 22:51:18 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-15 22:51:18 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-15 12:24:58 ----A---- C:\WINDOWS\systed.txt
2008-10-15 12:23:27 ----A---- C:\WINDOWS\systec.txt
2008-10-15 11:55:37 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-10-15 11:55:33 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-10-15 11:55:29 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-10-15 11:55:08 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-10-15 11:54:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-10-15 11:51:10 ----A---- C:\WINDOWS\systeb.txt
2008-10-14 12:34:13 ----A---- C:\WINDOWS\syste.txt
2008-10-06 23:28:02 ----A---- C:\LOGF3.tmp
2008-09-24 10:57:03 ----A---- C:\WINDOWS\system32\tpaerr.txt
2008-09-21 22:17:12 ----D---- C:\Program Files\DiskInternals
2008-09-19 17:30:47 ----D---- C:\Program Files\HTML Help Workshop
2008-09-19 17:26:04 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-18 23:10:37 ----A---- C:\WINDOWS\system32\muweb.dll
2008-09-18 23:10:37 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2008-09-18 23:10:37 ----A---- C:\WINDOWS\system32\mucltui.dll
2008-09-18 22:56:09 ----A---- C:\WINDOWS\system32\msonpmon.dll
2008-09-18 14:05:20 ----D---- C:\Documents and Settings\James\Application Data\Thunderbird
2008-09-18 02:09:04 ----A---- C:\WINDOWS\system32\OGACheckControl.dll
2008-09-17 12:44:35 ----D---- C:\Documents and Settings\James\Application Data\U3
2008-09-15 22:24:47 ----A---- C:\shutdown.bat
2008-09-15 21:20:30 ----D---- C:\Program Files\Common Files\LPG Shared
2008-09-15 13:39:34 ----D---- C:\Documents and Settings\James\Application Data\SPORE
2008-09-15 13:36:01 ----RHD---- C:\Documents and Settings\James\Application Data\SecuROM
2008-09-15 13:27:23 ----D---- C:\Program Files\Electronic Arts
2008-09-15 12:22:33 ----A---- C:\WINDOWS\system32\libusb0.dll
2008-09-10 16:30:01 ----A---- C:\WINDOWS\system32\DEBUG_LOG.txt
2008-09-10 01:40:23 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-09-10 01:39:58 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-08 23:01:40 ----A---- C:\WINDOWS\system32\ptpusb.dll
2008-09-08 23:01:39 ----A---- C:\WINDOWS\system32\ptpusd.dll
2008-09-08 21:42:29 ----D---- C:\WINDOWS\system32\Adobe
2008-09-08 20:55:35 ----D---- C:\Program Files\Common Files\SpellEx
2008-09-08 20:32:50 ----D---- C:\Program Files\TI Education
2008-09-08 20:32:50 ----D---- C:\Program Files\Common Files\TI Shared
2008-09-04 11:24:13 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-09-03 16:53:57 ----D---- C:\WINDOWS\Prefetch
2008-09-03 16:50:41 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-09-03 16:50:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-09-03 16:50:32 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-09-03 16:50:28 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-09-03 16:50:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-09-03 16:50:20 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-09-03 16:50:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-09-03 16:50:11 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-09-03 16:50:07 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-09-03 16:50:02 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-09-03 16:47:57 ----D---- C:\WINDOWS\system32\scripting
2008-09-03 16:47:57 ----D---- C:\WINDOWS\system32\en
2008-09-03 16:47:57 ----D---- C:\WINDOWS\l2schemas
2008-09-03 16:47:56 ----D---- C:\WINDOWS\system32\bits
2008-09-03 16:46:28 ----D---- C:\WINDOWS\ServicePackFiles
2008-09-03 16:42:27 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-27 17:22:47 ----N---- C:\WINDOWS\system32\wmphoto.dll
2008-08-27 17:22:46 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-08-27 17:22:46 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-27 17:22:46 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-27 17:22:44 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-08-27 17:22:44 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-08-27 17:22:43 ----N---- C:\WINDOWS\system32\spupdwxp.exe
2008-08-27 17:22:43 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slserv.exe
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slrundll.exe
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slgen.dll
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slextspk.dll
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\slcoinst.dll
2008-08-27 17:22:41 ----N---- C:\WINDOWS\system32\setupn.exe
2008-08-27 17:22:41 ----N---- C:\WINDOWS\slrundll.exe
2008-08-27 17:22:40 ----N---- C:\WINDOWS\system32\s3gnb.dll
