OTL logfile created on: 5/29/2010 10:26:23 PM - Run 1
OTL by OldTimer - Version 3.2.5.1 Folder = C:\Documents and Settings\Starwalker\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 3072 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 13.31 Gb Free Space | 35.72% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 931.51 Gb Total Space | 904.68 Gb Free Space | 97.12% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OWNER-2
Current User Name: Starwalker
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/05/29 22:25:07 | 000,571,392 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Starwalker\desktop\OTL.exe
PRC - [2010/05/06 15:59:42 | 002,815,192 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/05/06 15:59:38 | 000,040,384 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/04/30 06:06:31 | 000,353,736 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\bin\IncMail.exe
PRC - [2010/04/30 06:06:30 | 000,247,240 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\bin\ImApp.exe
PRC - [2010/04/15 08:25:20 | 001,872,320 | —- | M] (Emsi Software GmbH) – C:\Program Files\a-squared Free\a2service.exe
PRC - [2010/04/02 01:06:14 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/05/19 12:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2008/05/19 12:13:20 | 000,057,344 | —- | M] (Nalpeiron Ltd.) – C:\WINDOWS\system32\ASTSRV.EXE
PRC - [2008/05/09 20:42:21 | 000,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2001/08/17 17:36:42 | 000,024,064 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\devldr32.exe
========== Modules (SafeList) ==========
MOD - [2010/05/29 22:25:07 | 000,571,392 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Starwalker\desktop\OTL.exe
MOD - [2008/04/13 19:10:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010/05/06 15:59:38 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Web Scanner)
SRV - [2010/05/06 15:59:38 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Mail Scanner)
SRV - [2010/05/06 15:59:38 | 000,040,384 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV - [2010/04/15 08:25:20 | 001,872,320 | —- | M] (Emsi Software GmbH) [Auto | Running] – C:\Program Files\a-squared Free\a2service.exe – (a2free)
SRV - [2009/05/19 12:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2008/05/19 12:13:20 | 000,057,344 | —- | M] (Nalpeiron Ltd.) [Auto | Running] – C:\WINDOWS\system32\ASTSRV.EXE – (ASTSRV)
SRV - [2008/05/01 16:16:33 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
========== Driver Services (SafeList) ==========
DRV - [2010/05/28 06:04:52 | 000,014,896 | —- | M] (Secunia) [File_System | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\psi_mf.sys – (PSI)
DRV - [2010/05/15 03:17:25 | 000,068,168 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aswTdi.sys – (aswTdi)
DRV - [2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aswSP.sys – (aswSP)
DRV - [2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\aswRdr.sys – (aswRdr)
DRV - [2010/05/06 15:33:59 | 000,100,432 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\aswmon2.sys – (aswMon2)
DRV - [2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2010/05/06 15:33:29 | 000,028,880 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2010/02/19 16:05:16 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV)
DRV - [2010/02/19 16:05:16 | 000,012,872 | —- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2008/04/13 13:45:30 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/02/27 13:49:00 | 000,003,840 | —- | M] () [Kernel | System | Running] – C:\windows\System32\Drivers\BANTExt.sys – (BANTExt)
DRV - [2008/01/05 16:14:47 | 000,102,664 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm)
DRV - [2006/10/22 13:22:00 | 003,994,624 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2006/09/24 08:28:46 | 000,005,248 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] – C:\windows\system32\speedfan.sys – (speedfan)
DRV - [2004/08/03 22:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rtl8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/03/05 13:19:28 | 000,015,840 | —- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\PFMODNT.SYS – (PfModNT)
DRV - [2002/10/29 15:24:42 | 000,033,280 | —- | M] (DAVICOM Semiconductor, Inc. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DM9PCI5.SYS – (DM9102)
DRV - [2002/06/23 16:31:20 | 000,045,568 | R— | M] (D-Link Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DLKRTS.SYS – (DLKRTS)
DRV - [2001/08/17 07:50:26 | 000,731,648 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nv4.sys – (nv4)
DRV - [2001/08/17 07:19:34 | 000,036,480 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sfmanm.sys – (sfman) Creative SoundFont Manager Driver (WDM)
DRV - [2001/08/17 07:19:28 | 000,006,912 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctlfacem.sys – (emu10k1) Creative Interface Manager Driver (WDM)
DRV - [2001/08/17 07:19:26 | 000,283,904 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\emu10k1m.sys – (emu10k) Creative SB Live! (WDM)
DRV - [2001/08/17 07:19:20 | 000,003,712 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ctljystk.sys – (ctljystk)
DRV - [2001/05/14 18:15:40 | 000,010,368 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\windows\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)
DRV - [1996/04/03 14:33:26 | 000,005,248 | —- | M] () [Kernel | Boot | Running] – C:\windows\system32\giveio.sys – (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://news.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://eis.esnips.com/page/search/?client_…d2-41fde8d1391d
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Reganam Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "
http://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
FF - prefs.js..browser.search.order.1: "eSnips Search"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 44
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6
FF - prefs.js..extensions.enabledItems: {249df6a2-e336-47d1-b6c3-ec711ad140ca}:0.5.0.00021
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:3.0.8
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.0.5
FF - prefs.js..extensions.enabledItems: {1392b8d2-5c05-419f-a8f6-b9f15a596612}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:0.4.1.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.1.6
FF - prefs.js..extensions.enabledItems: {db9d7a78-a76c-4bf2-97c6-258925ee1542}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.6.7
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {c33c5b47-69c8-45a4-a5e0-af85bbe628dd}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}:1.0
FF - prefs.js..extensions.enabledItems: {95f24680-9e31-11da-a746-0800200c9a66}:0.1.5.5
FF - prefs.js..keyword.URL: "
http://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.17\extensions\\Components: F:\PORTAB~1\FIREFO~1\APP\firefox\components
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.17\extensions\\Plugins: F:\PORTAB~1\FIREFO~1\APP\firefox\plugins
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/16 01:41:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/25 23:50:30 | 000,000,000 | —D | M]
[2008/10/30 01:10:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Extensions
[2010/05/29 17:35:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions
[2010/05/08 22:13:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010/05/08 22:13:01 | 000,000,000 | —D | M] (Flagfox) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2010/02/15 16:37:08 | 000,000,000 | —D | M] (Freecorder Toolbar) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/04/26 22:26:13 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/04 21:43:02 | 000,000,000 | —D | M] (eBay Toolbar) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{249df6a2-e336-47d1-b6c3-ec711ad140ca}
[2010/04/09 01:29:16 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/25 23:54:26 | 000,000,000 | —D | M] (Update Notifier) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2010/05/12 10:20:55 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/04/08 02:49:40 | 000,000,000 | —D | M] (Interclue) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
[2009/11/19 12:10:17 | 000,000,000 | —D | M] (Fast Video Download (with SearchMenu)) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2010/05/21 00:24:06 | 000,000,000 | —D | M] (flashget3 Extension) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
[2010/02/11 00:38:31 | 000,000,000 | —D | M] (Reganam Toolbar) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{db9d7a78-a76c-4bf2-97c6-258925ee1542}
[2009/09/10 10:40:48 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/03/01 00:30:21 | 000,000,000 | —D | M] (SweetIM Toolbar for Firefox) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2010/05/15 03:18:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/03/16 19:00:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2009/03/15 23:13:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/03/25 18:03:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/03/29 02:39:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/04/01 02:17:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/05/20 02:01:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/05/10 23:57:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2009/08/06 13:40:06 | 000,002,836 | —- | M] () – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\searchplugins\bing.xml
[2010/04/30 06:04:34 | 000,002,149 | —- | M] () – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\searchplugins\MyStart Search.xml
[2009/11/19 12:14:54 | 000,003,915 | —- | M] () – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\searchplugins\sweetim.xml
[2010/05/27 23:22:24 | 000,001,952 | —- | M] () – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\searchplugins\thomasnet-industrial-search.xml
[2010/05/29 17:35:26 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/14 03:43:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/05/18 12:26:29 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/04/29 20:50:24 | 000,024,576 | —- | M] (My Web Search) – C:\Program Files\Mozilla Firefox\plugins\NPMySrWB.dll
[2010/03/19 18:59:38 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
O1 HOSTS File: ([2010/02/09 01:40:50 | 000,612,589 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 ads.active.com
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 data2.activshopper.com #[Trackware.ActivShopper]
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ad2games.com
O1 - Hosts: 127.0.0.1 cms.ad2click.nl
O1 - Hosts: 127.0.0.1 ads.ad2games.com
O1 - Hosts: 127.0.0.1 content.ad20.net
O1 - Hosts: 16208 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (no name) - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No CLSID value found.
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -Mozilla\5.0 ( File not found
O4 - Startup: C:\Documents and Settings\Starwalker\Start Menu\Programs\Startup\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 67
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKCU\..Trusted Domains: fnismls.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: getmedianow.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O15 - HKCU\..Trusted Domains: live.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: showingtime.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sitexdata.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: spellchecker.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: transactionpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: trpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virtualearth.net ([]* in Trusted sites)
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945}
http://static.ak.facebook.com/fbplugin/win…fbootloader.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Starwalker\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Starwalker\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/17 22:44:26 | 000,000,000 | —D | M] - F:\AutoFX.Mystical.Tint.Tone.and.Color.v2.0-FOSI – [ NTFS ]
O32 - AutoRun File - [2010/04/17 21:52:53 | 062,549,674 | —- | M] () - F:\AutoFX.Mystical.Tint.Tone.and.Color.v2.0-FOSI.rar – [ NTFS ]
O33 - MountPoints2\{70f5008a-175d-11df-bd31-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{70f5008a-175d-11df-bd31-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{70f5008a-175d-11df-bd31-806d6172696f}\Shell\AutoRun\command - "" = D:\AutoRun\AutoRun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (autocheck lsdelete) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/07/05 23:27:12 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/05/29 22:25:06 | 000,571,392 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Starwalker\Desktop\OTL.exe
[2010/05/29 22:24:48 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Starwalker\Recent
[2010/05/28 22:29:47 | 000,000,000 | —D | C] – C:\Program Files\Secunia
[2010/05/28 06:04:52 | 000,014,896 | —- | C] (Secunia) – C:\windows\System32\drivers\psi_mf.sys
[2010/05/19 01:13:45 | 000,000,000 | R–D | C] – C:\Documents and Settings\Starwalker\Desktop\Icons
[2010/05/18 23:37:33 | 000,057,344 | —- | C] (Nalpeiron Ltd.) – C:\windows\System32\ASTSRV.EXE
[2010/05/18 22:38:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Application Data\ThumbsPlus
[2010/05/18 22:35:40 | 000,000,000 | —D | C] – C:\Program Files\Thumbs7
[2010/05/18 22:29:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Application Data\Auto FX Software
[2010/05/18 22:27:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Application Data\ThePluginSite
[2010/05/18 22:27:22 | 000,000,000 | —D | C] – C:\Program Files\FocalBlade2
[2010/05/18 12:29:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Desktop\Readers
[2010/05/18 12:28:13 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Foxit Software
[2010/05/14 11:46:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\Starwalker\Desktop\chickens
[2010/05/14 03:43:55 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\deployJava1.dll
[2010/05/14 03:43:55 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\javaws.exe
[2010/05/14 03:43:55 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\javaw.exe
[2010/05/14 03:43:55 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\java.exe
[2010/05/11 03:57:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Application Data\Facebook
[2010/05/04 14:38:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Desktop\Funeral
[29 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/05/29 22:30:04 | 000,284,915 | —- | M] () – C:\Documents and Settings\Starwalker\Desktop\gmer.zip
[2010/05/29 22:25:07 | 000,571,392 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Starwalker\Desktop\OTL.exe
[2010/05/29 22:23:08 | 000,000,894 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/29 22:01:07 | 000,000,244 | —- | M] () – C:\windows\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/29 19:23:13 | 000,000,890 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/29 13:02:21 | 000,000,868 | —- | M] () – C:\windows\tasks\Google Software Updater.job
[2010/05/29 11:17:03 | 000,509,392 | —- | M] () – C:\windows\System32\PerfStringBackup.INI
[2010/05/29 11:17:03 | 000,432,664 | —- | M] () – C:\windows\System32\perfh009.dat
[2010/05/29 11:17:03 | 000,067,428 | —- | M] () – C:\windows\System32\perfc009.dat
[2010/05/29 11:12:43 | 000,000,322 | —- | M] () – C:\windows\tasks\GlaryInitialize.job
[2010/05/29 11:12:36 | 000,000,006 | -H– | M] () – C:\windows\tasks\SA.DAT
[2010/05/29 11:12:17 | 000,088,566 | —- | M] () – C:\windows\System32\nvapps.xml
[2010/05/29 11:11:34 | 000,002,048 | –S- | M] () – C:\windows\bootstat.dat
[2010/05/29 11:11:26 | 2146,516,992 | -HS- | M] () – C:\hiberfil.sys
[2010/05/29 03:41:09 | 014,680,064 | —- | M] () – C:\Documents and Settings\Starwalker\ntuser.dat
[2010/05/29 03:41:09 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Starwalker\ntuser.ini
[2010/05/28 22:30:00 | 000,000,727 | —- | M] () – C:\Documents and Settings\Starwalker\Start Menu\Programs\Startup\Secunia PSI.lnk
[2010/05/28 22:21:58 | 000,000,682 | —- | M] () – C:\Documents and Settings\Starwalker\Desktop\Glary Utilities.lnk
[2010/05/28 06:04:52 | 000,014,896 | —- | M] (Secunia) – C:\windows\System32\drivers\psi_mf.sys
[2010/05/24 02:21:23 | 000,077,389 | —- | M] () – C:\Documents and Settings\Starwalker\Desktop\vs17_129.pdf
[2010/05/24 00:26:57 | 000,000,245 | —- | M] () – C:\Documents and Settings\Starwalker\My Documents\Document-seeds.rtf
[2010/05/21 00:30:24 | 000,000,336 | —- | M] () – C:\windows\System32\secustat.dat
[2010/05/21 00:14:24 | 000,000,891 | —- | M] () – C:\windows\System32\secushr.dat
[2010/05/19 04:05:11 | 004,773,328 | -H– | M] () – C:\Documents and Settings\Starwalker\Local Settings\Application Data\IconCache.db
[2010/05/19 01:05:11 | 000,000,618 | —- | M] () – C:\Documents and Settings\All Users\Desktop\ThumbsPlus 7.lnk
[2010/05/16 13:46:13 | 000,000,811 | —- | M] () – C:\windows\lexstat.ini
[2010/05/11 13:43:57 | 000,014,848 | —- | M] () – C:\Documents and Settings\Starwalker\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/07 03:46:33 | 000,002,626 | —- | M] () – C:\windows\System32\CONFIG.NT
[2010/05/07 03:40:02 | 000,002,206 | —- | M] () – C:\windows\System32\wpa.dbl
[2010/05/06 15:59:36 | 000,165,032 | —- | M] (ALWIL Software) – C:\windows\System32\aswBoot.exe
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswTdi.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswSP.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswRdr.sys
[2010/05/06 15:33:59 | 000,100,432 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswmon2.sys
[2010/05/06 15:33:55 | 000,094,800 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswmon.sys
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswFsBlk.sys
[2010/05/06 15:33:29 | 000,028,880 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aavmker4.sys
[2010/05/05 03:41:31 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/30 06:07:11 | 000,001,750 | —- | M] () – C:\Documents and Settings\All Users\Desktop\IncrediMail.lnk
[29 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/05/28 22:30:00 | 000,000,727 | —- | C] () – C:\Documents and Settings\Starwalker\Start Menu\Programs\Startup\Secunia PSI.lnk
[2010/05/24 01:33:58 | 000,077,389 | —- | C] () – C:\Documents and Settings\Starwalker\Desktop\vs17_129.pdf
[2010/05/24 00:26:57 | 000,000,245 | —- | C] () – C:\Documents and Settings\Starwalker\My Documents\Document-seeds.rtf
[2010/05/18 22:35:54 | 000,000,618 | —- | C] () – C:\Documents and Settings\All Users\Desktop\ThumbsPlus 7.lnk
[2010/05/11 19:18:47 | 000,000,894 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/11 19:18:47 | 000,000,890 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/30 06:07:11 | 000,001,750 | —- | C] () – C:\Documents and Settings\All Users\Desktop\IncrediMail.lnk
[2010/03/25 22:08:36 | 000,000,025 | —- | C] () – C:\windows\libem.INI
[2010/02/13 01:00:58 | 000,000,116 | —- | C] () – C:\windows\NeroDigital.ini
[2009/10/13 17:49:20 | 000,230,752 | —- | C] () – C:\windows\patchw32.dll
[2009/01/31 12:39:09 | 000,003,840 | —- | C] () – C:\windows\System32\drivers\BANTExt.sys
[2008/10/29 13:25:37 | 000,000,049 | —- | C] () – C:\windows\System32\WRKVersion.ini
[2008/05/03 04:18:15 | 000,296,448 | —- | C] () – C:\windows\Xenofex.ini
[2008/01/24 21:59:23 | 000,000,670 | —- | C] () – C:\windows\nvrbm.ini
[2008/01/14 02:55:37 | 000,014,848 | —- | C] () – C:\windows\System32\BASSMOD.dll
[2008/01/06 00:34:46 | 000,005,515 | —- | C] () – C:\windows\fmachine.ini
[2007/11/05 12:16:51 | 000,000,061 | —- | C] () – C:\windows\PureEdgeAPI.ini
[2007/11/05 12:16:47 | 000,167,936 | —- | C] () – C:\windows\System32\MSQOLE.DLL
[2007/10/29 00:03:59 | 000,000,089 | —- | C] () – C:\windows\ULead32.ini
[2007/10/29 00:03:01 | 000,000,039 | —- | C] () – C:\windows\Wininit.ini
[2007/10/29 00:02:56 | 000,035,328 | —- | C] () – C:\windows\INETWH32.DLL
[2007/10/29 00:02:56 | 000,009,136 | —- | C] () – C:\windows\INETWH16.DLL
[2007/10/26 01:52:34 | 000,000,144 | —- | C] () – C:\windows\Eudcedit.ini
[2007/10/25 23:07:38 | 000,005,515 | —- | C] () – C:\windows\System32\fmachine.ini
[2007/10/15 04:38:46 | 000,373,248 | —- | C] () – C:\windows\EyeCand3.INI
[2007/10/02 17:59:26 | 000,210,944 | —- | C] () – C:\windows\System32\Msvcrt10.dll
[2007/10/02 17:59:25 | 000,057,344 | —- | C] () – C:\windows\System32\icmfilter.dll
[2007/07/18 12:11:22 | 000,004,096 | —- | C] () – C:\windows\System32\sysres.dll
[2007/07/07 23:10:53 | 000,000,811 | —- | C] () – C:\windows\lexstat.ini
[2006/10/22 13:22:00 | 001,662,976 | —- | C] () – C:\windows\System32\nvwdmcpl.dll
[2006/10/22 13:22:00 | 001,019,904 | —- | C] () – C:\windows\System32\nvwimg.dll
[2006/10/22 13:22:00 | 000,581,632 | —- | C] () – C:\windows\System32\nvhwvid.dll
[2006/10/22 13:22:00 | 000,286,720 | —- | C] () – C:\windows\System32\nvnt4cpl.dll
[2006/10/22 13:22:00 | 000,212,992 | —- | C] () – C:\windows\System32\nvapi.dll
[2003/08/18 05:46:38 | 000,077,824 | —- | C] () – C:\windows\System32\LXBKLCNP.DLL
[2003/07/28 16:19:00 | 001,470,464 | —- | C] () – C:\windows\System32\nview.dll
[2003/07/28 16:19:00 | 000,466,944 | —- | C] () – C:\windows\System32\nvshell.dll
[2002/11/13 10:40:22 | 000,040,960 | —- | C] () – C:\windows\System32\lxbkvs.dll
[2002/09/13 06:40:06 | 000,000,266 | —- | C] () – C:\windows\System32\lxbkcoin.ini
[1996/04/03 14:33:26 | 000,005,248 | —- | C] () – C:\windows\System32\giveio.sys
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[1996/10/24 17:45:24 | 000,059,952 | —- | M] () – C:\UNWISE.EXE
< MD5 for: AGP440.SYS >
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/01/03 14:06:23 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/01/03 14:06:23 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/01/03 14:06:23 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/01/03 14:06:23 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 04:31:44 | 000,348,160 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[29 C:\windows\system32\*.tmp files -> C:\windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007/07/05 18:13:17 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/07/05 18:13:17 | 000,606,208 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/07/05 18:13:17 | 000,393,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 187 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A31FAD21
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C5760A8B
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >