This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HTTP 404 not found

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi , For the past week or so i have been getting a window popping up with the title HTTP 404 not found . This window pops up every 30 minutes or so which has become quite an annoyance . please help.


OTL Extras logfile created on: 01/08/2010 21:53:38 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Program Files\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97.66 Gb Total Space | 34.95 Gb Free Space | 35.79% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 51.39 Gb Total Space | 37.69 Gb Free Space | 73.35% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ZAC-66AA64
Current User Name: Zac
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"FirewallOverride" = 0
"AntiVirusOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"6112:TCP" = 6112:TCP:*:Enabled:Warcraft 3 frozen throne
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"57698:TCP" = 57698:TCP:*:Enabled:Pando Media Booster
"57698:UDP" = 57698:UDP:*:Enabled:Pando Media Booster
"8370:TCP" = 8370:TCP:*:Enabled:League of Legends Launcher
"8370:UDP" = 8370:UDP:*:Enabled:League of Legends Launcher
"6898:TCP" = 6898:TCP:*:Enabled:League of Legends Launcher
"6898:UDP" = 6898:UDP:*:Enabled:League of Legends Launcher
"8376:TCP" = 8376:TCP:*:Enabled:League of Legends Launcher
"8376:UDP" = 8376:UDP:*:Enabled:League of Legends Launcher
"57315:TCP" = 57315:TCP:*:Enabled:Pando Media Booster
"57315:UDP" = 57315:UDP:*:Enabled:Pando Media Booster
"8377:TCP" = 8377:TCP:*:Enabled:League of Legends Launcher
"8377:UDP" = 8377:UDP:*:Enabled:League of Legends Launcher
"8378:TCP" = 8378:TCP:*:Enabled:League of Legends Launcher
"8378:UDP" = 8378:UDP:*:Enabled:League of Legends Launcher
"6953:TCP" = 6953:TCP:*:Enabled:League of Legends Launcher
"6953:UDP" = 6953:UDP:*:Enabled:League of Legends Launcher
"6952:TCP" = 6952:TCP:*:Enabled:League of Legends Launcher
"6952:UDP" = 6952:UDP:*:Enabled:League of Legends Launcher
"6990:TCP" = 6990:TCP:*:Enabled:League of Legends Launcher
"6990:UDP" = 6990:UDP:*:Enabled:League of Legends Launcher
"8379:TCP" = 8379:TCP:*:Enabled:League of Legends Launcher
"8379:UDP" = 8379:UDP:*:Enabled:League of Legends Launcher
"1075:TCP" = 1075:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 – (IniCom Networks, Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Curse\CurseClient.exe" = C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client – ()
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – (FrostWire Group)
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 – (IniCom Networks, Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Riot Games\League of Legends\air\LolClient.exe" = C:\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby – ()
"C:\Riot Games\League of Legends\game\League of Legends.exe" = C:\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client – ()
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Xfire\xfire.exe" = C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire – (Xfire Inc.)
"C:\Program Files\Heroes of Newerth\hon.exe" = C:\Program Files\Heroes of Newerth\hon.exe:*:Enabled:Heroes of Newerth – (S2 Games)
"C:\Program Files\THQ\Dawn of War\W40k.exe" = C:\Program Files\THQ\Dawn of War\W40k.exe:*:Enabled:W40K – (THQ Canada Inc.)
"C:\Program Files\THQ\Dawn of War\W40kWA.exe" = C:\Program Files\THQ\Dawn of War\W40kWA.exe:*:Enabled:W40kWA – (THQ Canada Inc.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Documents and Settings\Zac\Local Settings\Apps\2.0\JG5AK6CG.HM5\XRKWT800.DOL\curs..tion_eee711038731a406_0004.0000_1430d97334050788\CurseClient.exe" = C:\Documents and Settings\Zac\Local Settings\Apps\2.0\JG5AK6CG.HM5\XRKWT800.DOL\curs..tion_eee711038731a406_0004.0000_1430d97334050788\CurseClient.exe:*:Enabled:Curse Client 4.0 – (Curse)
"C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Disabled:Windows® NetMeeting® – (Microsoft Corporation)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Bywifi\bywifi.exe" = C:\Program Files\Bywifi\bywifi.exe:*:Enabled:Bywifi: Video Streaming Accelerator – (bywifi.com)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Steam\SteamApps\common\dawn of war 2\DOW2.exe" = C:\Program Files\Steam\SteamApps\common\dawn of war 2\DOW2.exe:*:Enabled:Warhammer® 40,000â„¢: Dawn of War® II – (THQ Canada Inc.)