2008-08-27 17:22:40 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-27 17:22:40 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-08-27 17:22:40 ----N---- C:\WINDOWS\system32\qutil.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\qagent.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-27 17:22:39 ----N---- C:\WINDOWS\system32\onex.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\napstat.exe
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-27 17:22:37 ----N---- C:\WINDOWS\system32\mssha.dll
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-27 17:22:34 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-27 17:22:31 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-27 17:22:28 ----N---- C:\WINDOWS\system32\smtpapi.dll
2008-08-27 17:22:28 ----N---- C:\WINDOWS\system32\rwnh.dll
2008-08-27 17:22:27 ----N---- C:\WINDOWS\system32\comsdupd.exe
2008-08-27 17:22:26 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\faxpatch.exe
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-27 17:22:25 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-08-27 17:22:25 ----A---- C:\WINDOWS\003070_.tmp
2008-08-27 17:22:24 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-08-27 17:22:24 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-27 17:22:24 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-27 17:22:24 ----N---- C:\WINDOWS\system32\credssp.dll
2008-08-27 17:22:22 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-27 17:22:22 ----N---- C:\WINDOWS\system32\azroles.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati3duag.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2008-08-27 17:22:21 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2008-08-27 17:22:20 ----N---- C:\WINDOWS\system32\aaclient.dll
2008-08-16 09:57:40 ----D---- C:\Program Files\NTE
2008-08-15 03:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2008-08-15 03:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2008-08-15 03:02:11 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$
2008-08-15 03:02:07 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2008-08-15 03:01:04 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-08-15 03:00:58 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2008-08-15 03:00:34 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2008-08-07 18:02:19 ----D---- C:\Program Files\Microsoft Silverlight
2008-07-25 05:02:23 ----A---- C:\WINDOWS\system32\javaws.exe
2008-07-25 05:02:23 ----A---- C:\WINDOWS\system32\javaw.exe
2008-07-25 05:02:23 ----A---- C:\WINDOWS\system32\java.exe

======List of files/folders modified in the last 3 months======

2008-10-20 01:52:28 ----D---- C:\WINDOWS\TEMP
2008-10-20 01:50:27 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-10-20 01:29:47 ----D---- C:\WINDOWS\system32
2008-10-19 22:34:56 ----D---- C:\Program Files\Mozilla Firefox
2008-10-19 21:27:36 ----D---- C:\WINDOWS\system32\CatRoot2
2008-10-19 20:26:27 ----D---- C:\WINDOWS\erdnt
2008-10-17 19:19:21 ----SHD---- C:\WINDOWS\Installer
2008-10-17 19:19:21 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-10-17 19:19:21 ----HD---- C:\Config.Msi
2008-10-17 19:04:35 ----RD---- C:\Program Files
2008-10-17 15:02:36 ----D---- C:\WINDOWS
2008-10-17 15:01:06 ----D---- C:\WINDOWS\system32\Macromed
2008-10-17 05:21:52 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-10-17 05:21:51 ----HD---- C:\WINDOWS\inf
2008-10-16 17:43:23 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-15 23:01:49 ----D---- C:\WINDOWS\system32\drivers
2008-10-15 13:38:54 ----D---- C:\Program Files\Common Files
2008-10-15 13:21:15 ----D---- C:\Program Files\ALGOR
2008-10-15 13:20:00 ----D---- C:\WINDOWS\WinSxS
2008-10-15 13:14:52 ----D---- C:\Program Files\Gravity
2008-10-15 12:51:29 ----D---- C:\Program Files\LimeWire
2008-10-15 12:43:37 ----D---- C:\Program Files\MSN Messenger
2008-10-15 12:42:53 ----D---- C:\Program Files\DAUM
2008-10-15 11:55:57 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-15 11:55:38 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-10-15 11:55:36 ----HD---- C:\WINDOWS\$hf_mig$
2008-10-15 11:55:35 ----A---- C:\WINDOWS\imsins.BAK
2008-10-15 11:55:23 ----D---- C:\Program Files\Internet Explorer
2008-10-15 11:52:31 ----D---- C:\WINDOWS\Registration
2008-10-13 19:53:32 ----D---- C:\Documents and Settings\James\Application Data\Move Networks
2008-10-13 18:30:25 ----A---- C:\WINDOWS\NeroDigital.ini
2008-10-10 00:00:21 ----D---- C:\Program Files\PeerGuardian2
2008-10-08 16:01:53 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2008-10-07 14:19:40 ----A---- C:\WINDOWS\system32\MRT.exe
2008-10-06 15:35:39 ----SD---- C:\Documents and Settings\James\Application Data\Microsoft
2008-10-03 12:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
2008-10-01 18:46:38 ----A---- C:\WINDOWS\win.ini
2008-09-30 15:00:01 ----D---- C:\Documents and Settings\James\Application Data\uTorrent
2008-09-28 21:19:02 ----D---- C:\WINDOWS\Minidump
2008-09-24 11:13:13 ----D---- C:\Program Files\WeatherMan
2008-09-22 23:46:34 ----D---- C:\Documents and Settings\James\Application Data\dvdcss
2008-09-19 17:35:04 ----AC---- C:\WINDOWS\vbaddin.ini
2008-09-19 17:34:52 ----RSD---- C:\WINDOWS\assembly
2008-09-19 17:34:38 ----D---- C:\WINDOWS\Microsoft.NET
2008-09-19 17:30:47 ----D---- C:\Program Files\Common Files\Microsoft Shared
2008-09-18 23:08:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-18 23:01:27 ----D---- C:\WINDOWS\SHELLNEW
2008-09-18 23:00:15 ----D---- C:\Program Files\Microsoft Visual Studio 8
2008-09-18 22:56:02 ----D---- C:\WINDOWS\system32\config
2008-09-18 22:54:23 ----D---- C:\Program Files\Microsoft Works
2008-09-18 22:53:58 ----D---- C:\Program Files\Microsoft Office
2008-09-18 22:50:53 ----D---- C:\WINDOWS\Help
2008-09-18 14:05:21 ----D---- C:\Documents and Settings\James\Application Data\Mozilla
2008-09-17 10:20:25 ----SH---- C:\boot.ini
2008-09-17 10:20:25 ----A---- C:\WINDOWS\system.ini
2008-09-15 21:15:51 ----D---- C:\WINDOWS\twain_32
2008-09-15 16:59:36 ----SD---- C:\WINDOWS\Tasks
2008-09-15 13:36:00 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2008-09-15 13:20:46 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-11 12:12:03 ----D---- C:\Program Files\Adobe
2008-09-08 23:28:17 ----SHD---- C:\RECYCLER
2008-09-08 23:28:13 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-09-08 20:32:51 ----D---- C:\WINDOWS\system
2008-09-03 16:56:08 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-03 16:54:57 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-09-03 16:54:01 ----AC---- C:\WINDOWS\setuplog.txt
2008-09-03 16:53:43 ----D---- C:\WINDOWS\system32\Setup
2008-09-03 16:53:43 ----D---- C:\WINDOWS\ime
2008-09-03 16:53:43 ----D---- C:\WINDOWS\AppPatch
2008-09-03 16:53:42 ----D---- C:\WINDOWS\system32\wbem
2008-09-03 16:52:17 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-03 16:50:03 ----D---- C:\Program Files\Messenger
2008-09-03 16:48:06 ----D---- C:\WINDOWS\system32\inetsrv
2008-09-03 16:48:06 ----D---- C:\WINDOWS\network diagnostic
2008-09-03 16:47:57 ----D---- C:\WINDOWS\system32\usmt
2008-09-03 16:47:57 ----D---- C:\WINDOWS\system32\en-US
2008-09-03 16:47:56 ----D---- C:\WINDOWS\PeerNet
2008-09-03 16:47:56 ----D---- C:\Program Files\Movie Maker
2008-09-03 16:46:21 ----D---- C:\WINDOWS\system32\Restore
2008-09-03 16:46:21 ----D---- C:\WINDOWS\system32\npp
2008-09-03 16:46:21 ----D---- C:\WINDOWS\mui
2008-09-03 16:46:20 ----D---- C:\WINDOWS\msagent
2008-09-03 16:46:19 ----D---- C:\WINDOWS\srchasst
2008-09-03 16:46:18 ----D---- C:\WINDOWS\system32\Com
2008-09-03 16:46:18 ----D---- C:\Program Files\NetMeeting
2008-09-03 16:46:16 ----D---- C:\Program Files\Windows NT
2008-09-03 16:46:16 ----D---- C:\Program Files\Windows Media Player
2008-09-03 16:46:16 ----D---- C:\Program Files\Outlook Express
2008-09-03 16:46:14 ----D---- C:\Program Files\Common Files\System
2008-09-03 16:46:01 ----D---- C:\WINDOWS\system32\oobe
2008-09-03 16:44:00 ----D---- C:\WINDOWS\security
2008-09-03 16:43:57 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-09-03 16:42:25 ----D---- C:\WINDOWS\ehome
2008-08-27 17:13:08 ----D---- C:\WINDOWS\Debug
2008-08-27 03:24:32 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-08-26 02:24:31 ----A---- C:\WINDOWS\system32\wininet.dll
2008-08-26 02:24:31 ----A---- C:\WINDOWS\system32\webcheck.dll
2008-08-26 02:24:31 ----A---- C:\WINDOWS\system32\urlmon.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\url.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\pngfilt.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\occache.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\mstime.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\msrating.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\mshtmled.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\msfeeds.dll
2008-08-26 02:24:30 ----A---- C:\WINDOWS\system32\jsproxy.dll
2008-08-26 02:24:29 ----A---- C:\WINDOWS\system32\iertutil.dll
2008-08-26 02:24:29 ----A---- C:\WINDOWS\system32\iernonce.dll
2008-08-26 02:24:29 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\ieaksie.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\ieakeng.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\icardie.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\extmgr.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\dxtrans.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2008-08-26 02:24:28 ----A---- C:\WINDOWS\system32\advpack.dll
2008-08-25 03:38:00 ----A---- C:\WINDOWS\system32\ieudinit.exe
2008-08-25 03:37:59 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2008-08-23 00:54:51 ----A---- C:\WINDOWS\system32\ieakui.dll
2008-08-19 05:32:20 ----D---- C:\Program Files\uTorrent
2008-08-14 05:09:26 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 04:33:16 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-25 05:02:23 ----D---- C:\Program Files\Java

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-07-17 75072]
R1 DhaHelper;DhaHelper; \??\C:\WINDOWS\system32\drivers\dhahelper.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-04-20 17801]
R2 cvintdrv;cvintdrv; C:\WINDOWS\system32\drivers\cvintdrv.sys [2006-07-27 4096]
R2 nxsIO32;NextSensor Kernel I/O Driver; \??\C:\WINDOWS\System32\DRIVERS\nxsIO32.sys []
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [1999-07-20 73216]
R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys []
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2005-01-10 138752]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-12-21 5747488]
R3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2005-01-10 106496]
R3 P17;SB Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys [2007-06-15 1127936]
R3 pgfilter;pgfilter; \??\C:\Program Files\PeerGuardian2\pgfilter.sys []
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-07-21 82432]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S3 avxts16h;avxts16h; C:\WINDOWS\system32\drivers\avxts16h.sys []
S3 BLKWGD;Belkin Wireless G Desktop Card Service; C:\WINDOWS\system32\DRIVERS\BLKWGD.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\James\LOCALS~1\Temp\catchme.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-24 4353024]
S3 libusb0;LibUsb-Win32 - Kernel Driver 03/20/2007, 0.1.12.1; C:\WINDOWS\system32\DRIVERS\libusb0.sys [2008-09-15 33792]
S3 nm;Network Monitor Driver; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 TiglUsb;TiglUsb.sys TI-GRAPH / DIRECT LINK USB driver; C:\WINDOWS\System32\Drivers\TiglUsb.sys []
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 wlanndi5;wlanndi5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\wlanndi5.SYS []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZDCNDIS5;ZDCNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\ZDCndis5.SYS []
S3 ZY202_XP;ZyXEL 802.11g XG202 1211 Driver; C:\WINDOWS\system32\DRIVERS\WlanUZXP.sys [2006-11-27 437760]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Atheros Configuration Service; C:\WINDOWS\system32\acs.exe [2005-05-05 36864]
R2 AntiVirScheduler;Avira AntiVir Personal – Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-07-17 68865]
R2 AntiVirService;Avira AntiVir Personal – Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-08-14 149761]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-07-25 100032]
R2 FLEXlm server for PTC;FLEXlm server for PTC; C:\Program Files\flexnet\i486_nt\obj\lmgrd.exe [2007-11-20 1294336]
R2 LkCitadelServer;Lookout Citadel Server; C:\WINDOWS\system32\lkcitdl.exe [2006-06-19 688190]
R2 lkClassAds;National Instruments PSP Server Locator; C:\WINDOWS\system32\lkads.exe [2006-07-25 45056]
R2 lkTimeSync;National Instruments Time Synchronization; C:\WINDOWS\system32\lktsrv.exe [2006-07-25 57344]
R2 matlabserver;MATLAB Server; C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe [2005-07-27 536576]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2005-10-14 28768528]
R2 mxssvr;NI Configuration Manager; C:\Program Files\National Instruments\MAX\nimxs.exe [2006-07-15 5728]
R2 NIDomainService;National Instruments Domain Service; C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe [2006-07-25 200704]
R2 niSvcLoc;NI Service Locator; C:\WINDOWS\system32\nisvcloc.exe [2006-02-06 49152]
R2 NITaggerService;National Instruments Variable Engine; C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe [2006-07-25 696320]
R2 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-01-08 118784]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-12-21 168004]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-04-24 66872]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2007-02-10 89968]
R2 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2007-01-25 1174152]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-07-25 2119360]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
S3 NILM License Manager;NILM License Manager; C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe [2006-06-27 1007616]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 OpcEnum;OpcEnum; C:\WINDOWS\system32\OpcEnum.exe [2004-12-02 98304]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2006-10-26 2799808]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2005-10-14 239320]

-----------------EOF-----------------
========================================

Edited by lol999, 20 October 2008 - 02:21 AM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users