"C:\Program Files\Steam\SteamApps\common\global agenda live\Binaries\GlobalAgenda.exe" = C:\Program Files\Steam\SteamApps\common\global agenda live\Binaries\GlobalAgenda.exe:*:Enabled:Global Agenda - Demo – (HiRez Studios, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Steam\SteamApps\common\alien swarm\srcds.exe" = C:\Program Files\Steam\SteamApps\common\alien swarm\srcds.exe:*:Enabled:Alien Swarm Dedicated Server – ()
"C:\Program Files\Steam\steam.exe" = C:\Program Files\Steam\steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine – ()
"C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III – (Blizzard Entertainment)
"C:\Program Files\Warcraft III\War3.exe" = C:\Program Files\Warcraft III\War3.exe:*:Enabled:Warcraft III – (Blizzard Entertainment)
"C:\Program Files\Steam\SteamApps\common\alien swarm\swarm.exe" = C:\Program Files\Steam\SteamApps\common\alien swarm\swarm.exe:*:Enabled:Alien Swarm – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{14FB4C04-0A21-4FE6-A2D2-13EA3B82A211}_is1" = PerfectOptimizer 5.1
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1DCC7418-2089-4BDD-B321-3771956160FC}" = ijji Auto Installer
"{1E99F5D7-4262-4C7C-9135-F066E7485811}" = System Requirements Lab
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{362D5167-9716-44BE-89FD-BF9EB6EF814B}" = DawnOfWar
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7148F0A8-6813-11D6-A77B-00B0D0142070}" = Java 2 Runtime Environment, SE v1.4.2_07
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{83729FE3-6785-476A-91F1-312D427B4522}" = League of Legends
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{868EC22E-7E82-4760-9265-3F2E705BF24B}" = League of Legends
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}" = Camera RAW Plug-In for EPSON Creativity Suite
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v3
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A14A8608-CF1C-4010-A348-7EA220C70305}_is1" = Perfect Optimizer 5.2
"{A1C962E2-2426-49C6-A38B-9A07E40D607C}" = Microsoft Games for Windows - LIVE
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5376B0E-C352-4B07-880C-8BB01179FCA5}" = ATI Catalyst Control Center
"{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}" = EPSON Easy Photo Print
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}" = AVIVO Codecs
"{C9FB868B-2086-4EE2-BD4F-BFBA36B131F4}" = NCsoft Launcher
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse
"{EDB32FFB-FC1C-414B-BF8E-4645217E9AF2}" = League of Legends
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AdssiteGames" = Adssite Games Collection
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Akamai" = Akamai NetSession Interface
"All ATI Software" = ATI - Software Uninstall Utility
"Ask Toolbar_is1" = Ask Toolbar
"ATI Display Driver" = ATI Display Driver
"Bywifi" = Bywifi 2.2.1
"CCleaner" = CCleaner (remove only)
"DivX Setup.divx.com" = DivX Setup
"D-Link VGA Webcam" = D-Link VGA Webcam
"DotA Allstars Launcher" = DotA Allstars Launcher
"Download Manager" = Download Manager 2.3.9
"eMusic Promotion" = eMusic - 50 Free MP3 offer
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Stylus C90_91_D92 User’s Guide" = EPSON Stylus C90_91_D92 Manual
"EUCOH" = City of Heroes/City of Villains (European) (remove only)
"Free Download Manager_is1" = Free Download Manager 2.5
"FrostWire" = FrostWire 4.18.6
"Google Chrome" = Google Chrome
"hon" = Heroes of Newerth
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Impulse" = Impulse
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{362D5167-9716-44BE-89FD-BF9EB6EF814B}" = DawnOfWar
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Picasa 3" = Picasa 3
"Recover My Files_is1" = Recover My Files
"Recuva" = Recuva
"RegDefense" = RegDefense
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"Secured eMule" = Secured eMule
"Secured eMule Toolbar" = Secured eMule Toolbar
"Software Informer_is1" = Software Informer 1.0 BETA
"SpeedBit Video Downloader" = SpeedBit Video Downloader
"Steam App 15620" = Warhammer 40,000: Dawn of War II
"Steam App 630" = Alien Swarm
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"vghd" = VirtuaGirl
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar for Internet Explorer
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Facebook Plug-In" = Facebook Plug-In
"ijji FireFox Launcher" = ijji FireFox Launcher 1.0
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 12/07/2010 02:30:57 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

Error - 12/07/2010 02:30:57 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

Error - 12/07/2010 12:31:07 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

Error - 12/07/2010 12:31:07 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

Error - 12/07/2010 13:24:51 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

Error - 12/07/2010 13:24:51 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

Error - 12/07/2010 14:44:28 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

Error - 12/07/2010 14:44:28 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

Error - 12/07/2010 14:59:35 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

Error - 12/07/2010 14:59:35 | Computer Name = ZAC-66AA64 | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 12/07/2010 15:09:33 | Computer Name = ZAC-66AA64 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
chrome.dll, version 5.0.375.99, fault address 0x0039cd07.

Error - 13/07/2010 15:39:34 | Computer Name = ZAC-66AA64 | Source = MsiInstaller | ID = 11327
Description = Product: Adobe Reader 8.1.0 – Error 1327.Invalid Drive: P:\

Error - 13/07/2010 15:40:01 | Computer Name = ZAC-66AA64 | Source = MsiInstaller | ID = 11327
Description = Product: Adobe Reader 8.1.0 – Error 1327.Invalid Drive: P:\

Error - 13/07/2010 15:40:21 | Computer Name = ZAC-66AA64 | Source = MsiInstaller | ID = 11327
Description = Product: Adobe Reader 8.1.0 – Error 1327.Invalid Drive: P:\

Error - 13/07/2010 15:43:24 | Computer Name = ZAC-66AA64 | Source = MsiInstaller | ID = 11327
Description = Product: Adobe Reader 8.1.0 – Error 1327.Invalid Drive: P:\

Error - 13/07/2010 15:47:37 | Computer Name = ZAC-66AA64 | Source = MsiInstaller | ID = 11327
Description = Product: Adobe Reader 9.3.3 – Error 1327.Invalid Drive: P:\

Error - 13/07/2010 15:47:47 | Computer Name = ZAC-66AA64 | Source = MsiInstaller | ID = 1023
Description = Product: Adobe Reader 9.3.3 - Update 'Adobe Reader 9.3.3 - CPSID_83708'
could not be installed. Error code 1603. Additional information is available in
the log file C:\DOCUME~1\Zac\LOCALS~1\Temp\MSI37fb8.LOG.

Error - 13/07/2010 15:47:47 | Computer Name = ZAC-66AA64 | Source = MsiInstaller | ID = 1023
Description = Product: Adobe Reader 9.3.3 - Update 'Adobe Reader 9.3.2 - CPSID_53951'
could not be installed. Error code 1603. Additional information is available in
the log file C:\DOCUME~1\Zac\LOCALS~1\Temp\MSI37fb8.LOG.

Error - 24/07/2010 10:22:29 | Computer Name = ZAC-66AA64 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 24/07/2010 10:22:29 | Computer Name = ZAC-66AA64 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

[ System Events ]
Error - 30/07/2010 14:25:57 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! iAVS4 Control Service service failed to start due to the
following error: %%3

Error - 30/07/2010 14:25:57 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! Antivirus service failed to start due to the following
error: %%3

Error - 31/07/2010 03:46:20 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! iAVS4 Control Service service failed to start due to the
following error: %%3

Error - 31/07/2010 03:46:20 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! Antivirus service failed to start due to the following
error: %%3

Error - 31/07/2010 09:10:33 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! iAVS4 Control Service service failed to start due to the
following error: %%3

Error - 31/07/2010 09:10:33 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! Antivirus service failed to start due to the following
error: %%3

Error - 01/08/2010 06:58:11 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! iAVS4 Control Service service failed to start due to the
following error: %%3

Error - 01/08/2010 06:58:11 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! Antivirus service failed to start due to the following
error: %%3

Error - 01/08/2010 16:18:12 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! iAVS4 Control Service service failed to start due to the
following error: %%3

Error - 01/08/2010 16:18:12 | Computer Name = ZAC-66AA64 | Source = Service Control Manager | ID = 7000
Description = The avast! Antivirus service failed to start due to the following
error: %%3


< End of report >

OTL logfile created on: 01/08/2010 21:53:38 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Program Files\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97.66 Gb Total Space | 34.95 Gb Free Space | 35.79% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 51.39 Gb Total Space | 37.69 Gb Free Space | 73.35% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ZAC-66AA64
Current User Name: Zac
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Bywifi\bywifi.exe (bywifi.com)
PRC - C:\Program Files\RegDefense\RDFNSListener.exe ()
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Program Files\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe File not found
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe File not found
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe File not found
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\rswin_3725.dll ()
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (ZDPSp50) – C:\WINDOWS\System32\Drivers\ZDPSp50.sys File not found
DRV - (USBAAPL) – C:\WINDOWS\System32\Drivers\usbaapl.sys File not found
DRV - (SetupNTGLM7X) – D:\NTGLM7X.sys File not found
DRV - (PCIIde) – C:\WINDOWS\System32\DRIVERS\pciide.sys File not found
DRV - (NTACCESS) – D:\NTACCESS.sys File not found
DRV - (MSICPL) – D:\install4\MSICPL.sys File not found
DRV - (IntelIde) – C:\WINDOWS\System32\DRIVERS\intelide.sys File not found
DRV - (GMSIPCI) – D:\INSTALL\GMSIPCI.SYS File not found
DRV - (catchme) – C:\DOCUME~1\Zac\LOCALS~1\Temp\catchme.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (MS1000) – C:\WINDOWS\system32\drivers\MS1000.sys ()
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (xfilt) – C:\WINDOWS\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc)
DRV - (videX32) – C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (UsbserFilt) – C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nmwcdc) – C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (upperdev) – C:\WINDOWS\system32\drivers\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nmwcd) – C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (BlueletAudio) – C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation)
DRV - (Btcsrusb) – C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation)
DRV - (BTHidEnum) – C:\WINDOWS\system32\drivers\vbtenum.sys ()
DRV - (BTHidMgr) – C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\BtNetDrv.sys (IVT Corporation)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation)
DRV - (ovt519) – C:\WINDOWS\system32\drivers\ov519vid.sys (OmniVision Technologies, Inc.)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\URLSearchHook: {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSecu.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: 0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: CA3EB689-8F09-4026-AA10-B9534C691CE0} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://localhost:9000/proxy.pac

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {0329E7D6-6F54-462D-93F6-F5C3118BADF2}:2.1.4
FF - prefs.js..keyword.URL: "http://search.speedbit.com/searchresults.asp?site=tb&q;="
FF - prefs.js..network.proxy.autoconfig_url: "http://localhost:9000/proxy.pac"
FF - prefs.js..network.proxy.no_proxies_on: "local"
FF - prefs.js..network.proxy.type: 2

FF - user.js..network.proxy.type: 2
FF - user.js..network.proxy.autoconfig_url: "http://localhost:9000/proxy.pac"

FF - HKLM\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SpeedBit Video Downloader\SPFireFox [2010/01/30 01:43:57 | 000,000,000 | —D | M]

[2010/04/16 16:12:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Mozilla\Extensions
[2009/04/11 21:36:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Mozilla\Firefox\extensions
[2009/04/11 21:36:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Zac\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010/04/27 20:02:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Mozilla\Firefox\Profiles\o8nbbkyi.default\extensions
[2010/04/17 08:10:47 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Zac\Application Data\Mozilla\Firefox\Profiles\o8nbbkyi.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/06/12 07:13:32 | 000,075,184 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll

O1 HOSTS File: ([2010/07/13 20:25:15 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Secured_eMule toolbar) - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSecu.dll (Conduit Ltd.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Winamp Toolbar BHO) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O2 - BHO: (SBCONVERT Class) - {3017FB3E-9A77-4396-88C5-0EC9548FB42F} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (SBCONVERT Class) - {A1056498-D09A-41E4-864B-505EDD640D9E} - C:\Program Files\SpeedBit Video Downloader\Toolbar\SpeedBitVideoDownloader.dll ()
O2 - BHO: (BywifiBHO Class) - {C4743D3E-20D7-4B52-84F2-5E4E277B2D82} - C:\Program Files\Bywifi\bywifiie.dll (bywifi.com)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SpeedBit Video Downloader\Toolbar\Grabber.dll (Speedbit Ltd.)
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Secured_eMule toolbar) - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSecu.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Secured_eMule toolbar) - {1D1B60FD-B21F-4B9A-8A5F-64E8544828D7} - C:\Program Files\Secured_eMule\tbSecu.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe (bywifi.com)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [RDFNSListener] C:\Program Files\RegDefense\RDFNSListener.exe ()
O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O4 - HKCU..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe (bywifi.com)
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Winamp; Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O9 - Extra Button: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (TODO: )
O9 - Extra 'Tools' menuitem : Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (TODO: )
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.1.4.cab (Bebo Uploader Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab (CDownloadCtrl Object)
O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} http://srtest-cdn.systemrequirementslab.co…eqlabdetect.cab (Reg Error: Value error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1192730461390 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1192731823093 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_07)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 192.168.1.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Zac\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Zac\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/18 18:08:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/01 21:24:17 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/07/28 14:51:54 | 000,139,264 | —- | C] (Blizzard Entertainment) – C:\WINDOWS\War3Unin.exe
[2010/07/28 13:08:56 | 000,000,000 | —D | C] – C:\Download
[2010/07/28 13:08:08 | 000,421,888 | —- | C] (NEXON Inc.) – C:\WINDOWS\NEXON_EU_DownloaderUpdater.exe
[2010/07/28 13:08:08 | 000,000,000 | —D | C] – C:\Nexon
[2010/07/28 08:59:51 | 000,000,000 | —D | C] – C:\Program Files\RegDefense
[2010/07/26 21:24:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/07/26 19:45:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Zac\Desktop\Logs
[2010/07/26 19:37:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft XNA
[2010/07/26 19:36:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Zac\Desktop\Bloodline+Champions+Beta+KeyGenerator
[2010/07/26 08:06:59 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/24 19:44:24 | 000,000,000 | —D | C] – C:\Program Files\EVE
[2010/07/19 18:16:47 | 000,000,000 | —D | C] – C:\Program Files\DivX Movies
[2010/07/18 03:29:27 | 000,000,000 | —D | C] – C:\Program Files\vghd
[2010/07/18 03:29:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Zac\Application Data\vghd
[2010/07/16 16:10:40 | 000,000,000 | —D | C] – C:\Program Files\Downloads
[2010/07/16 08:19:18 | 000,000,000 | R–D | C] – C:\Program Files\My Music
[2010/07/16 08:19:13 | 000,000,000 | R–D | C] – C:\Program Files\My Pictures
[2010/07/15 22:33:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Zac\FrostWire
[2010/07/14 19:18:52 | 000,000,000 | —D | C] – C:\DivX Movies
[2010/07/14 16:00:08 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/13 20:55:40 | 000,000,000 | —D | C] – C:\Heroes of Newerth
[2010/07/13 20:35:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Zac\Desktop\Unused Desktop Shortcuts
[2010/07/13 20:15:00 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/07/13 20:13:49 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/07/13 20:13:49 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/07/13 20:13:49 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/07/13 20:13:49 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/07/13 20:13:44 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/07/13 20:10:35 | 000,000,000 | —D | C] – C:\Qoobox
[2010/07/13 18:21:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/07/13 18:02:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Zac\Desktop\Advanced SystemCare Pro V3.0 Patch^N^Keygen,(Mrsilentlipes)
[2010/07/13 18:00:34 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2010/07/13 18:00:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Zac\Application Data\IObit
[2010/07/13 08:18:28 | 000,499,712 | —- | C] (eSage Lab) – C:\Documents and Settings\Zac\remover.exe
[2010/07/12 18:25:12 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2010/07/12 18:21:52 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/07/12 18:21:46 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/07/12 18:21:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/07/12 18:20:11 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/07/12 18:19:25 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/07/12 18:18:55 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/07/12 07:32:06 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Winamp Toolbar
[2010/07/11 17:17:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/11 16:25:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/07/11 16:00:45 | 000,000,000 | —D | C] – C:\Program Files\Real(2)
[2010/07/10 12:48:11 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Real
[2010/07/10 12:48:10 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Toolbar4
[2010/07/06 19:47:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DivX
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/01 21:25:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/01 21:20:08 | 000,000,372 | —- | M] () – C:\WINDOWS\tasks\AWC AutoSweep.job
[2010/08/01 21:19:26 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/01 21:17:59 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/01 21:17:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/01 17:14:19 | 009,437,184 | —- | M] () – C:\Documents and Settings\Zac\ntuser.dat
[2010/08/01 17:14:19 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Zac\ntuser.ini
[2010/08/01 17:14:10 | 005,359,144 | -H– | M] () – C:\Documents and Settings\Zac\Local Settings\Application Data\IconCache.db
[2010/08/01 16:19:21 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/07/29 16:55:00 | 000,002,038 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/29 12:09:36 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/28 15:41:23 | 000,082,795 | —- | M] () – C:\WINDOWS\War3Unin.dat
[2010/07/28 15:34:22 | 000,001,520 | —- | M] () – C:\Documents and Settings\Zac\Desktop\Frozen Throne.lnk
[2010/07/28 15:34:05 | 000,139,264 | —- | M] (Blizzard Entertainment) – C:\WINDOWS\War3Unin.exe
[2010/07/28 15:34:05 | 000,002,829 | —- | M] () – C:\WINDOWS\War3Unin.pif
[2010/07/28 14:53:28 | 000,001,513 | —- | M] () – C:\Documents and Settings\Zac\Desktop\Warcraft III.lnk
[2010/07/28 13:08:08 | 000,421,888 | —- | M] (NEXON Inc.) – C:\WINDOWS\NEXON_EU_DownloaderUpdater.exe
[2010/07/28 08:59:59 | 000,000,647 | —- | M] () – C:\Documents and Settings\Zac\Desktop\RegDefense.lnk
[2010/07/26 19:45:23 | 000,000,079 | —- | M] () – C:\Documents and Settings\Zac\Desktop\BloodlineChampions.ini
[2010/07/26 16:22:42 | 000,000,213 | —- | M] () – C:\Documents and Settings\Zac\Desktop\Alien Swarm.url
[2010/07/23 08:17:58 | 000,526,388 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/23 08:17:58 | 000,443,568 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/23 08:17:58 | 000,073,414 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/18 03:34:16 | 000,000,003 | —- | M] () – C:\WINDOWS\treeskp.sys
[2010/07/18 03:34:16 | 000,000,003 | —- | M] () – C:\WINDOWS\sbacknt.bin
[2010/07/18 03:29:27 | 000,152,904 | —- | M] () – C:\WINDOWS\System32\vghd.scr
[2010/07/15 20:50:35 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/14 19:19:05 | 000,001,149 | —- | M] () – C:\Documents and Settings\Zac\Desktop\DivX Movies.lnk
[2010/07/14 19:18:51 | 000,000,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/07/14 19:18:31 | 000,000,817 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Converter.lnk
[2010/07/13 20:25:15 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/13 20:15:06 | 000,000,293 | RHS- | M] () – C:\boot.ini
[2010/07/13 20:04:00 | 000,000,000 | —- | M] () – C:\Documents and Settings\Zac\defogger_reenable
[2010/07/12 19:01:40 | 000,001,678 | —- | M] () – C:\Documents and Settings\Zac\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/12 18:35:48 | 000,000,682 | —- | M] () – C:\Documents and Settings\Zac\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2010/07/12 18:20:33 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/07/12 18:19:27 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/12 18:08:14 | 000,002,137 | —- | M] () – C:\Documents and Settings\Zac\Desktop\iTunes.lnk
[2010/07/11 16:26:22 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/07/11 16:03:23 | 160,993,280 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/28 15:34:22 | 000,001,520 | —- | C] () – C:\Documents and Settings\Zac\Desktop\Frozen Throne.lnk
[2010/07/28 14:53:28 | 000,001,513 | —- | C] () – C:\Documents and Settings\Zac\Desktop\Warcraft III.lnk
[2010/07/28 14:51:55 | 000,082,795 | —- | C] () – C:\WINDOWS\War3Unin.dat
[2010/07/28 14:51:55 | 000,002,829 | —- | C] () – C:\WINDOWS\War3Unin.pif
[2010/07/28 08:59:59 | 000,000,647 | —- | C] () – C:\Documents and Settings\Zac\Desktop\RegDefense.lnk
[2010/07/26 19:45:23 | 000,000,079 | —- | C] () – C:\Documents and Settings\Zac\Desktop\BloodlineChampions.ini
[2010/07/26 16:22:42 | 000,000,213 | —- | C] () – C:\Documents and Settings\Zac\Desktop\Alien Swarm.url
[2010/07/18 03:29:29 | 000,000,003 | —- | C] () – C:\WINDOWS\treeskp.sys
[2010/07/18 03:29:29 | 000,000,003 | —- | C] () – C:\WINDOWS\sbacknt.bin
[2010/07/18 03:29:27 | 000,152,904 | —- | C] () – C:\WINDOWS\System32\vghd.scr
[2010/07/14 19:19:05 | 000,001,149 | —- | C] () – C:\Documents and Settings\Zac\Desktop\DivX Movies.lnk
[2010/07/14 19:18:50 | 000,000,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/07/14 19:18:31 | 000,000,817 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Converter.lnk
[2010/07/13 20:15:06 | 000,000,223 | —- | C] () – C:\Boot.bak
[2010/07/13 20:15:02 | 000,260,272 | —- | C] () – C:\cmldr
[2010/07/13 20:13:49 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/07/13 20:13:49 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/07/13 20:13:49 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/07/13 20:13:49 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/07/13 20:13:49 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/07/13 20:04:00 | 000,000,000 | —- | C] () – C:\Documents and Settings\Zac\defogger_reenable
[2010/07/13 18:17:24 | 000,000,372 | —- | C] () – C:\WINDOWS\tasks\AWC AutoSweep.job
[2010/07/13 08:18:28 | 000,003,089 | —- | C] () – C:\Documents and Settings\Zac\readme_ru.txt
[2010/07/13 08:18:28 | 000,002,697 | —- | C] () – C:\Documents and Settings\Zac\readme_en.txt
[2010/07/12 19:01:40 | 000,001,678 | —- | C] () – C:\Documents and Settings\Zac\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/12 18:22:41 | 000,002,038 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/12 18:20:33 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/01/06 15:34:28 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2009/12/23 00:59:32 | 000,041,872 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2009/11/06 11:58:04 | 000,178,975 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2009/08/03 01:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 01:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 01:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2009/03/03 22:10:06 | 000,005,376 | —- | C] () – C:\WINDOWS\System32\drivers\MS1000.sys
[2008/08/23 14:50:48 | 000,001,155 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/07/06 00:39:34 | 000,000,031 | —- | C] () – C:\WINDOWS\GunzLauncher.INI
[2008/03/26 19:23:31 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/03/26 19:21:10 | 000,000,025 | —- | C] () – C:\WINDOWS\CDED92Euro.ini
[2008/01/09 18:08:39 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/12/27 21:34:06 | 000,013,304 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2007/12/27 21:34:06 | 000,011,860 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[2007/10/18 18:36:03 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/10/18 18:32:02 | 000,000,000 | —- | C] () – C:\WINDOWS\msicpl.ini
[2007/09/17 01:07:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/09/17 01:07:00 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/09/17 01:07:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/09/17 01:07:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/09/17 01:07:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/07/12 14:44:42 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2004/08/04 13:00:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ipmontr.dll
[2004/03/23 16:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2010/07/11 16:25:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2008/10/31 23:37:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BufferZone
[2010/01/22 08:55:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2008/03/26 19:23:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2009/04/11 21:35:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FlashFXP
[2010/01/08 12:11:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
[2008/07/04 17:39:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IJJIGame
[2010/07/13 18:21:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/06/08 17:46:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2010/05/02 20:01:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/07/26 21:24:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/04/12 19:58:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Speedbit
[2009/04/16 07:38:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2010/05/02 10:37:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/03/26 19:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2009/04/15 18:41:56 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{1E77E486-38CF-4688-B1E4-B86D08856D09}
[2010/07/12 18:22:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/05/18 17:56:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\dota-allstars.71E01812711E1682B196CE418CDA466F24682743.1
[2009/07/12 10:52:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\dota_allstars
[2008/08/22 11:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Dreamlords
[2010/05/07 20:39:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Facebook
[2010/08/01 21:52:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Free Download Manager
[2010/07/15 22:44:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\FrostWire
[2009/05/26 01:05:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Zac\Application Data\ijjigame
[2010/07/13 18:00:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\IObit
[2008/07/20 21:07:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\LimeWire
[2010/05/14 19:31:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\LolClient
[2009/09/13 09:47:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2008/07/04 19:31:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\NPLUTO Corporation
[2009/01/24 17:16:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Samsung
[2010/01/08 12:13:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Software Informer
[2009/04/15 18:44:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Stardock
[2008/09/17 12:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\SystemRequirementsLab
[2010/01/30 01:43:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Toolbar4
[2010/05/02 20:30:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\Turbine
[2010/07/13 17:22:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\uTorrent
[2010/07/18 03:34:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Zac\Application Data\vghd
[2010/08/01 21:20:08 | 000,000,372 | —- | M] () – C:\WINDOWS\Tasks\AWC AutoSweep.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/07/12 15:18:52 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/07/12 15:18:52 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 19:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 19:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 19:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/07/12 15:18:52 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/07/12 15:18:52 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 01:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 01:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 01:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/14 01:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 01:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 01:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 01:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 01:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 01:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/14 01:11:51 | 000,033,280 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\cryptdll.dll
[2008/04/14 01:11:55 | 000,094,720 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\iphlpapi.dll
[2008/04/14 01:11:58 | 000,071,680 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msacm32.dll
[2009/03/08 04:22:38 | 000,156,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msls31.dll
[2008/04/13 19:30:46 | 000,061,440 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msvcrt40.dll
[2008/04/14 01:12:03 | 000,237,056 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\rasapi32.dll
[2008/04/14 01:12:03 | 000,061,440 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\rasman.dll
[2008/04/14 01:12:04 | 000,044,032 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\rtutils.dll
[2008/04/14 01:12:05 | 000,007,168 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\sensapi.dll
[2008/04/14 01:12:07 | 000,713,216 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\sxs.dll
[2008/04/14 01:12:07 | 000,181,760 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\tapi32.dll
[2008/04/13 18:39:24 | 002,897,920 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\xpsp2res.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2007/10/18 01:49:51 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/10/18 01:49:51 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/10/18 01:49:51 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

========== Alternate Data Streams ==========

@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A9662AE0
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63238B95
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI