This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu.com help ?

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi my computer is generally running slow and internet homepages have changed to searchqu.com when i open up new tabs, it has also started to pop up sites by itself - some not for family viewing !! and on some websites i get the message webpage could not be displayed……………Avast also reported a Dropper trojan ? Please could you take a look at my OTL files pasted below

Many Thanks in advance

OTL logfile created on: 29/04/2011 12:20:57 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Lee Edgar\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 192.00 Mb Available Physical Memory | 19.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 51.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.45 Gb Total Space | 26.47 Gb Free Space | 35.56% Space Free | Partition Type: NTFS
Drive G: | 149.05 Gb Total Space | 123.67 Gb Free Space | 82.98% Space Free | Partition Type: NTFS

Computer Name: MAINCOMPUTER | User Name: Lee Edgar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Documents and Settings\Lee Edgar\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\PrinterShare\paConsole.exe (PrinterAnywhere)
PRC - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
PRC - C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)
PRC - C:\Program Files\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Lee Edgar\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\Program Files\Unlocker\UnlockerHook.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SecureSrv) – File not found
SRV - (ResultBar Service) – File not found
SRV - (Pml Driver HPZ12) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (pdfFactory Pro Dispatcher v3) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (LBTServ) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (UxTuneUp) – C:\WINDOWS\SYSTEM32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (BVRPMPR5) – C:\WINDOWS\SYSTEM32\DRIVERS\BVRPMPR5.SYS (Avanquest Software)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (fssfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (nmwcd) – C:\WINDOWS\SYSTEM32\DRIVERS\ccdcmb.sys (Nokia)
DRV - (WinDriver6) – C:\WINDOWS\SYSTEM32\DRIVERS\windrvr6.sys (Jungo)
DRV - (LUsbFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouKE) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (LMouFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (L8042mou) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (L8042Kbd) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (PCANDIS5) – C:\WINDOWS\SYSTEM32\PCANDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (FilterService) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam E3500(UVC) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys ()
DRV - (pccsmcfd) – C:\WINDOWS\SYSTEM32\DRIVERS\pccsmcfd.sys (Nokia)
DRV - (s117obex) – C:\WINDOWS\SYSTEM32\DRIVERS\s117obex.sys (MCCI Corporation)
DRV - (s117mdm) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mdm.sys (MCCI Corporation)
DRV - (s117mgmt) Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mgmt.sys (MCCI Corporation)
DRV - (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117unic.sys (MCCI Corporation)
DRV - (s117nd5) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS) – C:\WINDOWS\SYSTEM32\DRIVERS\s117nd5.sys (MCCI Corporation)
DRV - (s117mdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mdfl.sys (MCCI Corporation)
DRV - (s117bus) Sony Ericsson Device 117 driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117bus.sys (MCCI Corporation)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (vaxscsi) – C:\WINDOWS\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (SE27mdm) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27mdm.sys (MCCI)
DRV - (SE27mdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27mdfl.sys (MCCI)
DRV - (SE27bus) Sony Ericsson Device 039 Driver driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27bus.sys (MCCI)
DRV - (LHidKe) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LHidUsbK) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidUsbK.sys (Logitech, Inc.)
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (Amps2prt) – C:\WINDOWS\SYSTEM32\DRIVERS\Amps2prt.sys (A4Tech Co.,Ltd.)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) – C:\WINDOWS\SYSTEM32\DRIVERS\alcan5wn.sys (THOMSON)
DRV - (alcaudsl) – C:\WINDOWS\SYSTEM32\DRIVERS\alcaudsl.sys (THOMSON)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (Machnm32) – C:\WINDOWS\SYSTEM32\Machnm32.sys ()
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (DCamUSBSQTECH) Dual-Mode DSC(2770) – C:\WINDOWS\SYSTEM32\DRIVERS\SQCaptur.sys (Service & Quality Technology.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (DLPortIO) – C:\WINDOWS\SYSTEM32\DRIVERS\DLPORTIO.SYS ()
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&am;…amp;affID=17978

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/iat/us_gb.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\..\URLSearchHook: {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbarsearch.com/?tmp=toolbar_mp3tube_results&prt;=pinballtb01ff&clid;=591a699985204c28835e93a02489f74a&subid;=&Keywords;={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 44
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:[removed]
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {34EFA911-B536-4C08-BECE-CD5E55C875B0}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: {40a1f5d7-afc2-498f-b264-02668d616ff6}:1.1
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.1.3
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=406&q;="

FF - user.js..keyword.URL: "http://mp3tubetoolbarsearch.com/?prt=pinballtb02ff&Keywords;="
FF - user.js..keyword.enabled: 1

FF - HKLM\software\mozilla\Firefox\extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010/04/15 23:15:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/18 15:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/24 13:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010/04/15 23:15:54 | 000,000,000 | —D | M]

[2011/04/24 14:09:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Extensions
[2011/04/24 14:09:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions
[2010/05/11 11:20:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/15 21:29:02 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/01/22 16:34:08 | 000,000,000 | —D | M] (Mega Manager Integration) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{40a1f5d7-afc2-498f-b264-02668d616ff6}
[2011/02/08 13:52:50 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/04/24 14:09:00 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011/01/16 20:18:29 | 000,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/09/15 19:29:11 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/02/08 13:53:02 | 000,000,000 | —D | M] (Page Speed) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2011/01/18 20:28:06 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/03/30 17:43:52 | 000,000,000 | —D | M] (Babylon) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\[removed]
[2010/12/31 15:35:08 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\[removed]
[2011/04/18 15:39:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\staged
[2011/01/22 16:35:54 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\vshare@toolbar
[2010/05/14 15:53:24 | 000,001,819 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\bing.xml
[2010/12/14 13:27:53 | 000,001,215 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\Mp3Tube.xml
[2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\SearchquWebSearch.xml
[2011/01/22 16:36:49 | 000,001,583 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\web-search.xml
[2011/04/24 14:09:21 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/14 14:30:39 | 000,000,000 | —D | M] (ResultBar) – C:\Program Files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
[2010/05/15 08:58:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/05 17:44:12 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/26 10:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/19 12:33:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/24 20:14:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
[2010/05/15 08:57:36 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/18 18:57:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/03/30 17:43:56 | 000,002,428 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/13 13:36:54 | 000,002,035 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchddr.xml
[2010/12/14 13:27:53 | 000,001,215 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\Mp3Tube.xml
[2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
[2010/01/01 09:00:00 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/04/14 18:49:40 | 000,000,734 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] File not found
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [iKeyWorks] C:\Program Files\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [pdfFactory Pro Dispatcher v3] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)
O4 - HKLM..\Run: [Windows Defender] File not found
O4 - HKCU..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [EPSON Stylus SX400 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [LDM] File not found
O4 - HKCU..\Run: [Mega Manager] C:\Program Files\Megaupload\Mega Manager\MegaManager.exe (Megaupload Limited)
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [PrinterShare] C:\Program Files\PrinterShare\paConsole.exe (PrinterAnywhere)
O4 - HKCU..\Run: [runner32] File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [Windows Defender] File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10o_ActiveX.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: Windows Defender = C:\Documents and Settings\Lee Edgar\Application Data\winup.exe
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: Policies = c:\directory\CyberGate\install\svchost.exe
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: ShopperReports - Compare product prices - {DB38E21A-0133-419d-92AD-ECDFD5244D6D} - Reg Error: Key error. File not found
O9 - Extra Button: ShopperReports - Compare travel rates - {EB620C54-E229-4942-87CE-E717109FC8C6} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: securesuite.co.uk ([www] https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} http://pcpitstop.com/internet/pcpConnCheck.cab (iCC Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} http://launcher.station.sony.com/weblaunch…ebInstaller.cab (SonyOnlineInstallerX)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} https://secure.footprint.net/kingsisle/stat…ameLauncher.CAB (Wizard101GameLauncher)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} http://u3.sandisk.com/download/apps/LPInstaller.CAB (CInstallLPCtrl Object)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.microsoft.com/download/Pow…N-US/msorun.cab (IEAnimBehaviorFactory Class)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\bw+0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\offline-8876480 {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\SYSTEM32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.SP54 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.SP55 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.SP56 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.SP57 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.SP58 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027075282206720)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/29 12:19:00 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lee Edgar\Desktop\OTL.exe
[2011/04/24 14:11:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Ilivid Player
[2011/04/24 14:09:50 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{6A6F35C2-F1BB-455A-85C0-F522DF746DDA}
[2011/04/24 14:09:34 | 000,000,000 | —D | C] – C:\Program Files\iLivid
[2011/04/24 14:08:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Application Data\searchqutoolbar
[2011/04/24 14:08:41 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/04/12 23:21:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\MetaGeek,_LLC
[2011/04/12 21:04:28 | 000,049,904 | R— | C] (Avanquest Software) – C:\WINDOWS\System32\drivers\BVRPMPR5.SYS
[2011/04/12 20:59:22 | 000,000,000 | —D | C] – C:\Netgear
[2011/04/12 12:50:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Application Data\PriceGong
[2011/04/12 12:23:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Application Data\BabylonToolbar
[2011/04/05 20:24:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\My Documents\EpicBot
[2011/04/05 20:23:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Yahoo
[2011/04/05 20:22:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\PackageAware
[2011/04/05 20:22:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2011/04/05 20:21:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2011/04/05 20:21:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Application Data\Yahoo!
[2011/04/05 20:21:07 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2011/04/04 11:21:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\My Documents\BookSmartData
[2011/04/04 11:20:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\.blurb
[2011/04/04 11:19:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\BookSmart
[2011/04/04 11:18:21 | 000,000,000 | —D | C] – C:\Program Files\BookSmart
[2011/04/02 12:33:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Wizard101(UK)
[2011/04/02 12:33:00 | 000,000,000 | —D | C] – C:\Program Files\Wizard101(UK)
[2006/10/28 16:10:12 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.sys
[7 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/29 12:57:36 | 000,004,204 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\data.dat
[2011/04/29 12:19:16 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lee Edgar\Desktop\OTL.exe
[2011/04/29 11:58:37 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/29 09:15:57 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job
[2011/04/28 22:05:51 | 000,000,129 | —- | M] () – C:\Documents and Settings\Lee Edgar\jagex_runescape_preferences2.dat
[2011/04/28 22:05:51 | 000,000,046 | —- | M] () – C:\Documents and Settings\Lee Edgar\jagex_runescape_preferences.dat
[2011/04/24 20:58:43 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/24 20:58:37 | 000,179,200 | —- | M] () – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/24 13:46:23 | 000,445,604 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2011/04/24 13:46:23 | 000,072,810 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2011/04/24 13:44:21 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/04/24 13:42:14 | 000,000,164 | —- | M] () – C:\WINDOWS\System32\FppLicense3.ini
[2011/04/24 13:41:05 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2011/04/24 13:33:53 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/23 12:26:22 | 010,541,276 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\Lee.zip
[2011/04/22 21:57:18 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/04/22 17:50:24 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2011/04/20 21:36:09 | 000,110,120 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/04/19 07:42:10 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/04/18 15:34:05 | 000,000,742 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/18 15:34:05 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/16 11:01:37 | 000,001,601 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\esemee prices.rtf
[2011/04/16 03:46:56 | 000,446,904 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/16 03:28:48 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/15 09:08:51 | 002,359,681 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\Router manual.pdf
[2011/04/12 22:29:12 | 000,006,203 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\Router_Setup.html
[2011/04/12 17:39:31 | 000,000,640 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\TweetDeck.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\BookSmart.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BookSmart.lnk
[7 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/28 20:53:10 | 000,004,179 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\data.dat
[2011/04/18 15:34:05 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/04/18 15:34:05 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/16 11:01:37 | 000,001,601 | —- | C] () – C:\Documents and Settings\Lee Edgar\My Documents\esemee prices.rtf
[2011/04/15 09:08:51 | 002,359,681 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Router manual.pdf
[2011/04/12 22:29:14 | 000,000,172 | R— | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Router Login.url
[2011/04/12 22:29:11 | 000,006,203 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Router_Setup.html
[2011/04/12 17:39:31 | 000,000,640 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\TweetDeck.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\BookSmart.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BookSmart.lnk
[2011/02/28 18:45:32 | 000,057,845 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\Lee Edgar3SQLite3.dll
[2011/02/25 14:24:42 | 000,000,000 | —- | C] () – C:\WINDOWS\Protector Eclipse.ini
[2011/02/20 08:19:06 | 001,970,176 | —- | C] () – C:\WINDOWS\System32\d3dx9.dll
[2011/01/01 14:36:58 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2010/12/06 14:58:56 | 002,496,715 | —- | C] () – C:\WINDOWS\System32\abgx360.exe
[2010/09/08 15:57:47 | 000,000,053 | —- | C] () – C:\WINDOWS\webica.ini
[2010/06/13 17:39:17 | 000,000,125 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/03/19 09:02:26 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\FppLicense3.ini
[2010/03/19 09:01:51 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\fppent3a.dll
[2009/12/28 21:18:54 | 000,110,120 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/21 00:51:22 | 000,001,353 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2009/11/19 20:57:14 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\dm.ini
[2009/09/10 20:16:37 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/09/04 17:35:54 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2009/09/04 17:35:51 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2009/05/29 20:40:06 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2009/05/29 19:50:27 | 000,111,932 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2009/05/29 19:50:27 | 000,001,146 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2009/05/29 19:50:27 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2009/05/29 19:50:27 | 000,001,120 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2009/05/29 19:50:27 | 000,001,107 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2009/05/29 19:50:27 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009/05/29 19:50:27 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/05/29 19:50:26 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2009/05/29 19:50:26 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2009/05/29 19:50:26 | 000,026,154 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2009/05/29 19:50:26 | 000,024,903 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2009/05/29 19:50:26 | 000,021,390 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2009/05/29 19:50:26 | 000,020,148 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2009/05/29 19:50:26 | 000,011,811 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2009/05/29 19:50:26 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2009/05/29 19:50:26 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2009/05/29 19:50:26 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2009/05/29 19:50:26 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2009/05/29 19:50:26 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2009/05/29 19:45:51 | 000,000,025 | —- | C] () – C:\WINDOWS\CDE SX400DEFGIPS.ini
[2009/05/03 17:18:19 | 000,081,110 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/12/17 21:51:13 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/12/16 21:58:54 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/12/16 21:50:56 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLgFT.dll
[2008/05/15 19:40:21 | 000,163,840 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\fontdb.mdb
[2008/05/15 19:40:21 | 000,000,130 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/03/12 20:28:43 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/03/02 14:54:08 | 000,001,057 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\vso_ts_preview.xml
[2007/12/07 22:19:24 | 000,001,298 | —- | C] () – C:\WINDOWS\ARCHPR.INI
[2007/11/12 17:12:54 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2007/11/10 15:14:20 | 000,015,840 | —- | C] () – C:\WINDOWS\System32\Machnm1.exe
[2007/11/10 15:14:20 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2007/05/08 14:26:59 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/02/25 13:48:02 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2006/12/03 12:04:03 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat_BAK_13980
[2006/12/03 12:04:03 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat
[2006/10/28 16:10:13 | 000,087,608 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\ezpinst.exe
[2006/10/28 16:10:13 | 000,007,824 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.cat
[2006/10/28 16:10:12 | 000,001,144 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.inf
[2006/09/26 20:37:54 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2006/09/07 21:58:16 | 000,696,320 | —- | C] () – C:\Program Files\Common Files\XCMHook.dll
[2006/09/07 21:58:16 | 000,024,576 | —- | C] () – C:\Program Files\Common Files\XCPCMenu.exe
[2006/08/19 12:21:38 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/08/19 11:56:35 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/07/29 22:23:21 | 000,737,280 | —- | C] () – C:\WINDOWS\dbplugin.exe
[2006/07/29 22:23:20 | 000,933,888 | —- | C] () – C:\WINDOWS\npdbplug.dll
[2006/07/29 22:23:20 | 000,346,624 | —- | C] () – C:\WINDOWS\dwbreader.exe
[2006/07/25 22:57:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/07/11 21:05:58 | 000,278,528 | —- | C] () – C:\Program Files\Common Files\FDEUnInstaller.exe
[2006/06/11 14:52:50 | 000,118,784 | R— | C] () – C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe
[2006/05/09 19:46:51 | 000,118,784 | —- | C] () – C:\WINDOWS\ShowBmp.exe
[2006/05/09 19:46:51 | 000,001,325 | —- | C] () – C:\WINDOWS\Remove.ini
[2006/04/20 20:13:52 | 000,000,959 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/04/20 19:34:17 | 000,002,215 | —- | C] () – C:\WINDOWS\CDPR.INI
[2006/03/05 14:51:06 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/10/03 19:14:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/10/03 09:16:04 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/09/23 23:43:24 | 003,596,288 | R— | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/09/23 23:43:24 | 000,159,744 | R— | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/09/23 23:43:22 | 000,831,488 | R— | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/09/23 23:43:22 | 000,524,288 | R— | C] () – C:\WINDOWS\System32\divxsm.exe
[2005/09/23 23:43:22 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\dtu100.dll
[2005/05/11 21:46:12 | 000,001,001 | —- | C] () – C:\WINDOWS\psmplay.ini
[2005/05/10 19:57:48 | 000,000,559 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/05/10 18:31:07 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\ESICOMMN.DLL
[2005/04/08 03:16:43 | 000,092,349 | -H– | C] () – C:\Documents and Settings\Lee Edgar\Application Data\Lee Edgarlog.dat
[2005/02/23 18:37:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlsz.INI
[2005/01/07 23:06:34 | 000,077,824 | —- | C] () – C:\WINDOWS\pysoft_uninstaller.exe
[2004/10/30 10:52:37 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/10/06 17:40:55 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2004/09/16 14:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 14:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/09/09 17:43:14 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/03/10 22:44:19 | 000,179,200 | —- | C] () – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/03/02 23:17:34 | 000,445,604 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/03/02 23:17:34 | 000,072,810 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/03/02 23:17:20 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/03/02 23:17:05 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/03/02 23:06:12 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/03/09 21:31:04 | 000,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2002/09/03 10:05:08 | 000,446,904 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2002/09/03 09:56:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/08/29 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2002/08/29 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2002/08/29 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2002/08/29 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2002/08/29 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2002/08/29 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/08/29 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2000/06/29 17:24:14 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\drivers\DLPORTIO.SYS
[1996/04/03 20:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
[1980/01/01 01:00:00 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\igfxtray.exe
[1980/01/01 01:00:00 | 000,126,976 | —- | C] () – C:\WINDOWS\System32\hkcmd.exe

========== LOP Check ==========

[2010/08/28 17:20:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/09/10 17:31:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2006/09/08 22:27:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bluetooth
[2009/05/29 19:49:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2010/04/15 23:13:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OviInstallerCache
[2010/04/15 23:33:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2011/03/08 22:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PrinterShare
[2010/12/26 17:58:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ResultBar
[2010/06/13 17:39:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2008/08/14 20:07:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2007/07/23 21:08:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SPAMfighter
[2006/09/09 20:15:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Teleca
[2010/08/16 21:23:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/09/11 19:31:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009/05/29 19:57:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2004/08/19 19:09:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/03/13 16:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011/04/24 14:09:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{6A6F35C2-F1BB-455A-85C0-F522DF746DDA}
[2009/12/25 08:27:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/11/07 20:41:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\.minecraft
[2011/01/20 20:08:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\abgx360
[2008/03/28 21:18:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\AutoTransfer
[2009/09/10 17:40:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\AVGTOOLBAR
[2008/06/01 09:57:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Azureus
[2011/04/12 12:23:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\BabylonToolbar
[2008/05/15 19:48:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\BorWare
[2010/03/02 08:36:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/05/16 13:49:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\com.imoneymanager.imm.2184A5AABEFD9A95272C652C16767C2B5E7A1512.1
[2010/12/12 13:14:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Electronic Arts
[2009/05/29 20:40:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\EPSON
[2011/01/16 09:58:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\facemoods.com
[2010/08/01 14:47:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\FixIt
[2010/08/04 17:49:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\FUJIFILM
[2011/01/01 14:37:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\GamesCafe
[2010/07/04 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\GameTuts
[2010/09/02 21:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\GARMIN
[2010/11/21 20:00:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\ICAClient
[2009/05/24 20:58:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Image Zone Express
[2011/01/20 22:37:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\ImgBurn
[2004/03/06 22:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Leadertech
[2008/06/01 09:57:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\MailWasherPro
[2011/01/20 00:13:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Megaupload
[2010/12/14 13:33:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar
[2010/04/15 23:35:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Nokia
[2010/04/15 23:33:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\PC Suite
[2011/04/12 12:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\PriceGong
[2011/04/24 14:09:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\searchqutoolbar
[2010/06/25 14:49:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\SmartDraw
[2011/03/30 17:43:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Sony
[2010/06/05 17:38:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Sony Online Entertainment
[2007/07/23 21:09:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\SPAMfighter
[2009/02/17 22:06:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Spectaculator
[2008/09/30 21:14:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\SpinTop
[2008/10/19 18:40:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Sports Interactive
[2009/09/23 22:30:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\TeamViewer
[2006/09/09 20:18:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Teleca
[2004/03/10 18:33:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Template
[2006/09/25 22:44:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\TuneUp Software
[2008/10/23 18:06:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\TuxPaint
[2010/10/25 17:21:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2004/08/19 19:09:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Ulead Systems
[2011/04/12 12:33:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Uniblue
[2011/04/24 20:54:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\uTorrent
[2010/09/25 16:02:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\vShare
[2011/03/31 19:58:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Vso
[2011/04/22 17:50:24 | 000,000,398 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job
[2011/04/29 09:15:57 | 000,000,430 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/03/09 20:11:55 | 000,504,058 | —- | M] () – C:\4D53082D.gpd
[2004/11/01 18:48:40 | 000,000,211 | —- | M] () – C:\Boot.bak
[2009/12/01 21:45:34 | 000,000,281 | -HS- | M] () – C:\BOOT.INI
[2002/09/03 09:38:46 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2002/09/03 09:59:58 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/17 21:57:15 | 000,000,133 | —- | M] () – C:\DeletePrintJobs.cmd
[2004/03/02 23:09:36 | 000,004,275 | RH– | M] () – C:\DELL.SDR
[2008/05/29 20:04:00 | 000,004,300 | —- | M] () – C:\hotfix.txt
[2009/05/25 09:53:48 | 000,000,488 | —- | M] () – C:\hpfr5550.xml
[2009/05/24 22:31:33 | 000,000,796 | -H– | M] () – C:\hpothb07.dat
[2009/05/24 22:31:33 | 000,001,495 | -H– | M] () – C:\hpothb07.tif
[2002/09/03 09:59:58 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2004/03/02 23:38:12 | 000,000,454 | -H– | M] () – C:\IPH.PH
[2002/09/03 09:59:58 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/11/01 18:39:33 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/06/01 16:26:41 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2006/09/07 22:03:30 | 000,000,456 | -H– | M] () – C:\os100944.bin
[2011/04/24 13:41:13 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2008/05/29 20:04:00 | 000,624,768 | —- | M] (Microsoft Corporation) – C:\q828133.exe
[2010/06/03 09:12:24 | 000,000,026 | —- | M] () – C:\register.js
[2009/04/30 10:19:06 | 000,345,448 | —- | M] (Adobe Systems Incorporated) – C:\Setup.exe
[2009/10/29 20:26:26 | 000,003,072 | -HS- | M] () – C:\Thumbs.db
[2004/05/04 22:39:47 | 000,000,016 | —- | M] () – C:\win2.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2002/09/03 09:59:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\msonpppr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/02/23 16:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2008/02/20 17:50:28 | 000,903,680 | —- | M] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Protector Eclipse.scr
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2006/06/28 22:04:42 | 000,001,618 | -H– | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2002/09/03 09:47:18 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002/09/03 09:47:18 | 000,602,112 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002/09/03 09:47:18 | 000,380,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/06/01 16:34:37 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/11/01 18:55:39 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/03/05 22:16:51 | 000,000,079 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/09/10 20:21:43 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Lee Edgar\Desktop\ATF-Cleaner.exe
[2011/02/25 15:36:03 | 010,257,408 | —- | M] (HaxScene.com) – C:\Documents and Settings\Lee Edgar\Desktop\Eclipse.exe
[2009/09/09 23:12:35 | 000,085,504 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\Inherit.exe
[2011/04/29 12:19:16 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lee Edgar\Desktop\OTL.exe
[2007/09/10 14:17:56 | 002,414,704 | —- | M] (Radica Games Limited) – C:\Documents and Settings\Lee Edgar\Desktop\Patch001.exe

< %PROGRAMFILES%\Common Files\*.* >
[2006/07/11 21:05:58 | 000,278,528 | —- | M] () – C:\Program Files\Common Files\FDEUnInstaller.exe
[2000/01/14 15:46:26 | 000,696,320 | —- | M] () – C:\Program Files\Common Files\XCMHook.dll
[2000/01/14 15:46:28 | 000,024,576 | —- | M] () – C:\Program Files\Common Files\XCPCMenu.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-28 16:44:41

< >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$hf_mig$\KB932168\KB932168] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB933729\KB933729] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB943460\KB943460] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\System.EnterpriseServices] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\IEExecRemote] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP283.tmp\ZAP283.tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA0.tmp\ZAPA0.tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\tmp\tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Cache\Adobe Reader 6.0.1\Adobe Reader 6.0.1] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Config\Config] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Connection Wizard\Connection Wizard] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Debug\UserMode\UserMode] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Downloaded Program Files\CONFLICT.1\CONFLICT.1] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ftpcache\ftpcache] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Help\SBSI\Training\WXPPer\Cbz\Cbz] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Help\SBSI\Training\WXPPer\Lib\Lib] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Help\SBSI\Training\WXPPer\Wave\Wave] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\IME\IMEJP\APPLETS\APPLETS] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\IME\IMEJP98\IMEJP98] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109411090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109440090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109511090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109711090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109910090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109B10090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109F100A0C00000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109F100C0400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\LastGood(2)\INF\INF] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Minidump\Minidump] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\MSAPPS\MSINFO\MSINFO] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\msdownld.tmp\msdownld.tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\MUI\MUI] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\ErrorRep\UserDumps\UserDumps] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\BATCH\BATCH] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\Config\CheckPoint\CheckPoint] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\HelpFiles\HelpFiles] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\InstalledSKUs\InstalledSKUs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\System\DFS\DFS] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\Temp\Temp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PIF\PIF] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Registration\CRMLog\CRMLog] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\REPAIR\Backup\ServiceState\ServiceState] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Sun\Java\Deployment\Deployment] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SxsCaPendDel\SxsCaPendDel] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1025\1025] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1028\1028] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1031\1031] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1037\1037] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1041\1041] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1042\1042] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1054\1054] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\2052\2052] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\3076\3076] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\3COM_DMI\3COM_DMI] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\Adobe\update\update] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\TempDir\TempDir] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Identities\{8D32DF8B-D3B8-4783-A0C5-FE37E2FC8659}\{8D32DF8B-D3B8-4783-A0C5-FE37E2FC8659}] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Credentials\Credentials] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\MMC\MMC] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun\Java\Deployment\javaws\cache\cache] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Desktop\Desktop] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\Credentials\Credentials] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My Pictures\Dell Image Expert Images\Dell Image Expert Images] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NetHood\NetHood] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\PrintHood\PrintHood] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\DHCP\DHCP] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\DRIVERS\DISDN\DISDN] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\EXPORT\EXPORT] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\FxsTmp\FxsTmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\INETSRV\INETSRV] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\Macromed\update\update] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\MUI\DISPSPEC\DISPSPEC] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\NtmsData\Export\Export] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\HTML\ISPSGNUP\ISPSGNUP] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\HTML\OEMCUST\OEMCUST] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\HTML\OEMHW\OEMHW] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\HTML\OEMREG\OEMREG] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\SAMPLE\SAMPLE] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\ShellExt\ShellExt] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\WBEM\MOF\BAD\BAD] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\WBEM\MOF\GOOD\GOOD] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\WBEM\SNMP\SNMP] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\WINS\WINS] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\XIRCOM\XIRCOM] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\WinSxS\InstallTemp\InstallTemp] -> \Device\__max++>\^ -> Mount Point

========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52B72A7C
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AFFC859A
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48A9EADC

< End of report >




OTL Extras logfile created on: 29/04/2011 12:20:57 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Lee Edgar\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 192.00 Mb Available Physical Memory | 19.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 51.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.45 Gb Total Space | 26.47 Gb Free Space | 35.56% Space Free | Partition Type: NTFS
Drive G: | 149.05 Gb Total Space | 123.67 Gb Free Space | 82.98% Space Free | Partition Type: NTFS

Computer Name: MAINCOMPUTER | User Name: Lee Edgar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.ini [@ = GetDiz.Document] – C:\Program Files\GetDiz\GetDiz.exe (Outer Technologies - http://outertech.com)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] – "C:\Program Files\FinePixViewer\FinePixViewer.exe" "%1" (FUJIFILM Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"16193:TCP" = 16193:TCP:*:Enabled:BitComet 16193 TCP
"16193:UDP" = 16193:UDP:*:Enabled:BitComet 16193 UDP
"55064:TCP" = 55064:TCP:*:Enabled:bitcomet 55064 tcp
"55064:UDP" = 55064:UDP:*:Enabled:bitcomet 55064 udp
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger – (Logitech)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast – (www.sopcast.com)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Disabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe" = C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0 – (Sony Creative Software Inc.)
"C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe" = C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Enabled:Football Manager 2008 – (Sports Interactive)
"C:\Program Files\PFPortChecker\PFPortChecker.exe" = C:\Program Files\PFPortChecker\PFPortChecker.exe:*:Enabled:PFPortchecker by portforward.com helps check if your ports are properly forwarded.
"C:\Documents and Settings\Lee Edgar\Application Data\SopCast\adv\SopAdver.exe" = C:\Documents and Settings\Lee Edgar\Application Data\SopCast\adv\SopAdver.exe:*:Enabled:SopAdver
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe" = C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application – (TeamViewer GmbH)
"C:\Program Files\Orange\Livebox\RGWREPAIR.EXE" = C:\Program Files\Orange\Livebox\RGWREPAIR.EXE:*:Enabled:RGWRepair – (Inventel)
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver – (www.sopcast.com)
"C:\Program Files\PrinterShare\paConsole.exe" = C:\Program Files\PrinterShare\paConsole.exe:*:Enabled:PrinterAnywhere Console – (PrinterAnywhere)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Windows iLivid Toolbar\ToolBar\dtUser.exe" = C:\Program Files\Windows iLivid Toolbar\ToolBar\dtUser.exe:*:Enabled:DTX broker – (Visicom Media Inc.)
"C:\DOCUME~1\LEEEDG~1\LOCALS~1\Temp\dll75.exe" = C:\DOCUME~1\LEEEDG~1\LOCALS~1\Temp\dll75.exe:*:Enabled:Windows Messanger
"C:\Documents and Settings\Lee Edgar\Application Data\winup.exe" = C:\Documents and Settings\Lee Edgar\Application Data\winup.exe:*:Enabled:Windows Messanger


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{06AC45D1-CB9B-48CC-B5C8-1A55DEE26AD0}" = Sony Ericsson Media Manager 1.0
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.5
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26792CA7-D87A-4DBE-896B-C2F66B344511}" =
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{26BDE7D8-93F0-4A07-AD47-1707DB417941}" = Camera Support Core Library
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2F81FBFC-9A37-431F-9050-14B55485DF5A}" = Internet Library
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{41A80758-D20A-4935-B128-15010FFF0001}" = PokerSidekick
"{42EDF895-158C-484E-A7F2-42B90759F281}" = Camera RAW Plug-In for EPSON Creativity Suite
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45EA11B5-874D-480E-89B9-2545505BBE3E}" = Microsoft OpenType Font File Properties Extension
"{46CBBDF8-55B5-40DB-B459-7B848394309C}" = EPSON File Manager
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E1CD3D5-D4EE-4246-AE24-F0FD5A60390D}" = OviMPlatform
"{4FFD1AB4-54F0-4069-88D9-3A55B38F874B}" = Nokia Ovi Suite Software Updater
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{607169F0-07F6-4797-99D2-D5E7C4715E20}" = Mega Manager
"{60DED9C2-22BF-47A3-B6C8-6B141BA31DFD}" = Ovi Desktop Sync Engine
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7397EDED-F38A-4654-B669-BF61065803D0}" = PC Connectivity Solution
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{7689CA7A-1270-425A-9959-EB4CB25EA29A}" = Sony Ericsson PC Suite 1.20.224
"{76BC2442-0002-47FA-9617-43BAD82BEF4C}" = Bonjour
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.0.0.1
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7784A172-61F1-445E-8368-601607E0DD22}" = MP3 Player Utilities 3.68
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{88D68A69-D247-466B-90DD-575F6BE16230}_is1" = CardRecovery 5.20
"{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A8F8391-4C2C-4BE1-A984-CD4A5A546467}" = EPSON Easy Photo Print
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90840409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{937B232D-9776-471E-92BD-D424E514EF14}" = Logitech QuickCam
"{9455959E-D588-EFAE-329C-F66CC797F32A}" = Adobe Media Player
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A4D10F4F-EF30-4498-8E18-CF2AB549DA97}" = PDF Download for Internet Explorer
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AD13BFB0-FDD2-4AFA-A8AF-9F4A950D56B7}" = ArcSoft Camera Suite 1.3
"{AEEB3643-71DE-414d-9E3F-1159177FE211}" = Office Animation Runtime
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AFE499B5-FCC4-45E6-A1A5-3C51AE0E539B}" = Mobipocket Creator 4.2
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2AE44CB-2AAB-4C08-A54B-D264BD604DA8}" = Citrix Presentation Server Client
"{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B9C9DB4C-6D77-4AE9-AD1C-C708C23239A0}" = Nokia Connectivity Cable Driver
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD 2.2.3.258
"{BBC0D330-C37B-4472-BFB9-AA217CF0C95F}" = Ulead Photo Express 4.0 SE
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1205500-2179-11D7-B0B9-0000E24D4B29}" = Digital Camera
"{C335649B-351B-4865-8136-F92D23340CF6}" = Spectaculator 6.25
"{C6E388F5-F0BE-A758-93BE-15758C09C0ED}" = TweetDeck
"{C8BB4912-12D9-42AE-B571-E580D8CD1B5B}" = TuneUp Utilities 2007
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDD55C1D-FC16-41F7-9E8D-884466E622EC}" = Roxio Easy DVD Copy 2
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}" = SpeedTouch USB Software
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.0.10.324
"{DCCF734A-42DA-4951-8C8E-92CD33D2FA2E}" = PrinterShare 2.3.05
"{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}" = Nokia Ovi Suite
"{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}" = FinePix Studio
"{E53A095D-F5A9-4D06-BEC9-98805DEDBF2A}_is1" = AmortizeIT! v3.2
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F01F78CF-A022-EA98-5E54-8F3D47DABDEE}" = iMoneyManager 1.1.1
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F19F7B24-AAD4-4236-8475-5335483DA676}" = Avery Wizard 3.1
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}" = Disc2Phone
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"A4Tech iKeyWorks" = A4Tech iKeyWorks 7.64
"abgx360" = abgx360 v1.0.5
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AdobeESD" = Adobe Download Manager 1.2 (Remove Only)
"Advanced Archive Password Recovery" = Advanced Archive Password Recovery (remove only)
"avast" = avast! Free Antivirus
"BookSmart® 3.0.2 3.0.2" = BookSmart® 3.0.2 3.0.2
"Branding" =
"Cheat Engine 5.5_is1" = Cheat Engine 5.5
"Cheat Engine 6.0_is1" = Cheat Engine 6.0
"CLUE Classic1.0" = CLUE Classic
"com.imoneymanager.imm.2184A5AABEFD9A95272C652C16767C2B5E7A1512.1" = iMoneyManager 1.1.1
"Connection Manager" =
"COVKITS Screensaver" = COVKITS Screensaver
"COVKITS[1] Screensaver" = COVKITS[1] Screensaver
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"DVD Decrypter" = DVD Decrypter (Remove Only)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Scanner" = EPSON Scan
"EPSON Stylus SX200_SX400_TX200_TX400 User’s Guide" = EPSON Stylus SX200_SX400_TX200_TX400 Manual
"EPSON Stylus SX400 Series" = EPSON Stylus SX400 Series Printer Uninstall
"ERUNT_is1" = ERUNT 1.1j
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Football Manager 2008" = Football Manager 2008
"GetDiz 3.0" = GetDiz 3.0
"Halo Tool Box" = Halo Tool Box
"Highfieldroad Screensaver" = Highfieldroad Screensaver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"iLivid" = iLivid
"ImgBurn" = ImgBurn
"InstallShield Uninstall Information" =
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{26BDE7D8-93F0-4A07-AD47-1707DB417941}" = Canon Camera Support Core Library
"InstallShield_{2F81FBFC-9A37-431F-9050-14B55485DF5A}" = Canon Internet Library for ZoomBrowser EX
"InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"Intelore - RAR Password Recovery" = RAR Password Recovery v1.1 RC16 (remove only)
"IrfanView" = IrfanView (remove only)
"legacyqcam_11.10" = Logitech Legacy USB Camera Driver Package
"lvdrivers_11.90" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"modding programs" = modding programs
"Mozilla Firefox 4.0 (x86 en-GB)" = Mozilla Firefox 4.0 (x86 en-GB)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"Nero - Burning Rom!UninstallKey" =
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia Ovi Suite" = Nokia Ovi Suite
"orange3" = Orange Search Toolbar
"PartyTool_is1" = PartyTool 1.24
"PCHealth" =
"pdfFactory Pro" = pdfFactory Pro
"PonyProg v1.17h_is1" = PonyProg v1.17h
"Protector Eclipse_is1" = Protector Eclipse
"QuickSFV" = QuickSFV (Remove only)
"RealPlayer 12.0" = RealPlayer
"ResultBar" = ResultBar 1.0 build 115
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"SkyBlue70s Screensaver" = SkyBlue70s Screensaver
"SontheVilla Screensaver" = SontheVilla Screensaver
"SopCast" = SopCast 3.2.9
"Space Invaders_is1" = Space Invaders 1.1.0
"SpywareGuard_is1" = SpywareGuard v2.2
"SSC Service Utility_is1" = SSC Service Utility v4.30
"Sunplus CA533A" = Icatch(IV) Camera Driver
"TeamViewer 4" = TeamViewer 4
"ToolBand.SkypeIEToolbarToolbar" = Skype add-on for IE
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"U.B. Funkeys" = U.B. Funkeys
"Unlocker" = Unlocker 1.8.5
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV 0.9.18
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6a
"VoilaBar" =
"vShare" = vShare Plugin
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WheelMouse" = A4Tech iWheelWorks 7.64
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinISO_is1" = WinISO 5.3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Wizard101(UK)_is1" = Wizard101(UK)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WMV9_VCM" = Microsoft Windows Media Video 9 VCM
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"EA SPORTS Gameface Browser Plugin" = EA SPORTS Gameface Browser Plugin 1.3.0.0
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 21/08/2010 23:54:16 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

Error - 22/08/2010 17:54:04 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

Error - 23/08/2010 12:41:23 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

Error - 24/08/2010 08:36:56 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

Error - 25/08/2010 05:47:04 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

Error - 26/08/2010 00:07:51 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

Error - 26/08/2010 18:22:37 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

Error - 27/08/2010 06:58:01 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

Error - 27/08/2010 13:53:37 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

Error - 28/08/2010 09:26:39 | Computer Name = MAINCOMPUTER | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 24/04/2011 08:45:33 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: Our Record 3 lost: 9B977D9C 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 13924 MAINCOMPUTER.local.

Error - 24/04/2011 08:45:33 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: Pkt Record: 9B977D9C 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 13924 MAINCOMPUTER.local.

Error - 24/04/2011 08:45:33 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: Our Record 2 won: 9B977D9C 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 25654 MAINCOMPUTER.local.

Error - 24/04/2011 08:45:33 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: Pkt Record: 9B977D9C 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 25654 MAINCOMPUTER.local.

Error - 24/04/2011 08:45:33 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: Our Record 3 lost: 9B977D9C 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 13924 MAINCOMPUTER.local.

Error - 24/04/2011 08:45:33 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: Pkt Record: 9B977D9C 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 25654 MAINCOMPUTER.local.

Error - 24/04/2011 08:45:33 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: Our Record 3 lost: 9B977D9C 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 13924 MAINCOMPUTER.local.

Error - 24/04/2011 08:45:34 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: Ignoring response received before we even
began probing: 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 13924 MAINCOMPUTER.local.

Error - 24/04/2011 08:45:34 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: Received from 192.168.0.4:1025 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 25654 MAINCOMPUTER.local.

Error - 24/04/2011 08:45:34 | Computer Name = MAINCOMPUTER | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: ProbeCount 2; will rename 26 The\032Edgar\032Family\032Computer._printershare._tcp.local.
SRV 0 0 13924 MAINCOMPUTER.local.

[ System Events ]
Error - 29/04/2011 06:58:54 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding

Error - 29/04/2011 06:58:55 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding

Error - 29/04/2011 06:58:55 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding

Error - 29/04/2011 06:58:55 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding

Error - 29/04/2011 06:58:55 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding

Error - 29/04/2011 06:58:55 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding

Error - 29/04/2011 06:58:55 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding

Error - 29/04/2011 06:58:56 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding

Error - 29/04/2011 06:58:56 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding

Error - 29/04/2011 06:58:56 | Computer Name = MAINCOMPUTER | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The
error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe
-secured -Embedding


< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, edgardavids

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

—————————————————————————————————

You have ( µTorrent ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


—————————————————————————————————
Hi, before we go any further I would like to have an antirookit scan.

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
hi Conspire

thanks for your help

here is the info you requested, could not seem to upload so i pasted - hope that is ok


GMER 1.0.15.15572 - http://www.gmer.net
Rootkit scan 2011-05-01 09:14:50
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort0 ST380011A rev.3.16
Running: 969vs1vb.exe; Driver: C:\DOCUME~1\LEEEDG~1\LOCALS~1\Temp\pxdyrpob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xEE9CE9CA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xEEA23A68]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xEE9EEAF5]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xEE9D0EAC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xEE9D0F04]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xEE9D101A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xEE9EE4A9]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xEE9D0E02]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xEE9D0F54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xEE9D0E56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xEE9D0FC8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xEE9CE9EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xEE9EF1BB]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xEE9EF471]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xEE9D129E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xEE9EF026]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xEE9EEE91]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xEEA23B18]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xEE9CE7B8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xEE9CEA12]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xEE9D1412]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xEE9CF4AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xEE9D0EDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xEE9D0F2C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xEE9D1044]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xEE9EE805]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xEE9D0E2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xEE9D10D6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xEE9D0F94]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xEE9D0E84]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xEE9D11BA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xEE9D0FF2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xEEA23BB0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xEE9EED0C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xEE9CF370]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xEE9EEB5E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xEEA2BE26]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xEE9EDB1C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xEE9CEA36]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xEE9CEA5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xEE9CE812]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xEE9CE94E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xEE9EF2C2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xEE9CE92A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xEE9CE972]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEEB2F620]
SSDT \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys ZwUnloadKey [0xED9326D0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xEE9CEA7E]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xEEA388DE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!_abnormal_termination + 70 804E26DC 4 Bytes JMP 0638157D
.text ntoskrnl.exe!_abnormal_termination + B0 804E271C 4 Bytes JMP B9C2EE9E
.text ntoskrnl.exe!_abnormal_termination + 140 804E27AC 4 Bytes JMP FA62164D
.text ntoskrnl.exe!_abnormal_termination + 200 804E286C 4 Bytes JMP 4261EE9C
.text ntoskrnl.exe!_abnormal_termination + 228 804E2894 8 Bytes CALL 8E7D1737
.text …
PAGE ntoskrnl.exe!ObInsertObject 805650BA 5 Bytes JMP EEA35D38 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 3CC 8056BB08 4 Bytes CALL EE9CFE25 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8058124C 7 Bytes JMP EEA388E2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ObMakeTemporaryObject 805A038B 5 Bytes JMP EEA3429E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload F70B78AC 5 Bytes JMP 871CF1C8
? System32\Drivers\apb4d5x9.SYS The system cannot find the path specified. !
? C:\WINDOWS\system32\Drivers\uphcleanhlp.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B00E4
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0120
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B00A8
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B0030
.text C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE[184] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B006C
.text C:\WINDOWS\System32\svchost.exe[240] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\System32\svchost.exe[240] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\System32\svchost.exe[240] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\System32\svchost.exe[240] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\System32\svchost.exe[240] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\System32\svchost.exe[240] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\System32\svchost.exe[240] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\System32\svchost.exe[240] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\System32\svchost.exe[240] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\System32\svchost.exe[240] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\System32\svchost.exe[240] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\System32\svchost.exe[240] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\System32\svchost.exe[240] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\System32\svchost.exe[240] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\System32\svchost.exe[240] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\Program Files\UPHClean\uphclean.exe[280] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\Program Files\UPHClean\uphclean.exe[280] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\Program Files\SpywareGuard\sgmain.exe[536] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003800E4
.text C:\Program Files\SpywareGuard\sgmain.exe[536] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380120
.text C:\Program Files\SpywareGuard\sgmain.exe[536] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003800A8
.text C:\Program Files\SpywareGuard\sgmain.exe[536] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00380030
.text C:\Program Files\SpywareGuard\sgmain.exe[536] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0038006C
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\SpywareGuard\sgmain.exe[536] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 004D01D4
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 004D00E4
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 004D0120
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 004D015C
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 004D0198
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 004D0030
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 004D006C
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 004D00A8
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 004E00E4
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 004E0120
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 004E00A8
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 004E0030
.text C:\Program Files\Logitech\SetPoint\SetPoint.exe[544] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 004E006C
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002D01D4
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002D00E4
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002D0120
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002D015C
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002D0198
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002D0030
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002D006C
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002D00A8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002E00E4
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002E0120
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002E00A8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002E0030
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[608] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002E006C
.text C:\WINDOWS\Explorer.EXE[620] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\Explorer.EXE[620] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\Explorer.EXE[620] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C01D4
.text C:\WINDOWS\Explorer.EXE[620] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C00E4
.text C:\WINDOWS\Explorer.EXE[620] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0120
.text C:\WINDOWS\Explorer.EXE[620] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C015C
.text C:\WINDOWS\Explorer.EXE[620] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0198
.text C:\WINDOWS\Explorer.EXE[620] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C0030
.text C:\WINDOWS\Explorer.EXE[620] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C006C
.text C:\WINDOWS\Explorer.EXE[620] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C00A8
.text C:\WINDOWS\Explorer.EXE[620] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D00E4
.text C:\WINDOWS\Explorer.EXE[620] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0120
.text C:\WINDOWS\Explorer.EXE[620] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D00A8
.text C:\WINDOWS\Explorer.EXE[620] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D0030
.text C:\WINDOWS\Explorer.EXE[620] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D006C
.text C:\WINDOWS\Explorer.EXE[620] SHELL32.dll!SHFileOperationW 7CA708A0 5 Bytes JMP 00CD1102 C:\Program Files\Unlocker\UnlockerHook.dll
.text C:\WINDOWS\system32\winlogon.exe[720] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00070030
.text C:\WINDOWS\system32\winlogon.exe[720] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0007006C
.text C:\WINDOWS\system32\winlogon.exe[720] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\winlogon.exe[720] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\winlogon.exe[720] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\winlogon.exe[720] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\winlogon.exe[720] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\winlogon.exe[720] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\winlogon.exe[720] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\winlogon.exe[720] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\winlogon.exe[720] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\winlogon.exe[720] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\winlogon.exe[720] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\winlogon.exe[720] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\winlogon.exe[720] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\services.exe[764] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\services.exe[764] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\services.exe[764] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\services.exe[764] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\services.exe[764] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\services.exe[764] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\services.exe[764] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\services.exe[764] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\services.exe[764] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\services.exe[764] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\services.exe[764] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\services.exe[764] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\services.exe[764] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\services.exe[764] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\services.exe[764] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\lsass.exe[776] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\lsass.exe[776] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\lsass.exe[776] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\lsass.exe[776] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\lsass.exe[776] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\lsass.exe[776] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\lsass.exe[776] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\svchost.exe[944] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[944] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[944] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[944] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[944] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[944] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[944] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\System32\svchost.exe[996] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\System32\svchost.exe[996] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\System32\svchost.exe[996] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\System32\svchost.exe[996] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\System32\svchost.exe[996] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\System32\svchost.exe[996] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\System32\svchost.exe[996] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\System32\svchost.exe[996] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\System32\svchost.exe[996] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\System32\svchost.exe[996] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\System32\svchost.exe[996] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\System32\svchost.exe[996] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\System32\svchost.exe[996] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\System32\svchost.exe[996] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\System32\svchost.exe[996] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\svchost.exe[1012] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[1012] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\System32\svchost.exe[1108] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\System32\svchost.exe[1108] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\System32\svchost.exe[1132] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\System32\svchost.exe[1132] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[1188] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[1188] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[1188] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1188] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[1188] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1208] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[1244] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[1244] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[1244] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1244] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[1244] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\Bonjour\mDNSResponder.exe[1260] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\WINDOWS\System32\svchost.exe[1312] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\System32\svchost.exe[1312] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\System32\svchost.exe[1312] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\System32\svchost.exe[1312] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\System32\svchost.exe[1312] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\System32\svchost.exe[1312] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\System32\svchost.exe[1312] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00080030
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0008006C
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C01D4
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C00E4
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0120
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C015C
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0198
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C0030
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C006C
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C00A8
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D00E4
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0120
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D00A8
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D0030
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE[1324] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D006C
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003800E4
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380120
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003800A8
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00380030
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0038006C
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\SpywareGuard\sgbhp.exe[1464] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\WINDOWS\system32\svchost.exe[1492] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[1492] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[1492] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[1492] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[1492] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1492] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[1492] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00080030
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0008006C
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C01D4
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C00E4
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0120
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C015C
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0198
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C0030
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C006C
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C00A8
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D00E4
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0120
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D00A8
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D0030
.text C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE[1548] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D006C
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1616] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\Java\jre6\bin\jqs.exe[1780] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[1808] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00050030
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0005006C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002A00E4
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002A0120
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002A00A8
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002A0030
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002A006C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[1840] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1872] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe[1904] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\WINDOWS\system32\spoolsv.exe[2032] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\spoolsv.exe[2032] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\spoolsv.exe[2032] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\spoolsv.exe[2032] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\spoolsv.exe[2032] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\spoolsv.exe[2032] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\spoolsv.exe[2032] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\spoolsv.exe[2032] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\spoolsv.exe[2032] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\spoolsv.exe[2032] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\spoolsv.exe[2032] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\spoolsv.exe[2032] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\spoolsv.exe[2032] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\spoolsv.exe[2032] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\spoolsv.exe[2032] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2080] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\Program Files\DAEMON Tools\daemon.exe[2308] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\WINDOWS\system32\ctfmon.exe[2404] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000A0030
.text C:\WINDOWS\system32\ctfmon.exe[2404] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000A006C
.text C:\WINDOWS\system32\ctfmon.exe[2404] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C01D4
.text C:\WINDOWS\system32\ctfmon.exe[2404] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\ctfmon.exe[2404] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\ctfmon.exe[2404] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C015C
.text C:\WINDOWS\system32\ctfmon.exe[2404] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0198
.text C:\WINDOWS\system32\ctfmon.exe[2404] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\ctfmon.exe[2404] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\ctfmon.exe[2404] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\ctfmon.exe[2404] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D00E4
.text C:\WINDOWS\system32\ctfmon.exe[2404] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0120
.text C:\WINDOWS\system32\ctfmon.exe[2404] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D00A8
.text C:\WINDOWS\system32\ctfmon.exe[2404] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D0030
.text C:\WINDOWS\system32\ctfmon.exe[2404] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D006C
.text C:\WINDOWS\BCMSMMSG.exe[2656] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\WINDOWS\BCMSMMSG.exe[2656] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\WINDOWS\BCMSMMSG.exe[2656] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003800E4
.text C:\WINDOWS\BCMSMMSG.exe[2656] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380120
.text C:\WINDOWS\BCMSMMSG.exe[2656] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003800A8
.text C:\WINDOWS\BCMSMMSG.exe[2656] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00380030
.text C:\WINDOWS\BCMSMMSG.exe[2656] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0038006C
.text C:\WINDOWS\BCMSMMSG.exe[2656] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\WINDOWS\BCMSMMSG.exe[2656] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\WINDOWS\BCMSMMSG.exe[2656] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\WINDOWS\BCMSMMSG.exe[2656] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\WINDOWS\BCMSMMSG.exe[2656] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\WINDOWS\BCMSMMSG.exe[2656] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\WINDOWS\BCMSMMSG.exe[2656] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\WINDOWS\BCMSMMSG.exe[2656] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\WINDOWS\System32\DSentry.exe[2664] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\WINDOWS\System32\DSentry.exe[2664] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\WINDOWS\System32\DSentry.exe[2664] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003801D4
.text C:\WINDOWS\System32\DSentry.exe[2664] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003800E4
.text C:\WINDOWS\System32\DSentry.exe[2664] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380120
.text C:\WINDOWS\System32\DSentry.exe[2664] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0038015C
.text C:\WINDOWS\System32\DSentry.exe[2664] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380198
.text C:\WINDOWS\System32\DSentry.exe[2664] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00380030
.text C:\WINDOWS\System32\DSentry.exe[2664] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0038006C
.text C:\WINDOWS\System32\DSentry.exe[2664] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003800A8
.text C:\WINDOWS\System32\DSentry.exe[2664] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\WINDOWS\System32\DSentry.exe[2664] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\WINDOWS\System32\DSentry.exe[2664] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\WINDOWS\System32\DSentry.exe[2664] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\WINDOWS\System32\DSentry.exe[2664] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\WINDOWS\system32\rundll32.exe[2688] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\rundll32.exe[2688] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\rundll32.exe[2688] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\rundll32.exe[2688] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\rundll32.exe[2688] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\rundll32.exe[2688] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\rundll32.exe[2688] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\rundll32.exe[2688] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C01D4
.text C:\WINDOWS\system32\rundll32.exe[2688] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\rundll32.exe[2688] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\rundll32.exe[2688] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C015C
.text C:\WINDOWS\system32\rundll32.exe[2688] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0198
.text C:\WINDOWS\system32\rundll32.exe[2688] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\rundll32.exe[2688] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\rundll32.exe[2688] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C00A8
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003800E4
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380120
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003800A8
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00380030
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0038006C
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe[2732] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003800E4
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380120
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003800A8
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00380030
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0038006C
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe[2740] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[2776] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003801D4
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003800E4
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380120
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0038015C
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380198
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00380030
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0038006C
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003800A8
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\Program Files\Unlocker\UnlockerAssistant.exe[2792] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003C00E4
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003C0120
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003C00A8
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003C0030
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003C006C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003D01D4
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003D00E4
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003D0120
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003D015C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003D0198
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003D0030
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003D006C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2832] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003D00A8
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B00E4
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0120
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B00A8
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B0030
.text C:\Program Files\Logitech\QuickCam\Quickcam.exe[2856] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B006C
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003B01D4
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003B00E4
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003B0120
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003B015C
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003B0198
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003B0030
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003B006C
.text C:\Program Files\Skype\Phone\Skype.exe[2912] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003B00A8
.text C:\Program Files\Skype\Phone\Skype.exe[2912] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003C00E4
.text C:\Program Files\Skype\Phone\Skype.exe[2912] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003C0120
.text C:\Program Files\Skype\Phone\Skype.exe[2912] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003C00A8
.text C:\Program Files\Skype\Phone\Skype.exe[2912] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003C0030
.text C:\Program Files\Skype\Phone\Skype.exe[2912] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003C006C
.text C:\Program Files\QuickTime\QTTask.exe[2948] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\QuickTime\QTTask.exe[2948] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\QuickTime\QTTask.exe[2948] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\Program Files\QuickTime\QTTask.exe[2948] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\Program Files\QuickTime\QTTask.exe[2948] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\Program Files\QuickTime\QTTask.exe[2948] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\Program Files\QuickTime\QTTask.exe[2948] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\Program Files\QuickTime\QTTask.exe[2948] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\Program Files\QuickTime\QTTask.exe[2948] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\Program Files\QuickTime\QTTask.exe[2948] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\Program Files\QuickTime\QTTask.exe[2948] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\Program Files\QuickTime\QTTask.exe[2948] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\Program Files\QuickTime\QTTask.exe[2948] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\Program Files\QuickTime\QTTask.exe[2948] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\Program Files\QuickTime\QTTask.exe[2948] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\Program Files\iTunes\iTunesHelper.exe[2980] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\Program Files\PrinterShare\paConsole.exe[3200] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\Program Files\PrinterShare\paConsole.exe[3200] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B00E4
.text C:\Program Files\PrinterShare\paConsole.exe[3200] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0120
.text C:\Program Files\PrinterShare\paConsole.exe[3200] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B00A8
.text C:\Program Files\PrinterShare\paConsole.exe[3200] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B0030
.text C:\Program Files\PrinterShare\paConsole.exe[3200] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B006C
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003800E4
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380120
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003800A8
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00380030
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0038006C
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[3324] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000A0030
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000A006C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 009801D4
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 009800E4
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00980120
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0098015C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00980198
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00980030
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0098006C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 009800A8
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 009900E4
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00990120
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 009900A8
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00990030
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3396] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0099006C
.text C:\WINDOWS\System32\alg.exe[3416] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\WINDOWS\System32\alg.exe[3416] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\WINDOWS\System32\alg.exe[3416] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002B00E4
.text C:\WINDOWS\System32\alg.exe[3416] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002B0120
.text C:\WINDOWS\System32\alg.exe[3416] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002B00A8
.text C:\WINDOWS\System32\alg.exe[3416] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002B0030
.text C:\WINDOWS\System32\alg.exe[3416] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002B006C
.text C:\WINDOWS\System32\alg.exe[3416] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C01D4
.text C:\WINDOWS\System32\alg.exe[3416] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C00E4
.text C:\WINDOWS\System32\alg.exe[3416] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0120
.text C:\WINDOWS\System32\alg.exe[3416] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C015C
.text C:\WINDOWS\System32\alg.exe[3416] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0198
.text C:\WINDOWS\System32\alg.exe[3416] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C0030
.text C:\WINDOWS\System32\alg.exe[3416] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C006C
.text C:\WINDOWS\System32\alg.exe[3416] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C00A8
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003800E4
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380120
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003800A8
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00380030
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0038006C
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe[3440] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\iPod\bin\iPodService.exe[3812] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\iPod\bin\iPodService.exe[3812] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\iPod\bin\iPodService.exe[3812] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\iPod\bin\iPodService.exe[3812] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\iPod\bin\iPodService.exe[3812] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\iPod\bin\iPodService.exe[3812] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B00E4
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0120
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B00A8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B0030
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3940] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B006C
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] user32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] user32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] user32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] user32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] user32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] advapi32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] advapi32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] advapi32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] advapi32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] advapi32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] advapi32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] advapi32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\Program Files\Skype\Plugin Manager\skypePM.exe[4076] advapi32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\Documents and Settings\Lee Edgar\Desktop\969vs1vb.exe[4892] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00150030
.text C:\Documents and Settings\Lee Edgar\Desktop\969vs1vb.exe[4892] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\internet explorer\iexplore.exe[4904] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10047D70 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 10047CF0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ntdll.dll!NtDeleteKey 7C90D24E 5 Bytes JMP 10047D90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ntdll.dll!NtDeleteValueKey 7C90D26E 5 Bytes JMP 10047DB0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10047D20 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ntdll.dll!NtQueryValueKey 7C90D96E 5 Bytes JMP 10047C90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 10047CC0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00D20780 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\internet explorer\iexplore.exe[4904] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003E01D4
.text C:\Program Files\internet explorer\iexplore.exe[4904] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003E00E4
.text C:\Program Files\internet explorer\iexplore.exe[4904] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003E0120
.text C:\Program Files\internet explorer\iexplore.exe[4904] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003E015C
.text C:\Program Files\internet explorer\iexplore.exe[4904] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003E0198
.text C:\Program Files\internet explorer\iexplore.exe[4904] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003E0030
.text C:\Program Files\internet explorer\iexplore.exe[4904] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003E006C
.text C:\Program Files\internet explorer\iexplore.exe[4904] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003E00A8
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9B01 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD125 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB5C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254664 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003F00A8
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003F0030
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003F006C
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5117 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E5049 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E50B4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4F1A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4F7C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E517A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4FDE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] SHLWAPI.dll!SHCreateStreamOnFileA + 2066 77FC22BC 5 Bytes JMP 00D1C790 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDBB8 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[4904] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E547F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00140030
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0014006C
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[4956] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00090030
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0009006C
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002D01D4
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002D00E4
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002D0120
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002D015C
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002D0198
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002D0030
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002D006C
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002D00A8
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002E00E4
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002E0120
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002E00A8
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002E0030
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[5144] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002E006C
.text C:\Program Files\internet explorer\iexplore.exe[5596] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10047D70 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[5596] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 10047CF0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[5596] ntdll.dll!NtDeleteKey 7C90D24E 5 Bytes JMP 10047D90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[5596] ntdll.dll!NtDeleteValueKey 7C90D26E 5 Bytes JMP 10047DB0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[5596] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10047D20 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[5596] ntdll.dll!NtQueryValueKey 7C90D96E 5 Bytes JMP 10047C90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[5596] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 10047CC0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[5596] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00D20780 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[5596] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0015006C
.text C:\Program Files\internet explorer\iexplore.exe[5596] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003E01D4
.text C:\Program Files\internet explorer\iexplore.exe[5596] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003E00E4
.text C:\Program Files\internet explorer\iexplore.exe[5596] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003E0120
.text C:\Program Files\internet explorer\iexplore.exe[5596] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003E015C
.text C:\Program Files\internet explorer\iexplore.exe[5596] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003E0198
.text C:\Program Files\internet explorer\iexplore.exe[5596] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003E0030
.text C:\Program Files\internet explorer\iexplore.exe[5596] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003E006C
.text C:\Program Files\internet explorer\iexplore.exe[5596] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003E00A8
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003F00E4
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB5C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003F0120
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003F00A8
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003F0030
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003F006C
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5117 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E5049 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E50B4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4F1A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4F7C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E517A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[5596] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4FDE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[5596] SHLWAPI.dll!SHCreateStreamOnFileA + 2066 77FC22BC 5 Bytes JMP 00D1C790 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\Program Files\internet explorer\iexplore.exe[5596] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00D22C50 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
Device \FileSystem\Ntfs \Ntfs 873D11E8

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

Device \FileSystem\Fastfat \FatCdrom 853D84D8

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\usbuhci \Device\USBPDO-0 871D47A0
Device \Driver\usbuhci \Device\USBPDO-1 871D47A0
Device \Driver\usbuhci \Device\USBPDO-2 871D47A0
Device \Driver\usbehci \Device\USBPDO-3 872161E8
Device \Driver\PCI_NTPNP2774 \Device\00000055 sptd.sys
Device \Driver\PCI_NTPNP2774 \Device\00000055 sptd.sys

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\Ftdisk \Device\HarddiskVolume1 873661E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 873661E8
Device \Driver\Cdrom \Device\CdRom0 871AB470
Device \Driver\atapi \Device\Ide\IdePort0 [F7357B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F7357B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F7357B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F7357B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 [F7357B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 [F7357B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Ftdisk \Device\HarddiskVolume3 873661E8
Device \Driver\Cdrom \Device\CdRom1 871AB470
Device \Driver\Cdrom \Device\CdRom2 871AB470
Device \Driver\USBSTOR \Device\00000076 86EE77A0
Device \Driver\NetBT \Device\NetBt_Wins_Export 871CE1E8
Device \Driver\USBSTOR \Device\00000078 86EE77A0
Device \Driver\NetBT \Device\NetbiosSmb 871CE1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{64A446F9-8064-4AB7-962B-1F0510437B72} 871CE1E8

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\usbuhci \Device\USBFDO-0 871D47A0
Device \Driver\usbuhci \Device\USBFDO-1 871D47A0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 86EFD528
Device \Driver\usbuhci \Device\USBFDO-2 871D47A0
Device \FileSystem\MRxSmb \Device\LanmanRedirector 86EFD528
Device \Driver\usbehci \Device\USBFDO-3 872161E8
Device \Driver\Ftdisk \Device\FtControl 873661E8
Device \Driver\apb4d5x9 \Device\Scsi\apb4d5x91Port2Path0Target0Lun0 871A27A0
Device \Driver\apb4d5x9 \Device\Scsi\apb4d5x91 871A27A0
Device \FileSystem\Fastfat \Fat 853D84D8

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

Device \FileSystem\Cdfs \Cdfs 86EE87A0

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x91 0xC8 0xF9 0xD4 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9A 0x10 0x16 0x5D …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xA4 0x82 0x9C 0xCE …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x04 0xDA 0x70 0x46 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x91 0xC8 0xF9 0xD4 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9A 0x10 0x16 0x5D …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xA4 0x82 0x9C 0xCE …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD4 0xBA 0x31 0x76 …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00081b868eb9 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00081b868eb9@0012472de4a3 0x6F 0xF8 0x5F 0xD3 …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00081b868eb9@0012472f9dfc 0x5E 0xA5 0x08 0x71 …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00081b868eb9@001813b95557 0xD5 0x43 0x45 0xEE …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00081b868eb9@00192ce9777e 0xF8 0x44 0x1A 0x91 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x91 0xC8 0xF9 0xD4 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9A 0x10 0x16 0x5D …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xA4 0x82 0x9C 0xCE …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x04 0xDA 0x70 0x46 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00081b868eb9
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00081b868eb9@0012472de4a3 0x6F 0xF8 0x5F 0xD3 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00081b868eb9@0012472f9dfc 0x5E 0xA5 0x08 0x71 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00081b868eb9@001813b95557 0xD5 0x43 0x45 0xEE …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00081b868eb9@00192ce9777e 0xF8 0x44 0x1A 0x91 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -717182018
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -556665947
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x91 0xC8 0xF9 0xD4 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9A 0x10 0x16 0x5D …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xA4 0x82 0x9C 0xCE …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x04 0xDA 0x70 0x46 …
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\00081b868eb9 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\00081b868eb9@0012472de4a3 0x6F 0xF8 0x5F 0xD3 …
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\00081b868eb9@0012472f9dfc 0x5E 0xA5 0x08 0x71 …
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\00081b868eb9@001813b95557 0xD5 0x43 0x45 0xEE …
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\00081b868eb9@00192ce9777e 0xF8 0x44 0x1A 0x91 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x91 0xC8 0xF9 0xD4 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9A 0x10 0x16 0x5D …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xA4 0x82 0x9C 0xCE …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x04 0xDA 0x70 0x46 …

—- EOF - GMER 1.0.15 —-
Hello,

Thank you for the log. :)

Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

    **********************************************
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here is the combofix log thanks…………………………..


ComboFix 11-04-30.05 - Lee Edgar 01/05/2011 12:17:40.4.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\What the Tech\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\directory\CyberGate
c:\documents and settings\All Users\Application Data\ResultBar
c:\documents and settings\All Users\Application Data\Yahoo!
c:\documents and settings\All Users\Application Data\Yahoo!\yau\yautoupdater_temp.xml
c:\documents and settings\Lee Edgar\Application Data\facemoods.com
c:\documents and settings\Lee Edgar\Application Data\Lee Edgarlog.dat
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\dailyhotdeals.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\divider.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\feeditem.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\games.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\savemp3.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\savemp3_disabled.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\screensaver.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\shopping.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\watermark.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\weatherbug.png
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\pref.xml
c:\documents and settings\Lee Edgar\Application Data\Mp3Tube Toolbar\tbconfig.xml
c:\documents and settings\Lee Edgar\Application Data\PriceGong
c:\documents and settings\Lee Edgar\Application Data\Yahoo!
c:\documents and settings\Lee Edgar\Application Data\Yahoo!\Companion\inq_data.inq
c:\documents and settings\Lee Edgar\Application Data\Yahoo!\Companion\inq_settings.xml
c:\documents and settings\Lee Edgar\Application Data\Yahoo!\Companion\resources.inq
c:\documents and settings\Lee Edgar\GoToAssistDownloadHelper.exe
c:\documents and settings\Lee Edgar\Recent\Thumbs.db
c:\documents and settings\Lee Edgar\System
c:\documents and settings\Lee Edgar\System\win_qs8.jqx
c:\documents and settings\Lee Edgar\WINDOWS
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\chrome\resultbar.jar
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\defaults\preferences\prefs.js
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\install.rdf
c:\program files\ResultBar
c:\program files\ResultBar\uninstall.exe
c:\windows\system32\Drivers\sptd.sys
c:\windows\system32\hkcmd.exe
c:\windows\system32\igfxtray.exe
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\XSxS
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_RESULTBAR_SERVICE
——-\Service_ResultBar Service
——-\Legacy_sptd
——-\Service_sptd
.
.
((((((((((((((((((((((((( Files Created from 2011-04-01 to 2011-05-01 )))))))))))))))))))))))))))))))
.
.
2011-05-01 11:43 . 2011-05-01 11:43 ——– d–h–r- c:\documents and settings\All Users\Application Data\yahoo!
2011-04-30 17:40 . 2011-04-30 17:43 ——– d—–w- C:\DunhelCache
2011-04-30 13:14 . 2011-04-30 13:15 ——– d—–w- C:\exorted_new_cache
2011-04-24 13:11 . 2011-04-24 13:11 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Ilivid Player
2011-04-24 13:09 . 2011-04-24 13:09 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{6A6F35C2-F1BB-455A-85C0-F522DF746DDA}
2011-04-24 13:09 . 2011-04-24 13:09 ——– d—–w- c:\program files\iLivid
2011-04-24 13:08 . 2011-04-24 13:09 ——– d—–w- c:\documents and settings\Lee Edgar\Application Data\searchqutoolbar
2011-04-24 13:08 . 2011-04-24 13:09 ——– d—–w- c:\program files\Windows iLivid Toolbar
2011-04-18 14:33 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-04-18 14:33 . 2011-03-18 17:57 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-04-18 14:33 . 2011-03-18 17:57 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-04-18 14:33 . 2011-03-18 17:57 728024 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-04-18 14:33 . 2011-03-18 17:57 1975768 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-04-18 14:33 . 2011-03-18 17:57 1893336 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-04-18 14:33 . 2011-03-18 17:57 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-04-18 14:33 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-04-14 02:39 . 2011-04-14 02:39 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-04-14 02:39 . 2011-04-14 02:39 103864 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2011-04-12 22:21 . 2011-04-12 22:21 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\MetaGeek,_LLC
2011-04-12 20:04 . 2010-09-13 02:58 49904 —-a-r- c:\windows\system32\drivers\BVRPMPR5.SYS
2011-04-12 19:59 . 2011-04-12 21:29 ——– d—–w- C:\Netgear
2011-04-12 11:23 . 2011-04-12 11:23 ——– d—–w- c:\documents and settings\Lee Edgar\Application Data\BabylonToolbar
2011-04-05 19:23 . 2011-04-05 19:23 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Yahoo
2011-04-05 19:22 . 2011-04-05 19:22 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\PackageAware
2011-04-05 19:21 . 2011-04-05 19:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2011-04-05 19:21 . 2011-04-05 19:22 ——– d—–w- c:\program files\Yahoo!
2011-04-04 10:20 . 2011-04-05 09:57 ——– d—–w- c:\documents and settings\Lee Edgar\.blurb
2011-04-04 10:18 . 2011-04-04 10:19 ——– d—–w- c:\program files\BookSmart
2011-04-02 11:33 . 2011-04-02 11:33 ——– d—–w- c:\program files\Wizard101(UK)
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-07 05:33 . 2004-06-07 13:19 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2002-08-29 05:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2002-08-29 05:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-28 17:45 . 2011-02-28 17:45 57845 —-a-w- c:\documents and settings\Lee Edgar\Application Data\Lee Edgar3SQLite3.dll
2011-02-23 15:04 . 2010-08-28 16:22 40648 —-a-w- c:\windows\avastSS.scr
2011-02-23 15:04 . 2009-09-10 18:38 190016 —-a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:56 . 2011-03-15 20:30 371544 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-02-23 14:56 . 2009-09-10 18:39 301528 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2009-09-10 18:39 49240 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2009-09-10 18:39 102232 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-23 14:55 . 2009-09-10 18:39 96344 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-23 14:55 . 2009-09-10 18:39 25432 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:54 . 2009-09-10 18:39 30680 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-23 14:54 . 2009-09-10 18:39 19544 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-22 23:06 . 2004-08-23 19:32 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2002-08-29 05:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2002-08-29 05:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-02-17 13:18 . 2002-08-29 05:00 455936 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2002-08-29 05:00 357888 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2009-04-16 02:41 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2002-08-29 05:00 290432 —-a-w- c:\windows\system32\atmfd.dll
2011-02-11 13:25 . 2004-03-02 22:17 229888 —-a-w- c:\windows\system32\fxscover.exe
2011-02-09 13:53 . 2002-08-29 05:00 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2002-08-29 05:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2002-08-29 05:00 978944 —-a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2002-08-29 05:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2011-02-02 21:40 . 2010-05-15 07:57 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-02 19:19 . 2011-02-24 19:14 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2002-08-29 05:00 2067456 —-a-w- c:\windows\system32\mstscax.dll
2006-07-11 20:05 . 2006-07-11 20:05 278528 —-a-w- c:\program files\Common Files\FDEUnInstaller.exe
2000-01-14 14:46 . 2006-09-07 20:58 24576 ——w- c:\program files\Common Files\XCPCMenu.exe
2000-01-14 14:46 . 2006-09-07 20:58 696320 ——w- c:\program files\Common Files\XCMHook.dll
2011-03-18 17:57 . 2011-04-18 14:33 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="\Program\" [X]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-14 1957888]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-04-29 2423752]
"Mega Manager"="c:\program files\Megaupload\Mega Manager\MegaManager.exe" [2010-11-03 2113024]
"PrinterShare"="c:\program files\PrinterShare\paConsole.exe" [2011-02-22 1107456]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"iKeyWorks"="c:\progra~1\A4Tech\Keyboard\Ikeymain.exe" [2004-08-31 61440]
"WheelMouse"="c:\progra~1\A4Tech\Mouse\Amoumain.exe" [2004-09-01 147456]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-13 198160]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2010-03-18 614400]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\Lee Edgar\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2010-8-4 303104]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-6-11 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-6-11 813584]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 12:28 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe"
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Orange\\Livebox\\RGWREPAIR.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\PrinterShare\\paConsole.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Windows iLivid Toolbar\\ToolBar\\dtUser.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16193:TCP"= 16193:TCP:BitComet 16193 TCP
"16193:UDP"= 16193:UDP:BitComet 16193 UDP
"55064:TCP"= 55064:TCP:bitcomet 55064 tcp
"55064:UDP"= 55064:UDP:bitcomet 55064 udp
.
R2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\Drivers\Ca533av.sys [x]
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\DRIVERS\Amps2prt.sys [2004-08-25 9984]
R3 BTCOMM;BTCOMM;c:\windows\system32\drivers\Btcomm.sys [x]
R3 BTKRNBDG;Bluetooth COM Bridge;c:\windows\system32\DRIVERS\btkrnbdg.sys [x]
R3 CSRBC01;%CSRBC01.SvcDesc%;c:\windows\system32\Drivers\csrbc01.sys [x]
R3 DLPortIO;DriverLINX Port I/O Driver;c:\windows\system32\DRIVERS\DLPortIO.SYS [2000-06-29 3584]
R3 MTK;Media Technology Kernel Driver;c:\windows\system32\Drivers\mtk.sys [x]
R3 SecureSrv;SecureSrv; [x]
R3 vad_multi;Windigo Virtual Audio Device (WDM);c:\windows\system32\drivers\vadmulti.sys [x]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2006-08-10 223128]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 aswFsBlk;aswFsBlk; [x]
S2 pdfFactory Pro Dispatcher v3;pdfFactory Pro Dispatcher v3;c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe [2010-03-18 614400]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - SASDIFSV
*Deregistered* - uphcleanhlp
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-29 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 21:51]
.
2011-04-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
2011-05-01 c:\windows\Tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
Trusted Zone: securesuite.co.uk\www
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://secure.footprint.net/kingsisle/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
FF - ProfilePath - c:\documents and settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406
FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&systemid=406&q=
FF - user.js: keyword.URL - hxxp://mp3tubetoolbarsearch.com/?prt=pinballtb02ff&Keywords=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-IgfxTray - c:\windows\system32\igfxtray.exe
HKLM-Run-HotKeysCmds - c:\windows\system32\hkcmd.exe
Notify-avgrsstarter - avgrsstx.dll
SafeBoot-Wdf01000.sys
MSConfigStartUp-FBSearch - c:\program files\Search Guard Plus\SearchGuardPlus.exe
HKLM_ActiveSetup-{CD1EAB0A-31BE-D4B7-BBFC-E9AE92DEBAFC} - c:\documents and settings\Lee Edgar\Application Data\winup.exe
HKCU_ActiveSetup-{CD1EAB0A-31BE-D4B7-BBFC-E9AE92DEBAFC} - c:\documents and settings\Lee Edgar\Application Data\winup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-01 12:46
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-10512063-1881097818-1119676352-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2a,d9,db,11,cc,c7,6e,95,52,b5,58,cb,a0,cf,e4,ad,27,de,53,33,93,32,9f,
ab,3a,83,12,94,c7,4b,50,8d,67,ec,61,46,52,f3,d8,a0,97,05,fc,c5,b7,1e,48,5d,\
"??"=hex:56,52,75,73,36,e9,4b,67,3c,6b,47,2a,09,08,ac,8b
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(664)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(7100)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\UPHClean\uphclean.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\windows\BCMSMMSG.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\progra~1\WI371A~1\Datamngr\DATAMN~1.EXE
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2011-05-01 13:01:26 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-01 12:01
.
Pre-Run: 28,047,446,016 bytes free
Post-Run: 28,635,561,984 bytes free
.
Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 727A1E213BDB032D1C5E94E9B68BD410
Hello again.

I need you to post a log in your next reply which can be found in C:\Qoobox\ComboFix-quarantined-files.txt

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan


click on Browse, and upload the following file for analysis:
c:\program files\Common Files\FDEUnInstaller.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results link(for Virus Total) here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

===================================================

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DirLook::
C:\DunhelCache
C:\exorted_new_cache

Folder::
c:\documents and settings\Lee Edgar\Application Data\searchqutoolbar

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"=-

Firefox::
FF - ProfilePath - c:\documents and settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\
FF - prefs.js: browser.search.selectedEngine - 
FF - prefs.js: browser.startup.homepage - 
FF - prefs.js: keyword.URL -
FF - user.js: keyword.URL -


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

===================================================

On your next reply please post :
Quarantined files log
File scanner report
Combofix log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Conspire, Thanks for sticking with me !

here are the logs/reports


QUARANTINED FILES LOG

2011-05-01 15:21:33 . 2011-05-01 15:21:33 0 —-a-w- C:\Qoobox\Quarantine\catchme.txt
2011-05-01 11:59:48 . 2011-05-01 11:59:48 208 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU_ActiveSetup-{CD1EAB0A-31BE-D4B7-BBFC-E9AE92DEBAFC}.reg.dat
2011-05-01 11:59:47 . 2011-05-01 11:59:47 209 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM_ActiveSetup-{CD1EAB0A-31BE-D4B7-BBFC-E9AE92DEBAFC}.reg.dat
2011-05-01 11:59:34 . 2011-05-01 11:59:34 630 —-a-w- C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-FBSearch.reg.dat
2011-05-01 11:59:32 . 2011-05-01 11:59:32 558 —-a-w- C:\Qoobox\Quarantine\Registry_backups\SafeBoot-Wdf01000.sys.reg.dat
2011-05-01 11:59:23 . 2011-05-01 11:59:23 378 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Notify-avgrsstarter.reg.dat
2011-05-01 11:58:52 . 2011-05-01 11:58:52 134 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-HotKeysCmds.reg.dat
2011-05-01 11:58:52 . 2011-05-01 11:58:52 134 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-IgfxTray.reg.dat
2011-05-01 11:58:43 . 2011-05-01 11:58:43 171 —-a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847}.reg.dat
2011-05-01 11:58:42 . 2011-05-01 11:58:42 171 —-a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829}.reg.dat
2011-05-01 11:58:40 . 2011-05-01 11:58:40 159 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-10.reg.dat
2011-05-01 11:58:39 . 2011-05-01 11:58:39 173 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-Locked.reg.dat
2011-05-01 11:58:38 . 2011-05-01 11:58:38 213 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829}.reg.dat
2011-05-01 11:58:33 . 2011-05-01 11:58:34 1,825 —-a-w- C:\Qoobox\Quarantine\Registry_backups\URLSearchHooks-{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}.reg.dat
2011-05-01 11:49:24 . 2011-05-01 11:49:24 54,016 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\temp\logishrd\_LVPrcInj01_.dll.zip
2011-05-01 11:34:32 . 2011-05-01 11:34:32 2,382 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_sptd.reg.dat
2011-05-01 11:34:32 . 2011-05-01 11:34:32 1,334 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_sptd.reg.dat
2011-05-01 11:32:10 . 2011-05-01 11:32:10 4,140 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_ResultBar Service.reg.dat
2011-05-01 11:32:09 . 2011-05-01 11:32:09 878 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_RESULTBAR_SERVICE.reg.dat
2011-05-01 11:31:24 . 2011-05-01 15:35:29 17,916 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2011-05-01 11:12:25 . 2011-05-01 15:16:29 288 —-a-w- C:\Qoobox\Quarantine\catchme.log
2011-04-29 13:11:52 . 2008-12-16 20:59:28 109,080 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\temp\logishrd\LVPrcInj01.dll.vir
2011-04-24 13:09:16 . 2011-04-24 13:09:16 266 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\searchqutoolbar\setupCfg.xml.vir
2011-04-24 13:09:00 . 2011-04-24 13:09:00 15 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\searchqutoolbar\dtx.ini.vir
2011-04-24 13:08:51 . 2011-04-24 13:08:51 38 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\searchqutoolbar\guid.dat.vir
2011-04-05 19:24:52 . 2011-04-05 19:25:01 340 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Yahoo!\Companion\inq_data.inq.vir
2011-04-05 19:24:47 . 2011-04-05 19:25:01 3,607 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Yahoo!\Companion\inq_settings.xml.vir
2011-04-05 19:24:46 . 2011-04-05 19:25:00 12,816 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Yahoo!\Companion\resources.inq.vir
2011-04-05 19:22:27 . 2011-05-01 05:56:44 1,502 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Yahoo!\yau\yautoupdater_temp.xml.vir
2010-12-22 05:17:45 . 2010-12-22 02:25:20 84,896 —-a-w- C:\Qoobox\Quarantine\C\Program Files\ResultBar\uninstall.exe.vir
2010-12-14 13:30:39 . 2010-12-22 05:17:45 94 —-a-w- C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\defaults\preferences\prefs.js.vir
2010-12-14 13:30:39 . 2010-12-10 10:50:16 5,343 —-a-w- C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\chrome\resultbar.jar.vir
2010-12-14 13:30:39 . 2010-12-10 10:50:14 302 —-a-w- C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\chrome.manifest.vir
2010-12-14 13:30:39 . 2010-12-10 10:50:14 1,105 —-a-w- C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\install.rdf.vir
2010-12-14 12:33:45 . 2010-12-14 12:38:18 97 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\pref.xml.vir
2010-12-14 12:27:49 . 2010-12-14 12:27:49 1,344 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\weatherbug.png.vir
2010-12-14 12:27:49 . 2010-12-14 12:27:49 1,004 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\feeditem.png.vir
2010-12-14 12:27:49 . 2010-12-14 12:27:49 929 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\divider.png.vir
2010-12-14 12:27:48 . 2010-12-14 12:27:48 5,301 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\watermark.png.vir
2010-12-14 12:27:48 . 2010-12-14 12:27:48 775 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\screensaver.png.vir
2010-12-14 12:27:48 . 2010-12-14 12:27:48 965 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\dailyhotdeals.png.vir
2010-12-14 12:27:48 . 2010-12-14 12:27:48 802 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\shopping.png.vir
2010-12-14 12:27:47 . 2010-12-14 12:27:47 695 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\games.png.vir
2010-12-14 12:27:47 . 2010-12-14 12:27:47 549 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\savemp3_disabled.png.vir
2010-12-14 12:27:47 . 2010-12-14 12:27:47 1,394 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\images\savemp3.png.vir
2010-12-14 12:27:46 . 2010-12-14 12:27:46 3,591 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Mp3Tube Toolbar\tbconfig.xml.vir
2010-11-22 12:52:32 . 2010-11-22 12:52:49 145,408 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Recent\Thumbs.db.vir
2010-02-08 15:12:09 . 2010-02-08 15:12:10 103,720 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\GoToAssistDownloadHelper.exe.vir
2008-11-06 22:07:23 . 2010-09-26 08:58:19 99 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\System\win_qs8.jqx.vir
2006-08-10 22:09:16 . 2007-06-16 09:45:51 682,232 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\sptd.sys.vir
2005-04-08 02:16:43 . 2011-03-08 10:45:32 92,349 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Lee Edgar\Application Data\Lee Edgarlog.dat.vir
1980-01-01 00:00:00 . 2005-10-19 07:59:12 126,976 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\hkcmd.exe.vir
1980-01-01 00:00:00 . 2005-10-19 07:59:14 155,648 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\igfxtray.exe.vir


FILE SCANNER REPORT

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: FDEUnInstaller.exe
Submission date: 2011-05-01 15:08:37 (UTC)
Current status: queued queued analysing finished


Result: 1/ 41 (2.4%)
VT Community

not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.05.01.00 2011.04.30 -
AntiVir 7.11.7.93 2011.05.01 -
Antiy-AVL 2.0.3.7 2011.05.01 -
Avast 4.8.1351.0 2011.05.01 -
Avast5 5.0.677.0 2011.05.01 -
AVG 10.0.0.1190 2011.05.01 -
BitDefender 7.2 2011.05.01 -
CAT-QuickHeal 11.00 2011.04.30 -
ClamAV 0.97.0.0 2011.05.01 -
Commtouch 5.3.2.6 2011.05.01 -
Comodo 8542 2011.05.01 -
DrWeb 5.0.2.03300 2011.05.01 -
eSafe 7.0.17.0 2011.04.28 -
eTrust-Vet 36.1.8299 2011.04.29 -
F-Prot 4.6.2.117 2011.05.01 -
F-Secure 9.0.16440.0 2011.05.01 -
Fortinet 4.2.257.0 2011.05.01 -
GData 22 2011.05.01 -
Ikarus T3.1.1.103.0 2011.05.01 -
Jiangmin 13.0.900 2011.04.30 -
K7AntiVirus 9.98.4527 2011.04.30 -
Kaspersky 9.0.0.837 2011.05.01 -
McAfee 5.400.0.1158 2011.05.01 -
McAfee-GW-Edition 2010.1D 2011.04.30 -
Microsoft 1.6802 2011.05.01 -
NOD32 6085 2011.05.01 -
Norman 6.07.07 2011.05.01 -
Panda 10.0.3.5 2011.05.01 -
PCTools 7.0.3.5 2011.04.29 -
Prevx 3.0 2011.05.01 -
Rising 23.55.04.03 2011.04.29 -
Sophos 4.64.0 2011.05.01 -
SUPERAntiSpyware 4.40.0.1006 2011.05.01 -
Symantec 20101.3.2.89 2011.05.01 WS.Reputation.1
TheHacker 6.7.0.1.184 2011.04.30 -
TrendMicro 9.200.0.1012 2011.05.01 -
TrendMicro-HouseCall 9.200.0.1012 2011.05.01 -
VBA32 3.12.16.0 2011.04.29 -
VIPRE 9168 2011.05.01 -
ViRobot 2011.4.30.4439 2011.05.01 -
VirusBuster 13.6.329.0 2011.04.30 -
Additional informationShow all
MD5 : 9ccdbc6c324cbbacd2f395004e653018
SHA1 : 5cc75dcc90405dcc5e84d35c84948b1da7271c3a
SHA256: c76bedeadeaa070880c101764dfb6d58b44b5816953ccb7cc114d17f842424de
ssdeep: 3072:Pfm8Jg2pJKVMsEzotgYAz5eI8nXmd5JPl2NqvzOqFnef5YZBZG/1UlLVgGZDUK9T:Pfm8J
9WhW5Z8Xmd5yqFJuCVgGZDUK
File size : 278528 bytes
First seen: 2009-02-24 20:05:18
Last seen : 2011-05-01 15:08:37
TrID:
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher….:
copyright….:
product……: FDEUninstaller
description..: FDEUninstaller
original name: FDEUninstaller
internal name: FDEUninstaller
file version.: 1, 0, 0, 1
comments…..:
signers……: -
signing date.: -
verified…..: Unsigned

PEiD: Armadillo v1.71
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x1449C
timedatestamp….: 0x4200A64C (Wed Feb 02 10:07:08 2005)
machinetype……: 0x14c (I386)

[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x30036, 0x31000, 6.42, 5b9a639391f978905697ea4d7d461c8c
.rdata, 0x32000, 0x85D6, 0x9000, 4.41, 9d7aa5df25265fe5ef2bf0f5c69c2001
.data, 0x3B000, 0x8DE8, 0x5000, 3.03, 986cfc2f6684fe011a4ca2c7d2ca9325
.rsrc, 0x44000, 0x3410, 0x4000, 3.37, e35aa82c8a7c0509031dc2751f9a1c0e

[[ 8 import(s) ]]
KERNEL32.dll: GetCPInfo, GetOEMCP, WritePrivateProfileStringA, SetErrorMode, RtlUnwind, ExitProcess, TerminateProcess, GetTimeZoneInformation, GetSystemTime, GetLocalTime, GetStartupInfoA, GetCommandLineA, SetStdHandle, GetFileType, GetACP, HeapAlloc, HeapFree, RaiseException, HeapReAlloc, HeapSize, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetProcessVersion, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetEnvironmentVariableA, HeapDestroy, HeapCreate, VirtualFree, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, VirtualAlloc, IsBadWritePtr, SetUnhandledExceptionFilter, IsBadReadPtr, IsBadCodePtr, CompareStringA, CompareStringW, SetEnvironmentVariableA, GlobalFlags, MulDiv, GetProfileStringA, GetFileTime, GetFileSize, TlsGetValue, LocalReAlloc, TlsSetValue, GlobalReAlloc, TlsFree, GlobalHandle, TlsAlloc, LocalAlloc, GetFullPathNameA, GetVolumeInformationA, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, DuplicateHandle, lstrcmpA, GetCurrentThread, LoadLibraryA, FreeLibrary, GetVersion, lstrcatA, GetCurrentThreadId, GlobalGetAtomNameA, lstrcmpiA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, lstrcpyA, GetModuleHandleA, GetProcAddress, GlobalLock, GlobalUnlock, WaitForSingleObject, lstrcpynA, SetLastError, GlobalFree, FileTimeToLocalFileTime, FileTimeToSystemTime, LocalFree, MultiByteToWideChar, InterlockedDecrement, InterlockedIncrement, SetThreadPriority, FindResourceExA, WideCharToMultiByte, FindFirstFileA, FindNextFileA, FindClose, GetVersionExA, GetCurrentProcess, Sleep, GetTickCount, CreateProcessA, GetExitCodeProcess, GetModuleFileNameA, lstrlenA, WinExec, CopyFileA, FindResourceA, SizeofResource, LoadResource, LockResource, CreateFileA, GetFileInformationByHandle, CloseHandle, GetFileAttributesA, GetWindowsDirectoryA, GetTempPathA, FormatMessageA, RemoveDirectoryA, GetLastError, ExpandEnvironmentStringsA, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, GetSystemDefaultLangID, GetUserDefaultLangID, DeleteFileA, CreateDirectoryA, GlobalAlloc, GetEnvironmentStrings
USER32.dll: SetCursor, GetCursorPos, ValidateRect, GetMessageA, CharUpperA, ClientToScreen, GetWindowDC, BeginPaint, EndPaint, TabbedTextOutA, DrawTextA, GrayStringA, GetClassNameA, PtInRect, LoadCursorA, GetSysColorBrush, DestroyMenu, InflateRect, InvalidateRect, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, CheckMenuItem, EnableMenuItem, ShowWindow, SetWindowTextA, IsDialogMessageA, LoadIconA, PostMessageA, UpdateWindow, SendDlgItemMessageA, MapWindowPoints, GetSysColor, GetFocus, SetFocus, AdjustWindowRectEx, ScreenToClient, GetClientRect, CopyRect, IsWindowVisible, GetTopWindow, GetCapture, WinHelpA, RegisterClassA, GetMenu, GetMenuItemCount, GetSubMenu, GetMenuItemID, GetWindowTextLengthA, GetWindowTextA, GetDlgCtrlID, GetKeyState, CreateWindowExA, SetWindowsHookExA, CallNextHookEx, GetClassLongA, SetPropA, GetPropA, CallWindowProcA, RemovePropA, DefWindowProcA, GetMessageTime, GetMessagePos, GetLastActivePopup, GetForegroundWindow, SetForegroundWindow, GetWindow, SetWindowLongA, SetWindowPos, RegisterWindowMessageA, OffsetRect, DispatchMessageA, TranslateMessage, PeekMessageA, UnregisterClassA, HideCaret, ShowCaret, ExcludeUpdateRgn, DrawFocusRect, IntersectRect, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, GetNextDlgTabItem, EndDialog, GetActiveWindow, SetActiveWindow, IsWindow, GetSystemMetrics, CreateDialogIndirectParamA, DestroyWindow, GetParent, GetWindowLongA, GetDlgItem, PostQuitMessage, LoadStringA, GetDC, ReleaseDC, GetMenuCheckMarkDimensions, LoadBitmapA, IsWindowEnabled, UnhookWindowsHookEx, wsprintfA, ExitWindowsEx, keybd_event, MessageBoxA, SendMessageA, EnableWindow, IsWindowUnicode, CharNextA, DefDlgProcA, GetClassInfoA
GDI32.dll: SetWindowExtEx, ScaleWindowExtEx, IntersectClipRect, DeleteObject, GetDeviceCaps, CreateSolidBrush, PtVisible, RectVisible, TextOutA, ExtTextOutA, Escape, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SetMapMode, SetBkMode, GetStockObject, SelectObject, RestoreDC, SaveDC, DeleteDC, PatBlt, CreateBitmap, GetObjectA, SetBkColor, SetTextColor, GetClipBox, CreateDIBitmap, GetTextExtentPointA, BitBlt, CreateCompatibleDC
comdlg32.dll: GetOpenFileNameA, GetSaveFileNameA, GetFileTitleA
WINSPOOL.DRV: OpenPrinterA, DocumentPropertiesA, ClosePrinter
ADVAPI32.dll: LookupPrivilegeValueA, RegDeleteKeyA, RegDeleteValueA, RegOpenKeyExA, RegCloseKey, RegSetValueExA, RegQueryValueExA, RegOpenKeyA, RegEnumKeyExA, RegCreateKeyExA, OpenProcessToken, RegCreateKeyA, AdjustTokenPrivileges, RegQueryInfoKeyA, RegEnumValueA
SHELL32.dll: SHGetSpecialFolderPathA, SHBrowseForFolderA, SHGetPathFromIDListA
COMCTL32.dll: -

ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 200704
Comments:
CompanyName:
EntryPoint: 0x1449c
FileDescription: FDEUninstaller
FileFlagsMask: 0x003f
FileOS: Win32
FileSize: 272 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 1, 0, 0, 1
FileVersionNumber: 1.0.0.1
ImageVersion: 0.0
InitializedDataSize: 90112
InternalName: FDEUninstaller
LanguageCode: French
LegalCopyright:
LegalTrademarks:
LinkerVersion: 6.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
ObjectFileType: Executable application
OriginalFilename: FDEUninstaller
PEType: PE32
PrivateBuild:
ProductName: FDEUninstaller
ProductVersion: 1, 0, 0, 1
ProductVersionNumber: 1.0.0.1
SpecialBuild:
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2005:02:02 11:07:08+01:00
UninitializedDataSize: 0



VT Community


COMBOFIX LOG



ComboFix 11-04-30.05 - Lee Edgar 01/05/2011 16:22:12.5.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\What the Tech\ComboFix.exe
Command switches used :: c:\documents and settings\Lee Edgar\Desktop\What the Tech\CFscript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Yahoo!
c:\documents and settings\Lee Edgar\Application Data\searchqutoolbar
c:\documents and settings\Lee Edgar\Application Data\searchqutoolbar\dtx.ini
c:\documents and settings\Lee Edgar\Application Data\searchqutoolbar\guid.dat
c:\documents and settings\Lee Edgar\Application Data\searchqutoolbar\setupCfg.xml
.
.
((((((((((((((((((((((((( Files Created from 2011-04-01 to 2011-05-01 )))))))))))))))))))))))))))))))
.
.
2011-04-30 17:40 . 2011-04-30 17:43 ——– d—–w- C:\DunhelCache
2011-04-30 13:14 . 2011-04-30 13:15 ——– d—–w- C:\exorted_new_cache
2011-04-24 13:11 . 2011-04-24 13:11 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Ilivid Player
2011-04-24 13:09 . 2011-04-24 13:09 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{6A6F35C2-F1BB-455A-85C0-F522DF746DDA}
2011-04-24 13:09 . 2011-04-24 13:09 ——– d—–w- c:\program files\iLivid
2011-04-24 13:08 . 2011-04-24 13:09 ——– d—–w- c:\program files\Windows iLivid Toolbar
2011-04-18 14:33 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-04-18 14:33 . 2011-03-18 17:57 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-04-18 14:33 . 2011-03-18 17:57 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-04-18 14:33 . 2011-03-18 17:57 728024 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-04-18 14:33 . 2011-03-18 17:57 1975768 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-04-18 14:33 . 2011-03-18 17:57 1893336 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-04-18 14:33 . 2011-03-18 17:57 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-04-18 14:33 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-04-14 02:39 . 2011-04-14 02:39 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-04-14 02:39 . 2011-04-14 02:39 103864 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2011-04-12 22:21 . 2011-04-12 22:21 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\MetaGeek,_LLC
2011-04-12 20:04 . 2010-09-13 02:58 49904 —-a-r- c:\windows\system32\drivers\BVRPMPR5.SYS
2011-04-12 19:59 . 2011-04-12 21:29 ——– d—–w- C:\Netgear
2011-04-12 11:23 . 2011-04-12 11:23 ——– d—–w- c:\documents and settings\Lee Edgar\Application Data\BabylonToolbar
2011-04-05 19:23 . 2011-04-05 19:23 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Yahoo
2011-04-05 19:22 . 2011-04-05 19:22 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\PackageAware
2011-04-05 19:21 . 2011-04-05 19:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2011-04-05 19:21 . 2011-04-05 19:22 ——– d—–w- c:\program files\Yahoo!
2011-04-04 10:20 . 2011-04-05 09:57 ——– d—–w- c:\documents and settings\Lee Edgar\.blurb
2011-04-04 10:18 . 2011-04-04 10:19 ——– d—–w- c:\program files\BookSmart
2011-04-02 11:33 . 2011-04-02 11:33 ——– d—–w- c:\program files\Wizard101(UK)
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-07 05:33 . 2004-06-07 13:19 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2002-08-29 05:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2002-08-29 05:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-28 17:45 . 2011-02-28 17:45 57845 —-a-w- c:\documents and settings\Lee Edgar\Application Data\Lee Edgar3SQLite3.dll
2011-02-23 15:04 . 2010-08-28 16:22 40648 —-a-w- c:\windows\avastSS.scr
2011-02-23 15:04 . 2009-09-10 18:38 190016 —-a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:56 . 2011-03-15 20:30 371544 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-02-23 14:56 . 2009-09-10 18:39 301528 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2009-09-10 18:39 49240 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2009-09-10 18:39 102232 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-23 14:55 . 2009-09-10 18:39 96344 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-23 14:55 . 2009-09-10 18:39 25432 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:54 . 2009-09-10 18:39 30680 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-23 14:54 . 2009-09-10 18:39 19544 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-22 23:06 . 2004-08-23 19:32 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2002-08-29 05:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2002-08-29 05:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-02-17 13:18 . 2002-08-29 05:00 455936 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2002-08-29 05:00 357888 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2009-04-16 02:41 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2002-08-29 05:00 290432 —-a-w- c:\windows\system32\atmfd.dll
2011-02-11 13:25 . 2004-03-02 22:17 229888 —-a-w- c:\windows\system32\fxscover.exe
2011-02-09 13:53 . 2002-08-29 05:00 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2002-08-29 05:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2002-08-29 05:00 978944 —-a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2002-08-29 05:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2011-02-02 21:40 . 2010-05-15 07:57 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-02 19:19 . 2011-02-24 19:14 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2002-08-29 05:00 2067456 —-a-w- c:\windows\system32\mstscax.dll
2006-07-11 20:05 . 2006-07-11 20:05 278528 —-a-w- c:\program files\Common Files\FDEUnInstaller.exe
2000-01-14 14:46 . 2006-09-07 20:58 24576 ——w- c:\program files\Common Files\XCPCMenu.exe
2000-01-14 14:46 . 2006-09-07 20:58 696320 ——w- c:\program files\Common Files\XCMHook.dll
2011-03-18 17:57 . 2011-04-18 14:33 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\DunhelCache —-
.
2011-04-30 17:43 . 2011-04-30 17:43 17684 —-a-w- c:\dunhelcache\sound3.wav
2011-04-30 17:43 . 2011-04-30 17:43 22094 —-a-w- c:\dunhelcache\sound2.wav
2011-04-30 17:43 . 2011-05-01 09:02 17684 —-a-w- c:\dunhelcache\sound1.wav
2011-04-30 17:43 . 2011-04-30 17:43 17836 —-a-w- c:\dunhelcache\shared_game_unpacker.dat
2011-04-30 17:43 . 2011-04-30 17:43 7706 —-a-w- c:\dunhelcache\npc.idx
2011-04-30 17:43 . 2011-04-30 17:43 356796 —-a-w- c:\dunhelcache\npc.dat
2011-04-30 17:43 . 2011-04-30 17:43 4852 —-a-w- c:\dunhelcache\models.idx
2011-04-30 17:43 . 2011-04-30 17:43 1265413 —-a-w- c:\dunhelcache\models.dat
2011-04-30 17:43 . 2011-05-01 09:02 61436 —-a-w- c:\dunhelcache\jingle1.mid
2011-04-30 17:43 . 2011-04-30 17:43 0 —-a-w- c:\dunhelcache\cacheVersion1.dat
2011-04-30 17:43 . 2011-04-30 17:43 421376 —-a-w- c:\dunhelcache\Sprites\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 42891 —-a-w- c:\dunhelcache\Sprites\tabarea.png
2011-04-30 17:43 . 2011-04-30 17:43 4584 —-a-w- c:\dunhelcache\Sprites\runorb.png
2011-04-30 17:43 . 2011-04-30 17:43 815 —-a-w- c:\dunhelcache\Sprites\REDSTONES 4.png
2011-04-30 17:43 . 2011-04-30 17:43 4684 —-a-w- c:\dunhelcache\Sprites\runclick.png
2011-04-30 17:43 . 2011-04-30 17:43 882 —-a-w- c:\dunhelcache\Sprites\REDSTONES 3.png
2011-04-30 17:43 . 2011-04-30 17:43 845 —-a-w- c:\dunhelcache\Sprites\REDSTONES 1.png
2011-04-30 17:43 . 2011-04-30 17:43 786 —-a-w- c:\dunhelcache\Sprites\REDSTONES 2.png
2011-04-30 17:43 . 2011-04-30 17:43 874 —-a-w- c:\dunhelcache\Sprites\REDSTONES 0.png
2011-04-30 17:43 . 2011-04-30 17:43 505 —-a-w- c:\dunhelcache\Sprites\prayerfill.PNG
2011-04-30 17:43 . 2011-04-30 17:43 464 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYON 7.PNG
2011-04-30 17:43 . 2011-04-30 17:43 34304 —-a-w- c:\dunhelcache\Sprites\Prayer\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 478 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYON 6.PNG
2011-04-30 17:43 . 2011-04-30 17:43 483 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYON 5.PNG
2011-04-30 17:43 . 2011-04-30 17:43 460 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYON 3.PNG
2011-04-30 17:43 . 2011-04-30 17:43 523 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYON 4.PNG
2011-04-30 17:43 . 2011-04-30 17:43 496 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYON 2.PNG
2011-04-30 17:43 . 2011-04-30 17:43 458 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYON 1.PNG
2011-04-30 17:43 . 2011-04-30 17:43 489 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYON 0.PNG
2011-04-30 17:43 . 2011-04-30 17:43 461 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYOFF 7.PNG
2011-04-30 17:43 . 2011-04-30 17:43 429 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYOFF 6.PNG
2011-04-30 17:43 . 2011-04-30 17:43 476 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYOFF 5.PNG
2011-04-30 17:43 . 2011-04-30 17:43 460 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYOFF 3.PNG
2011-04-30 17:43 . 2011-04-30 17:43 499 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYOFF 4.PNG
2011-04-30 17:43 . 2011-04-30 17:43 463 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYOFF 2.PNG
2011-04-30 17:43 . 2011-04-30 17:43 474 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYOFF 0.PNG
2011-04-30 17:43 . 2011-04-30 17:43 461 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYOFF 1.PNG
2011-04-30 17:43 . 2011-04-30 17:43 408 —-a-w- c:\dunhelcache\Sprites\Prayer\PRAYER 0.PNG
2011-04-30 17:43 . 2011-04-30 17:43 375 —-a-w- c:\dunhelcache\Sprites\Pest Control\PEST1 5.PNG
2011-04-30 17:43 . 2011-04-30 17:43 16384 —-a-w- c:\dunhelcache\Sprites\Pest Control\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 409 —-a-w- c:\dunhelcache\Sprites\Pest Control\PEST1 4.PNG
2011-04-30 17:43 . 2011-04-30 17:43 484 —-a-w- c:\dunhelcache\Sprites\Pest Control\PEST1 3.PNG
2011-04-30 17:43 . 2011-04-30 17:43 666 —-a-w- c:\dunhelcache\Sprites\Pest Control\PEST1 1.PNG
2011-04-30 17:43 . 2011-04-30 17:43 485 —-a-w- c:\dunhelcache\Sprites\Pest Control\PEST1 2.PNG
2011-04-30 17:43 . 2011-04-30 17:43 794 —-a-w- c:\dunhelcache\Sprites\Pest Control\PEST1 0.PNG
2011-04-30 17:43 . 2011-04-30 17:43 6656 —-a-w- c:\dunhelcache\Sprites\Other\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 138 —-a-w- c:\dunhelcache\Sprites\Other\infinity.png
2011-04-30 17:43 . 2011-04-30 17:43 935 —-a-w- c:\dunhelcache\Sprites\orbT.png
2011-04-30 17:43 . 2011-04-30 17:43 46080 —-a-w- c:\dunhelcache\Sprites\Options\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 503 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 36.PNG
2011-04-30 17:43 . 2011-04-30 17:43 610 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 9.PNG
2011-04-30 17:43 . 2011-04-30 17:43 923 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 35.PNG
2011-04-30 17:43 . 2011-04-30 17:43 571 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 33.PNG
2011-04-30 17:43 . 2011-04-30 17:43 533 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 34.PNG
2011-04-30 17:43 . 2011-04-30 17:43 571 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 32.PNG
2011-04-30 17:43 . 2011-04-30 17:43 686 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 30.PNG
2011-04-30 17:43 . 2011-04-30 17:43 687 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 31.PNG
2011-04-30 17:43 . 2011-04-30 17:43 735 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 29.PNG
2011-04-30 17:43 . 2011-04-30 17:43 626 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 28.PNG
2011-04-30 17:43 . 2011-04-30 17:43 659 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 27.PNG
2011-04-30 17:43 . 2011-04-30 17:43 677 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 26.PNG
2011-04-30 17:43 . 2011-04-30 17:43 669 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 25.PNG
2011-04-30 17:43 . 2011-04-30 17:43 694 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 24.PNG
2011-04-30 17:43 . 2011-04-30 17:43 479 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 23.PNG
2011-04-30 17:43 . 2011-04-30 17:43 466 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 21.PNG
2011-04-30 17:43 . 2011-04-30 17:43 450 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 22.PNG
2011-04-30 17:43 . 2011-04-30 17:43 524 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 19.PNG
2011-04-30 17:43 . 2011-04-30 17:43 453 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 20.PNG
2011-04-30 17:43 . 2011-04-30 17:43 720 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 18.PNG
2011-04-30 17:43 . 2011-04-30 17:43 716 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 16.PNG
2011-04-30 17:43 . 2011-04-30 17:43 746 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 17.PNG
2011-04-30 17:43 . 2011-04-30 17:43 714 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 15.PNG
2011-04-30 17:43 . 2011-04-30 17:43 838 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 14.PNG
2011-04-30 17:43 . 2011-04-30 17:43 602 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 13.PNG
2011-04-30 17:43 . 2011-04-30 17:43 500 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 11.PNG
2011-04-30 17:43 . 2011-04-30 17:43 567 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 12.PNG
2011-04-30 17:43 . 2011-04-30 17:43 640 —-a-w- c:\dunhelcache\Sprites\Options\SPRITE 10.PNG
2011-04-30 17:43 . 2011-04-30 17:43 15464 —-a-w- c:\dunhelcache\Sprites\maparea.png
2011-04-30 17:43 . 2011-04-30 17:43 7680 —-a-w- c:\dunhelcache\Sprites\Magic\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 343 —-a-w- c:\dunhelcache\Sprites\Magic\Home 1.png
2011-04-30 17:43 . 2011-04-30 17:43 152064 —-a-w- c:\dunhelcache\Sprites\Lunar\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 341 —-a-w- c:\dunhelcache\Sprites\Lunar\SPRITE 1.PNG
2011-04-30 17:43 . 2011-04-30 17:43 6374 —-a-w- c:\dunhelcache\Sprites\Lunar\SPRITE 0.PNG
2011-04-30 17:43 . 2011-04-30 17:43 914 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 9.png
2011-04-30 17:43 . 2011-04-30 17:43 921 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 8.png
2011-04-30 17:43 . 2011-04-30 17:43 904 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 7.png
2011-04-30 17:43 . 2011-04-30 17:43 931 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 5.png
2011-04-30 17:43 . 2011-04-30 17:43 934 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 6.png
2011-04-30 17:43 . 2011-04-30 17:43 879 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 4.png
2011-04-30 17:43 . 2011-04-30 17:43 897 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 2.png
2011-04-30 17:43 . 2011-04-30 17:43 872 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 3.png
2011-04-30 17:43 . 2011-04-30 17:43 879 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 14.PNG
2011-04-30 17:43 . 2011-04-30 17:43 900 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 13.png
2011-04-30 17:43 . 2011-04-30 17:43 917 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 11.png
2011-04-30 17:43 . 2011-04-30 17:43 901 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 12.png
2011-04-30 17:43 . 2011-04-30 17:43 914 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 10.png
2011-04-30 17:43 . 2011-04-30 17:43 900 —-a-w- c:\dunhelcache\Sprites\Lunar\Rune 1.png
2011-04-30 17:43 . 2011-04-30 17:43 605 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 8.PNG
2011-04-30 17:43 . 2011-04-30 17:43 287 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 9.PNG
2011-04-30 17:43 . 2011-04-30 17:43 509 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 7.PNG
2011-04-30 17:43 . 2011-04-30 17:43 460 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 6.PNG
2011-04-30 17:43 . 2011-04-30 17:43 347 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 4.PNG
2011-04-30 17:43 . 2011-04-30 17:43 401 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 5.PNG
2011-04-30 17:43 . 2011-04-30 17:43 393 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 38.PNG
2011-04-30 17:43 . 2011-04-30 17:43 340 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 37.PNG
2011-04-30 17:43 . 2011-04-30 17:43 369 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 36.PNG
2011-04-30 17:43 . 2011-04-30 17:43 395 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 35.PNG
2011-04-30 17:43 . 2011-04-30 17:43 347 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 33.PNG
2011-04-30 17:43 . 2011-04-30 17:43 335 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 34.PNG
2011-04-30 17:43 . 2011-04-30 17:43 520 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 32.PNG
2011-04-30 17:43 . 2011-04-30 17:43 502 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 30.PNG
2011-04-30 17:43 . 2011-04-30 17:43 544 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 31.PNG
2011-04-30 17:43 . 2011-04-30 17:43 283 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 3.PNG
2011-04-30 17:43 . 2011-04-30 17:43 521 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 29.PNG
2011-04-30 17:43 . 2011-04-30 17:43 505 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 27.PNG
2011-04-30 17:43 . 2011-04-30 17:43 405 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 28.PNG
2011-04-30 17:43 . 2011-04-30 17:43 541 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 26.PNG
2011-04-30 17:43 . 2011-04-30 17:43 398 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 24.PNG
2011-04-30 17:43 . 2011-04-30 17:43 340 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 25.PNG
2011-04-30 17:43 . 2011-04-30 17:43 436 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 23.PNG
2011-04-30 17:43 . 2011-04-30 17:43 349 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 22.PNG
2011-04-30 17:43 . 2011-04-30 17:43 394 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 20.PNG
2011-04-30 17:43 . 2011-04-30 17:43 369 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 21.PNG
2011-04-30 17:43 . 2011-04-30 17:43 496 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 2.PNG
2011-04-30 17:43 . 2011-04-30 17:43 480 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 19.PNG
2011-04-30 17:43 . 2011-04-30 17:43 459 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 18.PNG
2011-04-30 17:43 . 2011-04-30 17:43 297 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 17.PNG
2011-04-30 17:43 . 2011-04-30 17:43 489 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 16.PNG
2011-04-30 17:43 . 2011-04-30 17:43 482 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 14.PNG
2011-04-30 17:43 . 2011-04-30 17:43 459 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 15.PNG
2011-04-30 17:43 . 2011-04-30 17:43 351 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 13.PNG
2011-04-30 17:43 . 2011-04-30 17:43 480 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 12.PNG
2011-04-30 17:43 . 2011-04-30 17:43 372 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 10.PNG
2011-04-30 17:43 . 2011-04-30 17:43 574 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 11.PNG
2011-04-30 17:43 . 2011-04-30 17:43 343 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 1.PNG
2011-04-30 17:43 . 2011-04-30 17:43 389 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNARON 0.PNG
2011-04-30 17:43 . 2011-04-30 17:43 605 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 8.PNG
2011-04-30 17:43 . 2011-04-30 17:43 242 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 9.PNG
2011-04-30 17:43 . 2011-04-30 17:43 509 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 7.PNG
2011-04-30 17:43 . 2011-04-30 17:43 335 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 5.PNG
2011-04-30 17:43 . 2011-04-30 17:43 460 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 6.PNG
2011-04-30 17:43 . 2011-04-30 17:43 282 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 4.PNG
2011-04-30 17:43 . 2011-04-30 17:43 304 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 38.PNG
2011-04-30 17:43 . 2011-04-30 17:43 285 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 36.PNG
2011-04-30 17:43 . 2011-04-30 17:43 321 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 37.PNG
2011-04-30 17:43 . 2011-04-30 17:43 320 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 35.PNG
2011-04-30 17:43 . 2011-04-30 17:43 300 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 34.PNG
2011-04-30 17:43 . 2011-04-30 17:43 341 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 32.PNG
2011-04-30 17:43 . 2011-04-30 17:43 298 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 33.PNG
2011-04-30 17:43 . 2011-04-30 17:43 383 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 31.PNG
2011-04-30 17:43 . 2011-04-30 17:43 276 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 30.PNG
2011-04-30 17:43 . 2011-04-30 17:43 323 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 29.PNG
2011-04-30 17:43 . 2011-04-30 17:43 275 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 3.PNG
2011-04-30 17:43 . 2011-04-30 17:43 324 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 28.PNG
2011-04-30 17:43 . 2011-04-30 17:43 328 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 27.PNG
2011-04-30 17:43 . 2011-04-30 17:43 306 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 25.PNG
2011-04-30 17:43 . 2011-04-30 17:43 343 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 26.PNG
2011-04-30 17:43 . 2011-04-30 17:43 311 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 24.PNG
2011-04-30 17:43 . 2011-04-30 17:43 302 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 22.PNG
2011-04-30 17:43 . 2011-04-30 17:43 330 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 23.PNG
2011-04-30 17:43 . 2011-04-30 17:43 319 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 21.PNG
2011-04-30 17:43 . 2011-04-30 17:43 356 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 20.PNG
2011-04-30 17:43 . 2011-04-30 17:43 355 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 2.PNG
2011-04-30 17:43 . 2011-04-30 17:43 347 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 19.PNG
2011-04-30 17:43 . 2011-04-30 17:43 277 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 17.PNG
2011-04-30 17:43 . 2011-04-30 17:43 459 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 18.PNG
2011-04-30 17:43 . 2011-04-30 17:43 489 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 16.PNG
2011-04-30 17:43 . 2011-04-30 17:43 357 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 14.PNG
2011-04-30 17:43 . 2011-04-30 17:43 459 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 15.PNG
2011-04-30 17:43 . 2011-04-30 17:43 299 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 13.PNG
2011-04-30 17:43 . 2011-04-30 17:43 480 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 12.PNG
2011-04-30 17:43 . 2011-04-30 17:43 574 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 11.PNG
2011-04-30 17:43 . 2011-04-30 17:43 295 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 1.PNG
2011-04-30 17:43 . 2011-04-30 17:43 411 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 10.PNG
2011-04-30 17:43 . 2011-04-30 17:43 321 —-a-w- c:\dunhelcache\Sprites\Lunar\LUNAROFF 0.PNG
2011-04-30 17:43 . 2011-04-30 17:43 461 —-a-w- c:\dunhelcache\Sprites\Lunar\BOX 3.PNG
2011-04-30 17:43 . 2011-04-30 17:43 510 —-a-w- c:\dunhelcache\Sprites\Lunar\BOX 4.PNG
2011-04-30 17:43 . 2011-04-30 17:43 665 —-a-w- c:\dunhelcache\Sprites\Lunar\BOX 2.PNG
2011-04-30 17:43 . 2011-04-30 17:43 631 —-a-w- c:\dunhelcache\Sprites\Lunar\BOX 1.PNG
2011-04-30 17:43 . 2011-04-30 17:43 613 —-a-w- c:\dunhelcache\Sprites\Lunar\BOX 0.PNG
2011-04-30 17:43 . 2011-04-30 17:43 4609 —-a-w- c:\dunhelcache\Sprites\hoverorbrun2.PNG
2011-04-30 17:43 . 2011-04-30 17:43 4663 —-a-w- c:\dunhelcache\Sprites\hoverorbrun.PNG
2011-04-30 17:43 . 2011-04-30 17:43 592 —-a-w- c:\dunhelcache\Sprites\hitpointsfill.PNG
2011-04-30 17:43 . 2011-04-30 17:43 12800 —-a-w- c:\dunhelcache\Sprites\Friends\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 11118 —-a-w- c:\dunhelcache\Sprites\Friends\SPRITE 8.PNG
2011-04-30 17:43 . 2011-04-30 17:43 1158 —-a-w- c:\dunhelcache\Sprites\Friends\SPRITE 7.PNG
2011-04-30 17:43 . 2011-04-30 17:43 10238 —-a-w- c:\dunhelcache\Sprites\Friends\SPRITE 5.PNG
2011-04-30 17:43 . 2011-04-30 17:43 1106 —-a-w- c:\dunhelcache\Sprites\Friends\SPRITE 6.PNG
2011-04-30 17:43 . 2011-04-30 17:43 256 —-a-w- c:\dunhelcache\Sprites\Friends\SPRITE 4.PNG
2011-04-30 17:43 . 2011-04-30 17:43 5069 —-a-w- c:\dunhelcache\Sprites\frame.png
2011-04-30 17:43 . 2011-04-30 17:43 13824 —-a-w- c:\dunhelcache\Sprites\Equipment\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 483 —-a-w- c:\dunhelcache\Sprites\Equipment\CUSTOM 8.png
2011-04-30 17:43 . 2011-04-30 17:43 17033 —-a-w- c:\dunhelcache\Sprites\Equipment\CUSTOM 7.png
2011-04-30 17:43 . 2011-04-30 17:43 3134 —-a-w- c:\dunhelcache\Sprites\Equipment\CUSTOM 6.PNG
2011-04-30 17:43 . 2011-04-30 17:43 78848 —-a-w- c:\dunhelcache\Sprites\Emotes\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 763 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 8.PNG
2011-04-30 17:43 . 2011-04-30 17:43 784 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 9.PNG
2011-04-30 17:43 . 2011-04-30 17:43 806 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 7.PNG
2011-04-30 17:43 . 2011-04-30 17:43 840 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 6.PNG
2011-04-30 17:43 . 2011-04-30 17:43 785 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 5.PNG
2011-04-30 17:43 . 2011-04-30 17:43 517 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 33.PNG
2011-04-30 17:43 . 2011-04-30 17:43 802 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 4.PNG
2011-04-30 17:43 . 2011-04-30 17:43 1139 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 32.PNG
2011-04-30 17:43 . 2011-04-30 17:43 715 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 31.PNG
2011-04-30 17:43 . 2011-04-30 17:43 758 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 3.PNG
2011-04-30 17:43 . 2011-04-30 17:43 718 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 30.PNG
2011-04-30 17:43 . 2011-04-30 17:43 702 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 29.PNG
2011-04-30 17:43 . 2011-04-30 17:43 708 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 28.PNG
2011-04-30 17:43 . 2011-04-30 17:43 679 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 27.PNG
2011-04-30 17:43 . 2011-04-30 17:43 698 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 26.PNG
2011-04-30 17:43 . 2011-04-30 17:43 664 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 24.PNG
2011-04-30 17:43 . 2011-04-30 17:43 637 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 25.PNG
2011-04-30 17:43 . 2011-04-30 17:43 914 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 23.PNG
2011-04-30 17:43 . 2011-04-30 17:43 913 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 22.PNG
2011-04-30 17:43 . 2011-04-30 17:43 779 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 21.PNG
2011-04-30 17:43 . 2011-04-30 17:43 746 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 20.PNG
2011-04-30 17:43 . 2011-04-30 17:43 960 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 19.PNG
2011-04-30 17:43 . 2011-04-30 17:43 681 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 2.PNG
2011-04-30 17:43 . 2011-04-30 17:43 838 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 18.PNG
2011-04-30 17:43 . 2011-04-30 17:43 795 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 16.PNG
2011-04-30 17:43 . 2011-04-30 17:43 939 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 17.PNG
2011-04-30 17:43 . 2011-04-30 17:43 932 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 15.PNG
2011-04-30 17:43 . 2011-04-30 17:43 966 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 14.PNG
2011-04-30 17:43 . 2011-04-30 17:43 834 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 12.PNG
2011-04-30 17:43 . 2011-04-30 17:43 906 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 13.PNG
2011-04-30 17:43 . 2011-04-30 17:43 721 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 11.PNG
2011-04-30 17:43 . 2011-04-30 17:43 847 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 10.PNG
2011-04-30 17:43 . 2011-04-30 17:43 782 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 0.PNG
2011-04-30 17:43 . 2011-04-30 17:43 786 —-a-w- c:\dunhelcache\Sprites\Emotes\EMOTE 1.PNG
2011-04-30 17:43 . 2011-04-30 17:43 6144 —-a-w- c:\dunhelcache\Sprites\Clan Chat\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 1106 —-a-w- c:\dunhelcache\Sprites\Clan Chat\SPRITE 6.PNG
2011-04-30 17:43 . 2011-04-30 17:43 1158 —-a-w- c:\dunhelcache\Sprites\Clan Chat\SPRITE 7.PNG
2011-04-30 17:43 . 2011-04-30 17:43 256 —-a-w- c:\dunhelcache\Sprites\Clan Chat\SPRITE 4.PNG
2011-04-30 17:43 . 2011-04-30 17:43 9213 —-a-w- c:\dunhelcache\Sprites\Clan Chat\SPRITE 37.PNG
2011-04-30 17:43 . 2011-04-30 17:43 412 —-a-w- c:\dunhelcache\Sprites\Clan Chat\Lootshare 0.png
2011-04-30 17:43 . 2011-04-30 17:43 3198 —-a-w- c:\dunhelcache\Sprites\chatbuttons.png
2011-04-30 17:43 . 2011-04-30 17:43 40699 —-a-w- c:\dunhelcache\Sprites\chatarea.png
2011-04-30 17:43 . 2011-04-30 17:43 38400 —-a-w- c:\dunhelcache\Sprites\Attack\Thumbs.db
2011-04-30 17:43 . 2011-04-30 17:43 1002 —-a-w- c:\dunhelcache\Sprites\Attack\7609.png
2011-04-30 17:43 . 2011-04-30 17:43 1051 —-a-w- c:\dunhelcache\Sprites\Attack\7610.png
2011-04-30 17:43 . 2011-04-30 17:43 1004 —-a-w- c:\dunhelcache\Sprites\Attack\7608.png
2011-04-30 17:43 . 2011-04-30 17:43 999 —-a-w- c:\dunhelcache\Sprites\Attack\7607.png
2011-04-30 17:43 . 2011-04-30 17:43 1004 —-a-w- c:\dunhelcache\Sprites\Attack\7606.png
2011-04-30 17:43 . 2011-04-30 17:43 998 —-a-w- c:\dunhelcache\Sprites\Attack\7605.png
2011-04-30 17:43 . 2011-04-30 17:43 999 —-a-w- c:\dunhelcache\Sprites\Attack\7603.png
2011-04-30 17:43 . 2011-04-30 17:43 998 —-a-w- c:\dunhelcache\Sprites\Attack\7604.png
2011-04-30 17:43 . 2011-04-30 17:43 998 —-a-w- c:\dunhelcache\Sprites\Attack\7602.png
2011-04-30 17:43 . 2011-04-30 17:43 1039 —-a-w- c:\dunhelcache\Sprites\Attack\7601.png
2011-04-30 17:43 . 2011-04-30 17:43 1384 —-a-w- c:\dunhelcache\Sprites\Attack\7600.png
2011-04-30 17:43 . 2011-04-30 17:43 2306 —-a-w- c:\dunhelcache\Sprites\Attack\350a.png
2011-04-30 17:43 . 2011-04-30 17:43 1900 —-a-w- c:\dunhelcache\Sprites\Attack\7587.png
2011-04-30 17:43 . 2011-04-30 17:43 2570 —-a-w- c:\dunhelcache\Sprites\Attack\349a.png
2011-04-30 17:43 . 2011-04-30 17:43 2318 —-a-w- c:\dunhelcache\Sprites\Attack\350.png
2011-04-30 17:43 . 2011-04-30 17:43 2568 —-a-w- c:\dunhelcache\Sprites\Attack\349.png
2011-04-30 17:43 . 2011-04-30 17:43 2045 —-a-w- c:\dunhelcache\Sprites\Attack\19301a.png
2011-04-30 17:43 . 2011-04-30 17:43 2050 —-a-w- c:\dunhelcache\Sprites\Attack\19301.png
2011-04-30 17:43 . 2011-04-30 17:43 3158 —-a-w- c:\dunhelcache\Sprites\Attack\150.png
2011-04-30 17:43 . 2011-04-30 17:43 3133 —-a-w- c:\dunhelcache\Sprites\Attack\150a.png
2011-04-30 17:43 . 2011-04-30 17:43 1627 —-a-w- c:\dunhelcache\Raw\51802.dat
2011-04-30 17:43 . 2011-04-30 17:43 1627 —-a-w- c:\dunhelcache\Raw\51800.dat
2011-04-30 17:43 . 2011-04-30 17:43 1305 —-a-w- c:\dunhelcache\Raw\51799.dat
2011-04-30 17:43 . 2011-04-30 17:43 2303 —-a-w- c:\dunhelcache\Raw\44590.dat
2011-04-30 17:43 . 2011-04-30 17:43 2303 —-a-w- c:\dunhelcache\Raw\44590.mdl
2011-04-30 17:43 . 2011-04-30 17:43 3058 —-a-w- c:\dunhelcache\Raw\43660.mdl
2011-04-30 17:43 . 2011-04-30 17:43 3058 —-a-w- c:\dunhelcache\Raw\43660.dat
2011-04-30 17:43 . 2011-04-30 17:43 30124 —-a-w- c:\dunhelcache\data\300.dat
2011-04-30 17:43 . 2011-04-30 17:43 520 —-a-w- c:\dunhelcache\data\541.dat
2011-04-30 17:43 . 2011-04-30 17:43 12035 —-a-w- c:\dunhelcache\data\241.dat
2011-04-30 17:43 . 2011-04-30 17:43 25615 —-a-w- c:\dunhelcache\data\219.dat
2011-04-30 17:43 . 2011-04-30 17:43 29677 —-a-w- c:\dunhelcache\data\1919.dat
2011-04-30 17:43 . 2011-04-30 17:43 83046 —-a-w- c:\dunhelcache\data\1834.dat
2011-04-30 17:43 . 2011-04-30 17:43 36262 —-a-w- c:\dunhelcache\data\1775.dat
2011-04-30 17:43 . 2011-04-30 17:43 44570 —-a-w- c:\dunhelcache\data\1774.dat
2011-04-30 17:43 . 2011-04-30 17:43 27477 —-a-w- c:\dunhelcache\data\1773.dat
2011-04-30 17:43 . 2011-04-30 17:43 2627 —-a-w- c:\dunhelcache\data\1771.dat
2011-04-30 17:43 . 2011-04-30 17:43 5075 —-a-w- c:\dunhelcache\data\1768.dat
2011-04-30 17:43 . 2011-04-30 17:43 4444 —-a-w- c:\dunhelcache\data\1770.dat
2011-04-30 17:43 . 2011-04-30 17:43 2813 —-a-w- c:\dunhelcache\data\1766.dat
2011-04-30 17:43 . 2011-04-30 17:43 206 —-a-w- c:\dunhelcache\data\1759.dat
2011-04-30 17:43 . 2011-04-30 17:43 87 —-a-w- c:\dunhelcache\data\1765.dat
2011-04-30 17:43 . 2011-04-30 17:43 3556 —-a-w- c:\dunhelcache\data\1754.dat
2011-04-30 17:43 . 2011-04-30 17:43 4269 —-a-w- c:\dunhelcache\data\1751.dat
2011-04-30 17:43 . 2011-04-30 17:43 5747 —-a-w- c:\dunhelcache\data\1749.dat
2011-04-30 17:43 . 2011-04-30 17:43 2307 —-a-w- c:\dunhelcache\data\1750.dat
2011-04-30 17:43 . 2011-04-30 17:43 16601 —-a-w- c:\dunhelcache\data\1748.dat
2011-04-30 17:43 . 2011-04-30 17:43 9539 —-a-w- c:\dunhelcache\data\1695.dat
2011-04-30 17:43 . 2011-04-30 17:43 2249 —-a-w- c:\dunhelcache\data\1694.dat
2011-04-30 17:43 . 2011-04-30 17:43 57063 —-a-w- c:\dunhelcache\data\1675.dat
2011-04-30 17:43 . 2011-04-30 17:43 29677 —-a-w- c:\dunhelcache\data\1686.dat
2011-04-30 17:43 . 2011-04-30 17:43 8017 —-a-w- c:\dunhelcache\data\1674.dat
2011-04-30 17:43 . 2011-04-30 17:43 17202 —-a-w- c:\dunhelcache\data\1639.dat
2011-04-30 17:43 . 2011-04-30 17:43 6934 —-a-w- c:\dunhelcache\data\1379.dat
2011-04-30 17:43 . 2011-04-30 17:43 25056 —-a-w- c:\dunhelcache\data\1575.dat
2011-04-30 17:43 . 2011-04-30 17:43 519 —-a-w- c:\dunhelcache\data\1353.dat
2011-04-30 17:43 . 2011-04-30 17:43 54379 —-a-w- c:\dunhelcache\data\1345.dat
2011-04-30 17:43 . 2011-04-30 17:43 1126 —-a-w- c:\dunhelcache\data\1312.dat
2011-04-30 17:43 . 2011-04-30 17:43 16080 —-a-w- c:\dunhelcache\data\1313.dat
2011-04-30 17:43 . 2011-04-30 17:43 1870 —-a-w- c:\dunhelcache\data\1311.dat
2011-04-30 17:43 . 2011-04-30 17:43 5682 —-a-w- c:\dunhelcache\data\1310.dat
2011-04-30 17:43 . 2011-04-30 17:43 3967 —-a-w- c:\dunhelcache\data\1309.dat
2011-04-30 17:43 . 2011-04-30 17:43 5474 —-a-w- c:\dunhelcache\data\1307.dat
2011-04-30 17:43 . 2011-04-30 17:43 2363 —-a-w- c:\dunhelcache\data\1308.dat
2011-04-30 17:43 . 2011-04-30 17:43 5419 —-a-w- c:\dunhelcache\data\1306.dat
2011-04-30 17:43 . 2011-04-30 17:43 2695 —-a-w- c:\dunhelcache\data\1303.dat
2011-04-30 17:43 . 2011-04-30 17:43 3295 —-a-w- c:\dunhelcache\data\1305.dat
2011-04-30 17:43 . 2011-04-30 17:43 9281 —-a-w- c:\dunhelcache\data\1302.dat
2011-04-30 17:43 . 2011-04-30 17:43 8883 —-a-w- c:\dunhelcache\data\1301.dat
2011-04-30 17:43 . 2011-04-30 17:43 3810 —-a-w- c:\dunhelcache\data\1299.dat
2011-04-30 17:43 . 2011-04-30 17:43 11613 —-a-w- c:\dunhelcache\data\1300.dat
2011-04-30 17:43 . 2011-04-30 17:43 10395 —-a-w- c:\dunhelcache\data\1298.dat
2011-04-30 17:43 . 2011-04-30 17:43 4368 —-a-w- c:\dunhelcache\data\1297.dat
2011-04-30 17:43 . 2011-04-30 17:43 9833 —-a-w- c:\dunhelcache\data\1296.dat
2011-04-30 17:43 . 2011-04-30 17:43 10157 —-a-w- c:\dunhelcache\data\1295.dat
2011-04-30 17:43 . 2011-04-30 17:43 5302 —-a-w- c:\dunhelcache\data\1293.dat
2011-04-30 17:43 . 2011-04-30 17:43 19550 —-a-w- c:\dunhelcache\data\1294.dat
2011-04-30 17:43 . 2011-04-30 17:43 4060 —-a-w- c:\dunhelcache\data\1292.dat
2011-04-30 17:43 . 2011-04-30 17:43 7171 —-a-w- c:\dunhelcache\data\1291.dat
2011-04-30 17:43 . 2011-04-30 17:43 86861 —-a-w- c:\dunhelcache\data\1208.dat
2011-04-30 17:43 . 2011-04-30 17:43 3593 —-a-w- c:\dunhelcache\data\1177.dat
2011-04-30 17:43 . 2011-04-30 17:43 9315 —-a-w- c:\dunhelcache\data\1175.dat
2011-04-30 17:43 . 2011-04-30 17:43 5608 —-a-w- c:\dunhelcache\data\1173.dat
2011-04-30 17:43 . 2011-04-30 17:43 10396 —-a-w- c:\dunhelcache\data\1169.dat
2011-04-30 17:43 . 2011-04-30 17:43 11308 —-a-w- c:\dunhelcache\data\1166.dat
2011-04-30 17:43 . 2011-04-30 17:43 886 —-a-w- c:\dunhelcache\data\1161.dat
2011-04-30 17:43 . 2011-04-30 17:43 47690 —-a-w- c:\dunhelcache\data\1124.dat
2011-04-30 17:43 . 2011-04-30 17:43 53438 —-a-w- c:\dunhelcache\data\1088.dat
2011-04-30 17:43 . 2011-04-30 17:43 69017 —-a-w- c:\dunhelcache\data\1076.dat
2011-04-30 17:43 . 2011-04-30 17:43 25523 —-a-w- c:\dunhelcache\data\1063.dat
2011-04-30 17:40 . 2011-04-30 17:43 16208986 —-a-w- c:\dunhelcache\DunhelCache.zip
2011-04-30 17:40 . 2011-04-30 17:43 8340 —-a-w- c:\dunhelcache\main_file_cache.idx4
2011-04-30 17:40 . 2011-04-30 17:43 6264 —-a-w- c:\dunhelcache\main_file_cache.idx2
2011-04-30 17:40 . 2011-04-30 17:43 3876 —-a-w- c:\dunhelcache\main_file_cache.idx3
2011-04-30 17:40 . 2011-04-30 17:43 89562 —-a-w- c:\dunhelcache\main_file_cache.idx1
2011-04-30 17:40 . 2011-04-30 17:43 54 —-a-w- c:\dunhelcache\main_file_cache.idx0
2011-04-30 17:40 . 2011-04-30 17:43 19747367 —-a-w- c:\dunhelcache\main_file_cache.dat
2011-04-30 17:40 . 2011-04-30 17:43 4 —-a-w- c:\dunhelcache\uid.dat
.
—- Directory of C:\exorted_new_cache —-
.
2011-04-30 13:15 . 2011-04-30 13:15 43386 —-a-w- c:\exorted_new_cache\jingle3.mid
2011-04-30 13:15 . 2011-04-30 13:15 61436 —-a-w- c:\exorted_new_cache\jingle1.mid
2011-04-30 13:15 . 2011-04-30 13:15 43386 —-a-w- c:\exorted_new_cache\jingle2.mid
2011-04-30 13:15 . 2011-04-30 13:15 0 —-a-w- c:\exorted_new_cache\cacheVersion1.dat
2011-04-30 13:15 . 2011-04-30 13:15 21244 —-a-w- c:\exorted_new_cache\Data\Sprites\Vote\CUSTOM 4.png
2011-04-30 13:15 . 2011-04-30 13:15 4789 —-a-w- c:\exorted_new_cache\Data\Sprites\Vote\CUSTOM 3.png
2011-04-30 13:15 . 2011-04-30 13:15 5141 —-a-w- c:\exorted_new_cache\Data\Sprites\Vote\CUSTOM 1.png
2011-04-30 13:15 . 2011-04-30 13:15 4163 —-a-w- c:\exorted_new_cache\Data\Sprites\Vote\CUSTOM 2.png
2011-04-30 13:15 . 2011-04-30 13:15 4677 —-a-w- c:\exorted_new_cache\Data\Sprites\Vote\CUSTOM 0.png
2011-04-30 13:15 . 2011-04-30 13:15 2249 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\tabclicked.png
2011-04-30 13:15 . 2011-04-30 13:15 895 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\tabhover.PNG
2011-04-30 13:15 . 2011-04-30 13:15 32259 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\tabarea.png
2011-04-30 13:15 . 2011-04-30 13:15 524 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 9.png
2011-04-30 13:15 . 2011-04-30 13:15 468 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 8.png
2011-04-30 13:15 . 2011-04-30 13:15 532 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 7.png
2011-04-30 13:15 . 2011-04-30 13:15 475 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 6.png
2011-04-30 13:15 . 2011-04-30 13:15 553 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 4.png
2011-04-30 13:15 . 2011-04-30 13:15 544 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 5.png
2011-04-30 13:15 . 2011-04-30 13:15 496 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 3.png
2011-04-30 13:15 . 2011-04-30 13:15 502 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 2.png
2011-04-30 13:15 . 2011-04-30 13:15 519 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 13.png
2011-04-30 13:15 . 2011-04-30 13:15 3263 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 14.png
2011-04-30 13:15 . 2011-04-30 13:15 609 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 12.png
2011-04-30 13:15 . 2011-04-30 13:15 653 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 11.png
2011-04-30 13:15 . 2011-04-30 13:15 608 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 10.png
2011-04-30 13:15 . 2011-04-30 13:15 544 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 0.png
2011-04-30 13:15 . 2011-04-30 13:15 387 —-a-w- c:\exorted_new_cache\Data\Sprites\Tabarea\icon 1.png
2011-04-30 13:15 . 2011-04-30 13:15 10238 —-a-w- c:\exorted_new_cache\Data\Sprites\SPRITE 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 256 —-a-w- c:\exorted_new_cache\Data\Sprites\SPRITE 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 8.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 9.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 7.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 6.PNG
2011-04-30 13:15 . 2011-04-30 13:15 158 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 8107 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 18.PNG
2011-04-30 13:15 . 2011-04-30 13:15 418 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 17.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 15.PNG
2011-04-30 13:15 . 2011-04-30 13:15 475 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 16.png
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 14.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 13.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 12.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 11.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 157 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 10.PNG
2011-04-30 13:15 . 2011-04-30 13:15 643 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CHECK 1.png
2011-04-30 13:15 . 2011-04-30 13:15 445 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CUSTOM 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 520 —-a-w- c:\exorted_new_cache\Data\Sprites\PrivateChat\CHECK 0.png
2011-04-30 13:15 . 2011-04-30 13:15 804 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 9.png
2011-04-30 13:15 . 2011-04-30 13:15 740 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 8.png
2011-04-30 13:15 . 2011-04-30 13:15 384 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 7.PNG
2011-04-30 13:15 . 2011-04-30 13:15 516 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 6.PNG
2011-04-30 13:15 . 2011-04-30 13:15 502 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 483 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 496 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 460 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 458 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 489 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYON 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 717 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 9.png
2011-04-30 13:15 . 2011-04-30 13:15 663 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 8.png
2011-04-30 13:15 . 2011-04-30 13:15 370 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 7.PNG
2011-04-30 13:15 . 2011-04-30 13:15 476 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 6.PNG
2011-04-30 13:15 . 2011-04-30 13:15 476 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 499 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 460 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 463 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 461 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 474 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYOFF 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 408 —-a-w- c:\exorted_new_cache\Data\Sprites\Prayer\PRAYER 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 375 —-a-w- c:\exorted_new_cache\Data\Sprites\Pest Control\PEST1 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 409 —-a-w- c:\exorted_new_cache\Data\Sprites\Pest Control\PEST1 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 485 —-a-w- c:\exorted_new_cache\Data\Sprites\Pest Control\PEST1 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 484 —-a-w- c:\exorted_new_cache\Data\Sprites\Pest Control\PEST1 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 666 —-a-w- c:\exorted_new_cache\Data\Sprites\Pest Control\PEST1 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 794 —-a-w- c:\exorted_new_cache\Data\Sprites\Pest Control\PEST1 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1104 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\NOTINWILD1 0.png
2011-04-30 13:15 . 2011-04-30 13:15 1351 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\INWILD1 0.png
2011-04-30 13:15 . 2011-04-30 13:15 9108 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 9.png
2011-04-30 13:15 . 2011-04-30 13:15 138 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\infinity.png
2011-04-30 13:15 . 2011-04-30 13:15 12211 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 8.png
2011-04-30 13:15 . 2011-04-30 13:15 12096 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 7.png
2011-04-30 13:15 . 2011-04-30 13:15 12605 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 6.png
2011-04-30 13:15 . 2011-04-30 13:15 10997 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 4.png
2011-04-30 13:15 . 2011-04-30 13:15 13038 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 5.png
2011-04-30 13:15 . 2011-04-30 13:15 11182 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 3.png
2011-04-30 13:15 . 2011-04-30 13:15 10056 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 24.png
2011-04-30 13:15 . 2011-04-30 13:15 8995 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 23.png
2011-04-30 13:15 . 2011-04-30 13:15 22561 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 22.png
2011-04-30 13:15 . 2011-04-30 13:15 5631 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 201.png
2011-04-30 13:15 . 2011-04-30 13:15 18592 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 21.png
2011-04-30 13:15 . 2011-04-30 13:15 5567 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 200.png
2011-04-30 13:15 . 2011-04-30 13:15 10644 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 2.png
2011-04-30 13:15 . 2011-04-30 13:15 21123 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 20.png
2011-04-30 13:15 . 2011-04-30 13:15 10644 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 2 - Copy.png
2011-04-30 13:15 . 2011-04-30 13:15 17630 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 19.png
2011-04-30 13:15 . 2011-04-30 13:15 17893 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 18.png
2011-04-30 13:15 . 2011-04-30 13:15 15563 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 17.png
2011-04-30 13:15 . 2011-04-30 13:15 9609 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 16.png
2011-04-30 13:15 . 2011-04-30 13:15 11566 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 14.png
2011-04-30 13:15 . 2011-04-30 13:15 9530 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 15.png
2011-04-30 13:15 . 2011-04-30 13:15 11516 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 13.png
2011-04-30 13:15 . 2011-04-30 13:15 10997 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 11.png
2011-04-30 13:15 . 2011-04-30 13:15 11040 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 12.png
2011-04-30 13:15 . 2011-04-30 13:15 9299 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 10.png
2011-04-30 13:15 . 2011-04-30 13:15 10888 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 1.png
2011-04-30 13:15 . 2011-04-30 13:15 10888 —-a-w- c:\exorted_new_cache\Data\Sprites\Other\CUSTOM 1 - Copy.png
2011-04-30 13:15 . 2011-04-30 13:15 490 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\X 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 679 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\X 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 552 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\X 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 4584 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\runorb.png
2011-04-30 13:15 . 2011-04-30 13:15 4684 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\runclick.png
2011-04-30 13:15 . 2011-04-30 13:15 505 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\prayerfill.PNG
2011-04-30 13:15 . 2011-04-30 13:15 361 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 9.PNG
2011-04-30 13:15 . 2011-04-30 13:15 356 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 8.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1278 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 7.PNG
2011-04-30 13:15 . 2011-04-30 13:15 375 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 6.PNG
2011-04-30 13:15 . 2011-04-30 13:15 625 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 304 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 562 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 592 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1383 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 14.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1314 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 15.PNG
2011-04-30 13:15 . 2011-04-30 13:15 401 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 13.PNG
2011-04-30 13:15 . 2011-04-30 13:15 392 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 12.PNG
2011-04-30 13:15 . 2011-04-30 13:15 635 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 10.PNG
2011-04-30 13:15 . 2011-04-30 13:15 631 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 11.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1257 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 486 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\ORBS 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 4609 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\hoverorbrun2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 592 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\hitpointsfill.PNG
2011-04-30 13:15 . 2011-04-30 13:15 4663 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\hoverorbrun.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1257 —-a-w- c:\exorted_new_cache\Data\Sprites\Orbs\emptyorb.PNG
2011-04-30 13:15 . 2011-04-30 13:15 503 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 36.PNG
2011-04-30 13:15 . 2011-04-30 13:15 610 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 9.PNG
2011-04-30 13:15 . 2011-04-30 13:15 923 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 35.PNG
2011-04-30 13:15 . 2011-04-30 13:15 571 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 33.PNG
2011-04-30 13:15 . 2011-04-30 13:15 533 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 34.PNG
2011-04-30 13:15 . 2011-04-30 13:15 571 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 32.PNG
2011-04-30 13:15 . 2011-04-30 13:15 687 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 31.PNG
2011-04-30 13:15 . 2011-04-30 13:15 735 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 29.PNG
2011-04-30 13:15 . 2011-04-30 13:15 686 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 30.PNG
2011-04-30 13:15 . 2011-04-30 13:15 626 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 28.PNG
2011-04-30 13:15 . 2011-04-30 13:15 659 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 27.PNG
2011-04-30 13:15 . 2011-04-30 13:15 677 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 26.PNG
2011-04-30 13:15 . 2011-04-30 13:15 694 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 24.PNG
2011-04-30 13:15 . 2011-04-30 13:15 669 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 25.PNG
2011-04-30 13:15 . 2011-04-30 13:15 479 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 23.PNG
2011-04-30 13:15 . 2011-04-30 13:15 450 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 22.PNG
2011-04-30 13:15 . 2011-04-30 13:15 466 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 21.PNG
2011-04-30 13:15 . 2011-04-30 13:15 524 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 19.PNG
2011-04-30 13:15 . 2011-04-30 13:15 453 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 20.PNG
2011-04-30 13:15 . 2011-04-30 13:15 720 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 18.PNG
2011-04-30 13:15 . 2011-04-30 13:15 746 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 17.PNG
2011-04-30 13:15 . 2011-04-30 13:15 716 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 16.PNG
2011-04-30 13:15 . 2011-04-30 13:15 714 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 15.PNG
2011-04-30 13:15 . 2011-04-30 13:15 838 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 14.PNG
2011-04-30 13:15 . 2011-04-30 13:15 602 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 13.PNG
2011-04-30 13:15 . 2011-04-30 13:15 500 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 11.PNG
2011-04-30 13:15 . 2011-04-30 13:15 567 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 12.PNG
2011-04-30 13:15 . 2011-04-30 13:15 640 —-a-w- c:\exorted_new_cache\Data\Sprites\Options\SPRITE 10.PNG
2011-04-30 13:15 . 2011-04-30 13:15 3891 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Warriors 1.png
2011-04-30 13:15 . 2011-04-30 13:15 20274 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Varrock 0.png
2011-04-30 13:15 . 2011-04-30 13:15 3495 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Tzhaar 1.png
2011-04-30 13:15 . 2011-04-30 13:15 63488 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Thumbs.db
2011-04-30 13:15 . 2011-04-30 13:15 885 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Slayer 1.png
2011-04-30 13:15 . 2011-04-30 13:15 2337 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Taverly 1.png
2011-04-30 13:15 . 2011-04-30 13:15 3291 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Pk 1.png
2011-04-30 13:15 . 2011-04-30 13:15 3848 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\PestControl 1.png
2011-04-30 13:15 . 2011-04-30 13:15 10752 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\lumrbidge 0.png
2011-04-30 13:15 . 2011-04-30 13:15 986 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Kalphite 1.png
2011-04-30 13:15 . 2011-04-30 13:15 714 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Kbd 1.png
2011-04-30 13:15 . 2011-04-30 13:15 4934 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Hover 5.png
2011-04-30 13:15 . 2011-04-30 13:15 4934 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Hover 4.png
2011-04-30 13:15 . 2011-04-30 13:15 4934 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Hover 3.png
2011-04-30 13:15 . 2011-04-30 13:15 4934 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Hover 2.png
2011-04-30 13:15 . 2011-04-30 13:15 2909 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Hover 0.png
2011-04-30 13:15 . 2011-04-30 13:15 2850 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Hover 1.png
2011-04-30 13:15 . 2011-04-30 13:15 1207 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\HillGiants 1.png
2011-04-30 13:15 . 2011-04-30 13:15 1419 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Godwarss 1.png
2011-04-30 13:15 . 2011-04-30 13:15 13464 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Falador 0.png
2011-04-30 13:15 . 2011-04-30 13:15 3579 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\GodWars 1.png
2011-04-30 13:15 . 2011-04-30 13:15 4061 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\DuelArena 1.png
2011-04-30 13:15 . 2011-04-30 13:15 1857 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Dagganoths 1.png
2011-04-30 13:15 . 2011-04-30 13:15 562 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Corporeal 1.png
2011-04-30 13:15 . 2011-04-30 13:15 1170 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Crabs 1.png
2011-04-30 13:15 . 2011-04-30 13:15 293 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Chaos 1.png
2011-04-30 13:15 . 2011-04-30 13:15 835 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\brimhaven 1.png
2011-04-30 13:15 . 2011-04-30 13:15 3371 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Barrows 1.png
2011-04-30 13:15 . 2011-04-30 13:15 9345 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Background 1.png
2011-04-30 13:15 . 2011-04-30 13:15 4336 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Barbarian 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 3238 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Back 1.png
2011-04-30 13:15 . 2011-04-30 13:15 3256 —-a-w- c:\exorted_new_cache\Data\Sprites\Minigame\Back 0.png
2011-04-30 13:15 . 2011-04-30 13:15 536 —-a-w- c:\exorted_new_cache\Data\Sprites\Magic\Home 1.png
2011-04-30 13:15 . 2011-04-30 13:15 536 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\SPRITE 1.png
2011-04-30 13:15 . 2011-04-30 13:15 914 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 9.png
2011-04-30 13:15 . 2011-04-30 13:15 6374 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\SPRITE 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 921 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 8.png
2011-04-30 13:15 . 2011-04-30 13:15 904 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 7.png
2011-04-30 13:15 . 2011-04-30 13:15 934 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 6.png
2011-04-30 13:15 . 2011-04-30 13:15 879 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 4.png
2011-04-30 13:15 . 2011-04-30 13:15 931 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 5.png
2011-04-30 13:15 . 2011-04-30 13:15 872 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 3.png
2011-04-30 13:15 . 2011-04-30 13:15 897 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 2.png
2011-04-30 13:15 . 2011-04-30 13:15 879 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 14.PNG
2011-04-30 13:15 . 2011-04-30 13:15 900 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 13.png
2011-04-30 13:15 . 2011-04-30 13:15 901 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 12.png
2011-04-30 13:15 . 2011-04-30 13:15 917 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 11.png
2011-04-30 13:15 . 2011-04-30 13:15 914 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 10.png
2011-04-30 13:15 . 2011-04-30 13:15 900 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\Rune 1.png
2011-04-30 13:15 . 2011-04-30 13:15 287 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 9.PNG
2011-04-30 13:15 . 2011-04-30 13:15 509 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 7.PNG
2011-04-30 13:15 . 2011-04-30 13:15 605 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 8.PNG
2011-04-30 13:15 . 2011-04-30 13:15 460 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 6.PNG
2011-04-30 13:15 . 2011-04-30 13:15 401 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 393 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 38.PNG
2011-04-30 13:15 . 2011-04-30 13:15 347 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 340 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 37.PNG
2011-04-30 13:15 . 2011-04-30 13:15 395 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 35.PNG
2011-04-30 13:15 . 2011-04-30 13:15 369 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 36.PNG
2011-04-30 13:15 . 2011-04-30 13:15 335 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 34.PNG
2011-04-30 13:15 . 2011-04-30 13:15 347 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 33.PNG
2011-04-30 13:15 . 2011-04-30 13:15 520 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 32.PNG
2011-04-30 13:15 . 2011-04-30 13:15 544 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 31.PNG
2011-04-30 13:15 . 2011-04-30 13:15 502 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 30.PNG
2011-04-30 13:15 . 2011-04-30 13:15 521 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 29.PNG
2011-04-30 13:15 . 2011-04-30 13:15 283 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 405 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 28.PNG
2011-04-30 13:15 . 2011-04-30 13:15 505 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 27.PNG
2011-04-30 13:15 . 2011-04-30 13:15 541 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 26.PNG
2011-04-30 13:15 . 2011-04-30 13:15 340 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 25.PNG
2011-04-30 13:15 . 2011-04-30 13:15 436 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 23.PNG
2011-04-30 13:15 . 2011-04-30 13:15 398 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 24.PNG
2011-04-30 13:15 . 2011-04-30 13:15 349 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 22.PNG
2011-04-30 13:15 . 2011-04-30 13:15 369 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 21.PNG
2011-04-30 13:15 . 2011-04-30 13:15 496 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 394 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 20.PNG
2011-04-30 13:15 . 2011-04-30 13:15 480 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 19.PNG
2011-04-30 13:15 . 2011-04-30 13:15 459 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 18.PNG
2011-04-30 13:15 . 2011-04-30 13:15 297 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 17.PNG
2011-04-30 13:15 . 2011-04-30 13:15 489 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 16.PNG
2011-04-30 13:15 . 2011-04-30 13:15 482 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 14.PNG
2011-04-30 13:15 . 2011-04-30 13:15 459 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 15.PNG
2011-04-30 13:15 . 2011-04-30 13:15 351 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 13.PNG
2011-04-30 13:15 . 2011-04-30 13:15 480 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 12.PNG
2011-04-30 13:15 . 2011-04-30 13:15 372 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 10.PNG
2011-04-30 13:15 . 2011-04-30 13:15 574 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 11.PNG
2011-04-30 13:15 . 2011-04-30 13:15 343 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 389 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNARON 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 392 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 8.PNG
2011-04-30 13:15 . 2011-04-30 13:15 242 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 9.PNG
2011-04-30 13:15 . 2011-04-30 13:15 334 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 7.PNG
2011-04-30 13:15 . 2011-04-30 13:15 309 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 6.PNG
2011-04-30 13:15 . 2011-04-30 13:15 335 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 282 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 321 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 37.PNG
2011-04-30 13:15 . 2011-04-30 13:15 304 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 38.PNG
2011-04-30 13:15 . 2011-04-30 13:15 285 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 36.PNG
2011-04-30 13:15 . 2011-04-30 13:15 320 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 35.PNG
2011-04-30 13:15 . 2011-04-30 13:15 298 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 33.PNG
2011-04-30 13:15 . 2011-04-30 13:15 300 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 34.PNG
2011-04-30 13:15 . 2011-04-30 13:15 341 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 32.PNG
2011-04-30 13:15 . 2011-04-30 13:15 383 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 31.PNG
2011-04-30 13:15 . 2011-04-30 13:15 275 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 276 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 30.PNG
2011-04-30 13:15 . 2011-04-30 13:15 323 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 29.PNG
2011-04-30 13:15 . 2011-04-30 13:15 328 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 27.PNG
2011-04-30 13:15 . 2011-04-30 13:15 324 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 28.PNG
2011-04-30 13:15 . 2011-04-30 13:15 343 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 26.PNG
2011-04-30 13:15 . 2011-04-30 13:15 306 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 25.PNG
2011-04-30 13:15 . 2011-04-30 13:15 330 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 23.PNG
2011-04-30 13:15 . 2011-04-30 13:15 311 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 24.PNG
2011-04-30 13:15 . 2011-04-30 13:15 302 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 22.PNG
2011-04-30 13:15 . 2011-04-30 13:15 319 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 21.PNG
2011-04-30 13:15 . 2011-04-30 13:15 355 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 356 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 20.PNG
2011-04-30 13:15 . 2011-04-30 13:15 347 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 19.PNG
2011-04-30 13:15 . 2011-04-30 13:15 328 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 18.PNG
2011-04-30 13:15 . 2011-04-30 13:15 341 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 16.PNG
2011-04-30 13:15 . 2011-04-30 13:15 277 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 17.PNG
2011-04-30 13:15 . 2011-04-30 13:15 339 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 15.PNG
2011-04-30 13:15 . 2011-04-30 13:15 299 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 13.PNG
2011-04-30 13:15 . 2011-04-30 13:15 357 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 14.PNG
2011-04-30 13:15 . 2011-04-30 13:15 364 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 12.PNG
2011-04-30 13:15 . 2011-04-30 13:15 367 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 11.PNG
2011-04-30 13:15 . 2011-04-30 13:15 411 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 10.PNG
2011-04-30 13:15 . 2011-04-30 13:15 295 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 321 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\LUNAROFF 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 461 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\BOX 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 510 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\BOX 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 665 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\BOX 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 631 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\BOX 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 613 —-a-w- c:\exorted_new_cache\Data\Sprites\Lunar\BOX 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 8060 —-a-w- c:\exorted_new_cache\Data\Sprites\Login\titlebutton.png
2011-04-30 13:15 . 2011-04-30 13:15 5246 —-a-w- c:\exorted_new_cache\Data\Sprites\Login\titlebox.png
2011-04-30 13:15 . 2011-04-30 13:15 18878 —-a-w- c:\exorted_new_cache\Data\Sprites\Login\bg.jpg
2011-04-30 13:15 . 2011-04-30 13:15 6971 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\WorldMap\XmlConverter.java
2011-04-30 13:15 . 2011-04-30 13:15 29018 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\WorldMap\WorldMap.jar
2011-04-30 13:15 . 2011-04-30 13:15 354341 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\WorldMap\worldmap.dat
2011-04-30 13:15 . 2011-04-30 13:15 3723 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\tools2.png
2011-04-30 13:15 . 2011-04-30 13:15 3914 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\tools.png
2011-04-30 13:15 . 2011-04-30 13:15 6662 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\toggles.png
2011-04-30 13:15 . 2011-04-30 13:15 2268 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\splash.png
2011-04-30 13:15 . 2011-04-30 13:15 4415 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\profile.png
2011-04-30 13:15 . 2011-04-30 13:15 4006 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\ItemList\Itemlist.jar
2011-04-30 13:15 . 2011-04-30 13:15 6655 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\ItemList\ItemList Files\XmlConverter.java
2011-04-30 13:15 . 2011-04-30 13:15 5628 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\ItemList\ItemList Files\XmlConverter.class
2011-04-30 13:15 . 2011-04-30 13:15 51 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\ItemList\ItemList Files\META-INF\MANIFEST.MF
2011-04-30 13:15 . 2011-04-30 13:15 163 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\ItemList\ItemList Files\Applet.app
2011-04-30 13:15 . 2011-04-30 13:15 90 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\ItemList\ItemList Files\Build.bat
2011-04-30 13:15 . 2011-04-30 13:15 3018 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\icon.png
2011-04-30 13:15 . 2011-04-30 13:15 13813 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\bar.png
2011-04-30 13:15 . 2011-04-30 13:15 3550 —-a-w- c:\exorted_new_cache\Data\Sprites\JFrame\file.png
2011-04-30 13:15 . 2011-04-30 13:15 340 —-a-w- c:\exorted_new_cache\Data\Sprites\HITPOINTS_1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 470 —-a-w- c:\exorted_new_cache\Data\Sprites\HITPOINTS_0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 23944 —-a-w- c:\exorted_new_cache\Data\Sprites\Gameframe\MAPBACK 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 23228 —-a-w- c:\exorted_new_cache\Data\Sprites\Gameframe\MAPBACK 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 2060 —-a-w- c:\exorted_new_cache\Data\Sprites\Gameframe\Globe 2.png
2011-04-30 13:15 . 2011-04-30 13:15 3198 —-a-w- c:\exorted_new_cache\Data\Sprites\Gameframe\chatbuttons.png
2011-04-30 13:15 . 2011-04-30 13:15 2046 —-a-w- c:\exorted_new_cache\Data\Sprites\Gameframe\Globe 1.png
2011-04-30 13:15 . 2011-04-30 13:15 40699 —-a-w- c:\exorted_new_cache\Data\Sprites\Gameframe\chatarea.png
2011-04-30 13:15 . 2011-04-30 13:15 11118 —-a-w- c:\exorted_new_cache\Data\Sprites\Friends\SPRITE 8.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1158 —-a-w- c:\exorted_new_cache\Data\Sprites\Friends\SPRITE 7.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1106 —-a-w- c:\exorted_new_cache\Data\Sprites\Friends\SPRITE 6.PNG
2011-04-30 13:15 . 2011-04-30 13:15 256 —-a-w- c:\exorted_new_cache\Data\Sprites\Friends\SPRITE 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 10238 —-a-w- c:\exorted_new_cache\Data\Sprites\Friends\SPRITE 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 483 —-a-w- c:\exorted_new_cache\Data\Sprites\Equipment\SPRITE 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 483 —-a-w- c:\exorted_new_cache\Data\Sprites\Equipment\SPRITE 1.png
2011-04-30 13:15 . 2011-04-30 13:15 390 —-a-w- c:\exorted_new_cache\Data\Sprites\Equipment\CUSTOM 9.PNG
2011-04-30 13:15 . 2011-04-30 13:15 387 —-a-w- c:\exorted_new_cache\Data\Sprites\Equipment\CUSTOM 8.png
2011-04-30 13:15 . 2011-04-30 13:15 17033 —-a-w- c:\exorted_new_cache\Data\Sprites\Equipment\CUSTOM 7.png
2011-04-30 13:15 . 2011-04-30 13:15 1378 —-a-w- c:\exorted_new_cache\Data\Sprites\Equipment\CUSTOM 3.png
2011-04-30 13:15 . 2011-04-30 13:15 1425 —-a-w- c:\exorted_new_cache\Data\Sprites\Equipment\CUSTOM 2.png
2011-04-30 13:15 . 2011-04-30 13:15 1277 —-a-w- c:\exorted_new_cache\Data\Sprites\Equipment\CUSTOM 1.png
2011-04-30 13:15 . 2011-04-30 13:15 20771 —-a-w- c:\exorted_new_cache\Data\Sprites\Equipment\bg 1.png
2011-04-30 13:15 . 2011-04-30 13:15 784 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 9.PNG
2011-04-30 13:15 . 2011-04-30 13:15 763 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 8.PNG
2011-04-30 13:15 . 2011-04-30 13:15 806 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 7.PNG
2011-04-30 13:15 . 2011-04-30 13:15 840 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 6.PNG
2011-04-30 13:15 . 2011-04-30 13:15 802 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 785 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 5.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1139 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 33.PNG
2011-04-30 13:15 . 2011-04-30 13:15 715 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 31.PNG
2011-04-30 13:15 . 2011-04-30 13:15 718 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 30.PNG
2011-04-30 13:15 . 2011-04-30 13:15 702 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 29.PNG
2011-04-30 13:15 . 2011-04-30 13:15 758 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 3.PNG
2011-04-30 13:15 . 2011-04-30 13:15 708 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 28.PNG
2011-04-30 13:15 . 2011-04-30 13:15 679 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 27.PNG
2011-04-30 13:15 . 2011-04-30 13:15 698 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 26.PNG
2011-04-30 13:15 . 2011-04-30 13:15 637 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 25.PNG
2011-04-30 13:15 . 2011-04-30 13:15 664 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 24.PNG
2011-04-30 13:15 . 2011-04-30 13:15 914 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 23.PNG
2011-04-30 13:15 . 2011-04-30 13:15 913 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 22.PNG
2011-04-30 13:15 . 2011-04-30 13:15 779 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 21.PNG
2011-04-30 13:15 . 2011-04-30 13:15 746 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 20.PNG
2011-04-30 13:15 . 2011-04-30 13:15 681 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 2.PNG
2011-04-30 13:15 . 2011-04-30 13:15 960 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 19.PNG
2011-04-30 13:15 . 2011-04-30 13:15 939 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 17.PNG
2011-04-30 13:15 . 2011-04-30 13:15 838 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 18.PNG
2011-04-30 13:15 . 2011-04-30 13:15 795 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 16.PNG
2011-04-30 13:15 . 2011-04-30 13:15 932 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 15.PNG
2011-04-30 13:15 . 2011-04-30 13:15 966 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 14.PNG
2011-04-30 13:15 . 2011-04-30 13:15 834 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 12.PNG
2011-04-30 13:15 . 2011-04-30 13:15 906 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 13.PNG
2011-04-30 13:15 . 2011-04-30 13:15 721 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 11.PNG
2011-04-30 13:15 . 2011-04-30 13:15 847 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 10.PNG
2011-04-30 13:15 . 2011-04-30 13:15 786 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 1.PNG
2011-04-30 13:15 . 2011-04-30 13:15 782 —-a-w- c:\exorted_new_cache\Data\Sprites\Emotes\EMOTE 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 54 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\desktop.ini
2011-04-30 13:15 . 2011-04-30 13:15 51086 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 9.png
2011-04-30 13:15 . 2011-04-30 13:15 51367 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 8.png
2011-04-30 13:15 . 2011-04-30 13:15 51193 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 7.png
2011-04-30 13:15 . 2011-04-30 13:15 50047 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 6.png
2011-04-30 13:15 . 2011-04-30 13:15 51135 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 5.png
2011-04-30 13:15 . 2011-04-30 13:15 52549 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 4.png
2011-04-30 13:15 . 2011-04-30 13:15 51597 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 3.png
2011-04-30 13:15 . 2011-04-30 13:15 51155 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 2.png
2011-04-30 13:15 . 2011-04-30 13:15 4145 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 15.png
2011-04-30 13:15 . 2011-04-30 13:15 4007 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 14.png
2011-04-30 13:15 . 2011-04-30 13:15 4124 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 13.png
2011-04-30 13:15 . 2011-04-30 13:15 4058 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 12.png
2011-04-30 13:15 . 2011-04-30 13:15 3977 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 11.png
2011-04-30 13:15 . 2011-04-30 13:15 51546 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 10.png
2011-04-30 13:15 . 2011-04-30 13:15 51595 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 1.png
2011-04-30 13:15 . 2011-04-30 13:15 1310 —-a-w- c:\exorted_new_cache\Data\Sprites\CustomCursors\Cursor 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 736 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 9.png
2011-04-30 13:15 . 2011-04-30 13:15 1353 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 7.png
2011-04-30 13:15 . 2011-04-30 13:15 804 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 8.png
2011-04-30 13:15 . 2011-04-30 13:15 909 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 6.png
2011-04-30 13:15 . 2011-04-30 13:15 723 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 5.png
2011-04-30 13:15 . 2011-04-30 13:15 694 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 3.png
2011-04-30 13:15 . 2011-04-30 13:15 754 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 4.png
2011-04-30 13:15 . 2011-04-30 13:15 854 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 2.png
2011-04-30 13:15 . 2011-04-30 13:15 752 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 19.png
2011-04-30 13:15 . 2011-04-30 13:15 774 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 17.png
2011-04-30 13:15 . 2011-04-30 13:15 720 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 18.png
2011-04-30 13:15 . 2011-04-30 13:15 841 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 16.png
2011-04-30 13:15 . 2011-04-30 13:15 1060 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 15.png
2011-04-30 13:15 . 2011-04-30 13:15 752 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 14.png
2011-04-30 13:15 . 2011-04-30 13:15 876 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 13.png
2011-04-30 13:15 . 2011-04-30 13:15 705 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 12.png
2011-04-30 13:15 . 2011-04-30 13:15 714 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 11.png
2011-04-30 13:15 . 2011-04-30 13:15 937 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 1.png
2011-04-30 13:15 . 2011-04-30 13:15 750 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 10.png
2011-04-30 13:15 . 2011-04-30 13:15 771 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYON 0.png
2011-04-30 13:15 . 2011-04-30 13:15 638 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 9.png
2011-04-30 13:15 . 2011-04-30 13:15 1049 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 7.png
2011-04-30 13:15 . 2011-04-30 13:15 717 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 8.png
2011-04-30 13:15 . 2011-04-30 13:15 729 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 6.png
2011-04-30 13:15 . 2011-04-30 13:15 594 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 4.png
2011-04-30 13:15 . 2011-04-30 13:15 644 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 5.png
2011-04-30 13:15 . 2011-04-30 13:15 542 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 3.png
2011-04-30 13:15 . 2011-04-30 13:15 623 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 19.png
2011-04-30 13:15 . 2011-04-30 13:15 584 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 2.png
2011-04-30 13:15 . 2011-04-30 13:15 627 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 18.png
2011-04-30 13:15 . 2011-04-30 13:15 681 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 16.png
2011-04-30 13:15 . 2011-04-30 13:15 632 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 17.png
2011-04-30 13:15 . 2011-04-30 13:15 855 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 15.png
2011-04-30 13:15 . 2011-04-30 13:15 607 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 14.png
2011-04-30 13:15 . 2011-04-30 13:15 578 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 12.png
2011-04-30 13:15 . 2011-04-30 13:15 753 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 13.png
2011-04-30 13:15 . 2011-04-30 13:15 597 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 11.png
2011-04-30 13:15 . 2011-04-30 13:15 694 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 1.png
2011-04-30 13:15 . 2011-04-30 13:15 682 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 10.png
2011-04-30 13:15 . 2011-04-30 13:15 663 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\PRAYOFF 0.png
2011-04-30 13:15 . 2011-04-30 13:15 430 —-a-w- c:\exorted_new_cache\Data\Sprites\Curses\GLOW 0.PNG
2011-04-30 13:15 . 2011-04-30 13:15 995 —-a-w- c:\exorted_new_cache\Data\Sprites\Configuration\empty.png
2011-04-30 13:15 . 2011-04-30 13:15 560 —-a-w- c:\exorted_new_cache\Data\Sprites\Configuration\full.png
2011-04-30 13:15 . 2011-04-30 13:15 1158 —-a-w- c:\exorted_new_cache\Data\Sprites\Clan Chat\SPRITE 7.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1106 —-a-w- c:\exorted_new_cache\Data\Sprites\Clan Chat\SPRITE 6.PNG
2011-04-30 13:15 . 2011-04-30 13:15 256 —-a-w- c:\exorted_new_cache\Data\Sprites\Clan Chat\SPRITE 4.PNG
2011-04-30 13:15 . 2011-04-30 13:15 412 —-a-w- c:\exorted_new_cache\Data\Sprites\Clan Chat\Lootshare 0.png
2011-04-30 13:15 . 2011-04-30 13:15 9213 —-a-w- c:\exorted_new_cache\Data\Sprites\Clan Chat\SPRITE 37.PNG
2011-04-30 13:15 . 2011-04-30 13:15 1051 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7610.png
2011-04-30 13:15 . 2011-04-30 13:15 1002 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7609.png
2011-04-30 13:15 . 2011-04-30 13:15 1004 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7608.png
2011-04-30 13:15 . 2011-04-30 13:15 999 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7607.png
2011-04-30 13:15 . 2011-04-30 13:15 1004 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7606.png
2011-04-30 13:15 . 2011-04-30 13:15 998 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7605.png
2011-04-30 13:15 . 2011-04-30 13:15 998 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7604.png
2011-04-30 13:15 . 2011-04-30 13:15 998 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7602.png
2011-04-30 13:15 . 2011-04-30 13:15 999 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7603.png
2011-04-30 13:15 . 2011-04-30 13:15 1039 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7601.png
2011-04-30 13:15 . 2011-04-30 13:15 1384 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7600.png
2011-04-30 13:15 . 2011-04-30 13:15 2306 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\350a.png
2011-04-30 13:15 . 2011-04-30 13:15 1900 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\7587.png
2011-04-30 13:15 . 2011-04-30 13:15 2318 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\350.png
2011-04-30 13:15 . 2011-04-30 13:15 2570 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\349a.png
2011-04-30 13:15 . 2011-04-30 13:15 2568 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\349.png
2011-04-30 13:15 . 2011-04-30 13:15 2050 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\19301.png
2011-04-30 13:15 . 2011-04-30 13:15 2045 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\19301a.png
2011-04-30 13:15 . 2011-04-30 13:15 3133 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\150a.png
2011-04-30 13:15 . 2011-04-30 13:15 3158 —-a-w- c:\exorted_new_cache\Data\Sprites\Attack\150.png
2011-04-30 13:15 . 2011-04-30 13:15 15325 —-a-w- c:\exorted_new_cache\Data\Sprites\Achieve\ACH 2.png
2011-04-30 13:15 . 2011-04-30 13:15 21620 —-a-w- c:\exorted_new_cache\Data\Sprites\Achieve\ACH 1.png
2011-04-30 13:15 . 2011-04-30 13:15 266 —-a-w- c:\exorted_new_cache\Data\Sprites\Achieve\ACH 0.png
2011-04-30 13:15 . 2011-04-30 13:15 4868 —-a-w- c:\exorted_new_cache\Data\pbcapewear.dat
2011-04-30 13:15 . 2011-04-30 13:15 4808 —-a-w- c:\exorted_new_cache\Data\pbcapedrop.dat
2011-04-30 13:15 . 2011-04-30 13:15 3340 —-a-w- c:\exorted_new_cache\Data\models3.idx
2011-04-30 13:15 . 2011-04-30 13:15 1472181 —-a-w- c:\exorted_new_cache\Data\models3.dat
2011-04-30 13:15 . 2011-04-30 13:15 364 —-a-w- c:\exorted_new_cache\Data\models2.idx
2011-04-30 13:15 . 2011-04-30 13:15 133720 —-a-w- c:\exorted_new_cache\Data\models2.dat
2011-04-30 13:15 . 2011-04-30 13:15 4852 —-a-w- c:\exorted_new_cache\Data\models.idx
2011-04-30 13:15 . 2011-04-30 13:15 1265413 —-a-w- c:\exorted_new_cache\Data\models.dat
2011-04-30 13:15 . 2011-04-30 13:15 2 —-a-w- c:\exorted_new_cache\Data\login.ini
2011-04-30 13:15 . 2011-04-30 13:15 251881 —-a-w- c:\exorted_new_cache\Data\Animation\anim2\1290.dat
2011-04-30 13:15 . 2011-04-30 13:15 69084 —-a-w- c:\exorted_new_cache\Data\Animation\anim\999.dat
2011-04-30 13:15 . 2011-04-30 13:15 30124 —-a-w- c:\exorted_new_cache\Data\Animation\anim\300.dat
2011-04-30 13:15 . 2011-04-30 13:15 520 —-a-w- c:\exorted_new_cache\Data\Animation\anim\541.dat
2011-04-30 13:15 . 2011-04-30 13:15 51527 —-a-w- c:\exorted_new_cache\Data\Animation\anim\2571.dat
2011-04-30 13:15 . 2011-04-30 13:15 40034 —-a-w- c:\exorted_new_cache\Data\Animation\anim\2514.dat
2011-04-30 13:15 . 2011-04-30 13:15 12035 —-a-w- c:\exorted_new_cache\Data\Animation\anim\241.dat
2011-04-30 13:15 . 2011-04-30 13:15 29709 —-a-w- c:\exorted_new_cache\Data\Animation\anim\2301.dat
2011-04-30 13:15 . 2011-04-30 13:15 36595 —-a-w- c:\exorted_new_cache\Data\Animation\anim\2286.dat
2011-04-30 13:15 . 2011-04-30 13:15 30629 —-a-w- c:\exorted_new_cache\Data\Animation\anim\2013.dat
2011-04-30 13:15 . 2011-04-30 13:15 25615 —-a-w- c:\exorted_new_cache\Data\Animation\anim\219.dat
2011-04-30 13:15 . 2011-04-30 13:15 29516 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1955.dat
2011-04-30 13:15 . 2011-04-30 13:15 29677 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1919.dat
2011-04-30 13:15 . 2011-04-30 13:15 160543 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1868.dat
2011-04-30 13:15 . 2011-04-30 13:15 83046 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1834.dat
2011-04-30 13:15 . 2011-04-30 13:15 104585 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1843.dat
2011-04-30 13:15 . 2011-04-30 13:15 104512 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1816.dat
2011-04-30 13:15 . 2011-04-30 13:15 36262 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1775.dat
2011-04-30 13:15 . 2011-04-30 13:15 27477 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1773.dat
2011-04-30 13:15 . 2011-04-30 13:15 44570 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1774.dat
2011-04-30 13:15 . 2011-04-30 13:15 2627 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1771.dat
2011-04-30 13:15 . 2011-04-30 13:15 4444 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1770.dat
2011-04-30 13:15 . 2011-04-30 13:15 5075 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1768.dat
2011-04-30 13:15 . 2011-04-30 13:15 87 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1765.dat
2011-04-30 13:15 . 2011-04-30 13:15 2813 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1766.dat
2011-04-30 13:15 . 2011-04-30 13:15 206 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1759.dat
2011-04-30 13:15 . 2011-04-30 13:15 3556 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1754.dat
2011-04-30 13:15 . 2011-04-30 13:15 2307 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1750.dat
2011-04-30 13:15 . 2011-04-30 13:15 4269 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1751.dat
2011-04-30 13:15 . 2011-04-30 13:15 16601 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1748.dat
2011-04-30 13:15 . 2011-04-30 13:15 5747 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1749.dat
2011-04-30 13:15 . 2011-04-30 13:15 9539 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1695.dat
2011-04-30 13:15 . 2011-04-30 13:15 2249 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1694.dat
2011-04-30 13:15 . 2011-04-30 13:15 57063 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1675.dat
2011-04-30 13:15 . 2011-04-30 13:15 8017 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1674.dat
2011-04-30 13:15 . 2011-04-30 13:15 66387 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1662.dat
2011-04-30 13:15 . 2011-04-30 13:15 17202 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1639.dat
2011-04-30 13:15 . 2011-04-30 13:15 54497 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1589.dat
2011-04-30 13:15 . 2011-04-30 13:15 47923 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1590.dat
2011-04-30 13:15 . 2011-04-30 13:15 25056 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1575.dat
2011-04-30 13:15 . 2011-04-30 13:15 3440 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1525.dat
2011-04-30 13:15 . 2011-04-30 13:15 28200 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1513.dat
2011-04-30 13:15 . 2011-04-30 13:15 53387 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1512.dat
2011-04-30 13:15 . 2011-04-30 13:15 6934 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1379.dat
2011-04-30 13:15 . 2011-04-30 13:15 519 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1353.dat
2011-04-30 13:15 . 2011-04-30 13:15 54379 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1345.dat
2011-04-30 13:15 . 2011-04-30 13:15 16080 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1313.dat
2011-04-30 13:15 . 2011-04-30 13:15 1126 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1312.dat
2011-04-30 13:15 . 2011-04-30 13:15 5682 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1310.dat
2011-04-30 13:15 . 2011-04-30 13:15 1870 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1311.dat
2011-04-30 13:15 . 2011-04-30 13:15 2363 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1308.dat
2011-04-30 13:15 . 2011-04-30 13:15 3967 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1309.dat
2011-04-30 13:15 . 2011-04-30 13:15 5474 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1307.dat
2011-04-30 13:15 . 2011-04-30 13:15 5419 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1306.dat
2011-04-30 13:15 . 2011-04-30 13:15 3295 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1305.dat
2011-04-30 13:15 . 2011-04-30 13:15 4951 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1304.dat
2011-04-30 13:15 . 2011-04-30 13:15 2695 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1303.dat
2011-04-30 13:15 . 2011-04-30 13:15 8883 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1301.dat
2011-04-30 13:15 . 2011-04-30 13:15 9281 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1302.dat
2011-04-30 13:15 . 2011-04-30 13:15 11613 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1300.dat
2011-04-30 13:15 . 2011-04-30 13:15 3810 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1299.dat
2011-04-30 13:15 . 2011-04-30 13:15 10395 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1298.dat
2011-04-30 13:15 . 2011-04-30 13:15 9833 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1296.dat
2011-04-30 13:15 . 2011-04-30 13:15 4368 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1297.dat
2011-04-30 13:15 . 2011-04-30 13:15 10157 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1295.dat
2011-04-30 13:15 . 2011-04-30 13:15 19550 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1294.dat
2011-04-30 13:15 . 2011-04-30 13:15 4060 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1292.dat
2011-04-30 13:15 . 2011-04-30 13:15 5302 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1293.dat
2011-04-30 13:15 . 2011-04-30 13:15 7171 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1291.dat
2011-04-30 13:15 . 2011-04-30 13:15 22237 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1287.dat
2011-04-30 13:15 . 2011-04-30 13:15 86861 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1208.dat
2011-04-30 13:15 . 2011-04-30 13:15 3593 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1177.dat
2011-04-30 13:15 . 2011-04-30 13:15 9315 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1175.dat
2011-04-30 13:15 . 2011-04-30 13:15 5608 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1173.dat
2011-04-30 13:15 . 2011-04-30 13:15 10396 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1169.dat
2011-04-30 13:15 . 2011-04-30 13:15 11308 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1166.dat
2011-04-30 13:15 . 2011-04-30 13:15 886 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1161.dat
2011-04-30 13:15 . 2011-04-30 13:15 47690 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1124.dat
2011-04-30 13:15 . 2011-04-30 13:15 65382 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1123.dat
2011-04-30 13:15 . 2011-04-30 13:15 53438 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1088.dat
2011-04-30 13:15 . 2011-04-30 13:15 69017 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1076.dat
2011-04-30 13:15 . 2011-04-30 13:15 25523 —-a-w- c:\exorted_new_cache\Data\Animation\anim\1063.dat
2011-04-30 13:15 . 2011-04-30 13:15 17684 —-a-w- c:\exorted_new_cache\sound1.wav
2011-04-30 13:14 . 2011-04-30 13:15 18004776 —-a-w- c:\exorted_new_cache\ecache.zip
2011-04-30 13:14 . 2011-04-30 13:15 8340 —-a-w- c:\exorted_new_cache\main_file_cache.idx4
2011-04-30 13:14 . 2011-04-30 13:15 6264 —-a-w- c:\exorted_new_cache\main_file_cache.idx2
2011-04-30 13:14 . 2011-04-30 13:15 3876 —-a-w- c:\exorted_new_cache\main_file_cache.idx3
2011-04-30 13:14 . 2011-04-30 13:15 89562 —-a-w- c:\exorted_new_cache\main_file_cache.idx1
2011-04-30 13:14 . 2011-04-30 13:15 54 —-a-w- c:\exorted_new_cache\main_file_cache.idx0
2011-04-30 13:14 . 2011-04-30 13:15 19778420 —-a-w- c:\exorted_new_cache\main_file_cache.dat
2011-04-30 13:14 . 2011-04-30 13:15 4 —-a-w- c:\exorted_new_cache\uid.dat
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-14 1957888]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-04-29 2423752]
"Mega Manager"="c:\program files\Megaupload\Mega Manager\MegaManager.exe" [2010-11-03 2113024]
"PrinterShare"="c:\program files\PrinterShare\paConsole.exe" [2011-02-22 1107456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"iKeyWorks"="c:\progra~1\A4Tech\Keyboard\Ikeymain.exe" [2004-08-31 61440]
"WheelMouse"="c:\progra~1\A4Tech\Mouse\Amoumain.exe" [2004-09-01 147456]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-13 198160]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2010-03-18 614400]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\Lee Edgar\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2010-8-4 303104]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-6-11 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-6-11 813584]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 12:28 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe"
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Orange\\Livebox\\RGWREPAIR.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\PrinterShare\\paConsole.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Windows iLivid Toolbar\\ToolBar\\dtUser.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16193:TCP"= 16193:TCP:BitComet 16193 TCP
"16193:UDP"= 16193:UDP:BitComet 16193 UDP
"55064:TCP"= 55064:TCP:bitcomet 55064 tcp
"55064:UDP"= 55064:UDP:bitcomet 55064 udp
.
R2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\Drivers\Ca533av.sys [x]
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\DRIVERS\Amps2prt.sys [2004-08-25 9984]
R3 BTCOMM;BTCOMM;c:\windows\system32\drivers\Btcomm.sys [x]
R3 BTKRNBDG;Bluetooth COM Bridge;c:\windows\system32\DRIVERS\btkrnbdg.sys [x]
R3 CSRBC01;%CSRBC01.SvcDesc%;c:\windows\system32\Drivers\csrbc01.sys [x]
R3 DLPortIO;DriverLINX Port I/O Driver;c:\windows\system32\DRIVERS\DLPortIO.SYS [2000-06-29 3584]
R3 MTK;Media Technology Kernel Driver;c:\windows\system32\Drivers\mtk.sys [x]
R3 SecureSrv;SecureSrv; [x]
R3 vad_multi;Windigo Virtual Audio Device (WDM);c:\windows\system32\drivers\vadmulti.sys [x]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2006-08-10 223128]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 aswFsBlk;aswFsBlk; [x]
S2 pdfFactory Pro Dispatcher v3;pdfFactory Pro Dispatcher v3;c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe [2010-03-18 614400]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - SASDIFSV
*Deregistered* - uphcleanhlp
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-29 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 21:51]
.
2011-04-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
2011-05-01 c:\windows\Tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
Trusted Zone: securesuite.co.uk\www
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://secure.footprint.net/kingsisle/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
FF - ProfilePath - c:\documents and settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - user.js: keyword.enabled - 1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-01 16:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-10512063-1881097818-1119676352-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2a,d9,db,11,cc,c7,6e,95,52,b5,58,cb,a0,cf,e4,ad,27,de,53,33,93,32,9f,
ab,3a,83,12,94,c7,4b,50,8d,67,ec,61,46,52,f3,d8,a0,97,05,fc,c5,b7,1e,48,5d,\
"??"=hex:56,52,75,73,36,e9,4b,67,3c,6b,47,2a,09,08,ac,8b
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(664)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2011-05-01 16:45:27
ComboFix-quarantined-files.txt 2011-05-01 15:45
ComboFix2.txt 2011-05-01 12:01
.
Pre-Run: 28,629,315,584 bytes free
Post-Run: 28,621,148,160 bytes free
.
Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 710E565B92BB2EFE8ECC27BEAD483612
You're welcome :)

Re-run Malwarebytes' Anti-Malware
  • Double-click MalwareBytes' (Note to Vista users, please right-click and select Run as Administrator.)
    • Go to Update tab to update Malwarebytes' Anti-Malware
  • Then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • Look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

Please get a new OTL scan log. Please set OTL up this way for the scan.

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
===================================================

On your next reply please post :
MBAM log
ESET log
Fresh OTL log
Advice on your system's behaviour


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi There

My computer seems much better, its quicker and is now bringing up the correct pages and Searchqu.com looks to have gone.

here are the log files

MBAM

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6490

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

02/05/2011 09:26:49
mbam-log-2011-05-02 (09-26-49).txt

Scan type: Quick scan
Objects scanned: 204780
Time elapsed: 15 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Typelib\{B035BA6B-57CD-4F72-B545-65BE465FCAF6} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D44FD6F0-9746-484E-B5C4-C66688393872} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0EB3F101-224A-4B2B-9E5B-DF720857529C} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Mp3Tube (Adware.Mp3Tube) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files\mozilla firefox\searchplugins\Mp3Tube.xml (Adware.Mp3Tube) -> Quarantined and deleted successfully.
c:\documents and settings\lee edgar\application data\data.dat (Stolen.Data) -> Quarantined and deleted successfully.


ESET ONLINE SCANNER


ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=65121148375d8e48b06b25f9eb0fae79
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-05-02 11:37:53
# local_time=2011-05-02 12:37:53 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=768 16777215 100 0 21313650 21313650 0 0
# compatibility_mode=8192 67108863 100 0 2780 2780 0 0
# scanned=148788
# found=23
# cleaned=0
# scan_time=9367
C:\Documents and Settings\Lee Edgar\Application Data\Sun\Java\Deployment\cache\6.0\17\2d86a291-1dd87cdc multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Application Data\Sun\Java\Deployment\cache\6.0\26\3223fa1a-4b6ce19e Java/TrojanDownloader.Agent.NAM trojan (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Application Data\Sun\Java\Deployment\cache\6.0\41\70d92269-3ca13453 multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Application Data\Sun\Java\Deployment\cache\6.0\43\14f255ab-1da2eb2a multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Application Data\Sun\Java\Deployment\cache\6.0\46\4935eaae-2c9ee5cf multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Application Data\Sun\Java\Deployment\cache\6.0\61\1e8e14bd-21eaeaed Java/TrojanDownloader.Agent.NAM trojan (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Desktop\Radio decoders\BPcalc v1[1].0 .exe probably a variant of Win32/Agent.KRKADFL trojan (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Desktop\Radio decoders\Ford ALC.exe probably a variant of Win32/Agent.IEOPSDV trojan (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Local Settings\temp\mediaget_installer.exe Win32/Adware.GoodMedia.C application (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Local Settings\Temporary Internet Files\Content.IE5\J2BHRKZH\st[1].txt HTML/Iframe.B.Gen virus (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Lee Edgar\Local Settings\Temporary Internet Files\Content.IE5\QDGWFD3R\st[1].txt HTML/Iframe.B.Gen virus (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Halo Tool Box\Addons\screenies.exe probably a variant of Win32/PSW.Agent.NWCWQAJ trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Halo Tool Box\h3filmtools\MirageBETA.95.exe probably a variant of Win32/Bifrose.CZYYOIC trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Orange\setup\Orange_icons.EXE Win32/Adware.BHO.MegaSearch application (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2555\A0214446.rbf Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2555\A0214447.rbf Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2555\A0214448.rbf Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2555\A0214449.rbf Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2555\A0214450.rbf Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2555\A0214451.rbf Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2556\A0214530.exe Win32/Adware.Toolbar.Shopper application (unable to clean) 00000000000000000000000000000000 I
C:\WINDOWS\dbplugin.ocx probably a variant of Win32/Adware.Agent.MCARLOM application (unable to clean) 00000000000000000000000000000000 I
G:\dans stuff\Ebook.rar a variant of MSIL/Injector.FP trojan (unable to clean) 00000000000000000000000000000000 I


OTL LOG



OTL logfile created on: 02/05/2011 12:42:45 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Lee Edgar\Desktop\What the Tech
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 479.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.45 Gb Total Space | 26.39 Gb Free Space | 35.44% Space Free | Partition Type: NTFS
Drive F: | 941.92 Mb Total Space | 157.57 Mb Free Space | 16.73% Space Free | Partition Type: FAT32
Drive G: | 149.05 Gb Total Space | 125.05 Gb Free Space | 83.90% Space Free | Partition Type: NTFS

Computer Name: MAINCOMPUTER | User Name: Lee Edgar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Lee Edgar\Desktop\What the Tech\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)
PRC - C:\Program Files\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Lee Edgar\Desktop\What the Tech\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\Program Files\Unlocker\UnlockerHook.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SecureSrv) – File not found
SRV - (Pml Driver HPZ12) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (pdfFactory Pro Dispatcher v3) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (LBTServ) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (UxTuneUp) – C:\WINDOWS\SYSTEM32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (BVRPMPR5) – C:\WINDOWS\SYSTEM32\DRIVERS\BVRPMPR5.SYS (Avanquest Software)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (fssfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (nmwcd) – C:\WINDOWS\SYSTEM32\DRIVERS\ccdcmb.sys (Nokia)
DRV - (WinDriver6) – C:\WINDOWS\SYSTEM32\DRIVERS\windrvr6.sys (Jungo)
DRV - (LUsbFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouKE) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (LMouFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (L8042mou) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (L8042Kbd) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (PCANDIS5) – C:\WINDOWS\SYSTEM32\PCANDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (FilterService) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam E3500(UVC) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys ()
DRV - (pccsmcfd) – C:\WINDOWS\SYSTEM32\DRIVERS\pccsmcfd.sys (Nokia)
DRV - (s117obex) – C:\WINDOWS\SYSTEM32\DRIVERS\s117obex.sys (MCCI Corporation)
DRV - (s117mdm) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mdm.sys (MCCI Corporation)
DRV - (s117mgmt) Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mgmt.sys (MCCI Corporation)
DRV - (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117unic.sys (MCCI Corporation)
DRV - (s117nd5) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS) – C:\WINDOWS\SYSTEM32\DRIVERS\s117nd5.sys (MCCI Corporation)
DRV - (s117mdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mdfl.sys (MCCI Corporation)
DRV - (s117bus) Sony Ericsson Device 117 driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117bus.sys (MCCI Corporation)
DRV - (vaxscsi) – C:\WINDOWS\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (SE27mdm) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27mdm.sys (MCCI)
DRV - (SE27mdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27mdfl.sys (MCCI)
DRV - (SE27bus) Sony Ericsson Device 039 Driver driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27bus.sys (MCCI)
DRV - (LHidKe) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LHidUsbK) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidUsbK.sys (Logitech, Inc.)
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (Amps2prt) – C:\WINDOWS\SYSTEM32\DRIVERS\Amps2prt.sys (A4Tech Co.,Ltd.)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) – C:\WINDOWS\SYSTEM32\DRIVERS\alcan5wn.sys (THOMSON)
DRV - (alcaudsl) – C:\WINDOWS\SYSTEM32\DRIVERS\alcaudsl.sys (THOMSON)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (Machnm32) – C:\WINDOWS\SYSTEM32\Machnm32.sys ()
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (DCamUSBSQTECH) Dual-Mode DSC(2770) – C:\WINDOWS\SYSTEM32\DRIVERS\SQCaptur.sys (Service & Quality Technology.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (DLPortIO) – C:\WINDOWS\SYSTEM32\DRIVERS\DLPORTIO.SYS ()
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbarsearch.com/?tmp=toolbar_mp3tube_results&prt=pinballtb01ff&clid=591a699985204c28835e93a02489f74a&subid=&Keywords={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 44
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:[removed]
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {34EFA911-B536-4C08-BECE-CD5E55C875B0}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: {40a1f5d7-afc2-498f-b264-02668d616ff6}:1.1
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.1.3

FF - user.js..keyword.enabled: 1

FF - HKLM\software\mozilla\Firefox\extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010/04/15 23:15:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/18 15:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/24 13:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010/04/15 23:15:54 | 000,000,000 | —D | M]

[2011/04/24 14:09:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Extensions
[2011/04/24 14:09:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions
[2010/05/11 11:20:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/15 21:29:02 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/01/22 16:34:08 | 000,000,000 | —D | M] (Mega Manager Integration) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{40a1f5d7-afc2-498f-b264-02668d616ff6}
[2011/02/08 13:52:50 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/04/24 14:09:00 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011/01/16 20:18:29 | 000,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/09/15 19:29:11 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/02/08 13:53:02 | 000,000,000 | —D | M] (Page Speed) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2011/01/18 20:28:06 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/03/30 17:43:52 | 000,000,000 | —D | M] (Babylon) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\[removed]
[2010/12/31 15:35:08 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\[removed]
[2011/04/18 15:39:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\staged
[2011/01/22 16:35:54 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\vshare@toolbar
[2010/05/14 15:53:24 | 000,001,819 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\bing.xml
[2010/12/14 13:27:53 | 000,001,215 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\Mp3Tube.xml
[2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\SearchquWebSearch.xml
[2011/01/22 16:36:49 | 000,001,583 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\web-search.xml
[2011/04/24 14:09:21 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/15 08:58:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/05 17:44:12 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/26 10:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/19 12:33:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/24 20:14:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
[2010/05/15 08:57:36 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
[2011/03/18 18:57:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/03/30 17:43:56 | 000,002,428 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/13 13:36:54 | 000,002,035 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchddr.xml
[2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
[2010/01/01 09:00:00 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/05/01 16:40:16 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - No CLSID value found.
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DC59A0D4-0ED6-4A73-B356-1B977F2A7725} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] File not found
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [iKeyWorks] C:\Program Files\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [pdfFactory Pro Dispatcher v3] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)
O4 - HKCU..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [LDM] File not found
O4 - HKCU..\Run: [Mega Manager] C:\Program Files\Megaupload\Mega Manager\MegaManager.exe (Megaupload Limited)
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [PrinterShare] C:\Program Files\PrinterShare\paConsole.exe (PrinterAnywhere)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: securesuite.co.uk ([www] https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} http://pcpitstop.com/internet/pcpConnCheck.cab (iCC Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} http://launcher.station.sony.com/weblaunch…ebInstaller.cab (SonyOnlineInstallerX)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} https://secure.footprint.net/kingsisle/stat…ameLauncher.CAB (Wizard101GameLauncher)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} http://u3.sandisk.com/download/apps/LPInstaller.CAB (CInstallLPCtrl Object)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.microsoft.com/download/Pow…N-US/msorun.cab (IEAnimBehaviorFactory Class)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\bw+0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\offline-8876480 {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/02 09:57:47 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/05/02 09:15:29 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/05/02 06:55:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2011/05/01 20:31:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Media Get LLC
[2011/05/01 20:27:44 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/05/01 20:27:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\MediaGet2
[2011/05/01 12:12:43 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/05/01 12:12:43 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/05/01 12:12:43 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/05/01 12:12:43 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/05/01 12:11:53 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/01 09:41:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Desktop\What the Tech
[2011/04/30 18:40:24 | 000,000,000 | —D | C] – C:\DunhelCache
[2011/04/30 14:14:18 | 000,000,000 | —D | C] – C:\exorted_new_cache
[2011/04/24 14:11:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Ilivid Player
[2011/04/24 14:09:50 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{6A6F35C2-F1BB-455A-85C0-F522DF746DDA}
[2011/04/24 14:09:34 | 000,000,000 | —D | C] – C:\Program Files\iLivid
[2011/04/24 14:08:41 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/04/12 23:21:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\MetaGeek,_LLC
[2011/04/12 21:04:28 | 000,049,904 | R— | C] (Avanquest Software) – C:\WINDOWS\System32\drivers\BVRPMPR5.SYS
[2011/04/12 20:59:22 | 000,000,000 | —D | C] – C:\Netgear
[2011/04/12 12:23:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Application Data\BabylonToolbar
[2011/04/05 20:24:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\My Documents\EpicBot
[2011/04/05 20:23:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Yahoo
[2011/04/05 20:22:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\PackageAware
[2011/04/05 20:21:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2011/04/05 20:21:07 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2011/04/04 11:21:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\My Documents\BookSmartData
[2011/04/04 11:20:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\.blurb
[2011/04/04 11:19:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\BookSmart
[2011/04/04 11:18:21 | 000,000,000 | —D | C] – C:\Program Files\BookSmart
[2006/10/28 16:10:12 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.sys
[7 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/02 11:11:34 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job
[2011/05/02 09:33:43 | 000,445,604 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2011/05/02 09:33:43 | 000,072,810 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2011/05/02 09:30:27 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/05/02 09:29:30 | 000,000,164 | —- | M] () – C:\WINDOWS\System32\FppLicense3.ini
[2011/05/02 09:28:47 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2011/05/01 21:32:38 | 000,000,046 | —- | M] () – C:\Documents and Settings\Lee Edgar\jagex_runescape_preferences.dat
[2011/05/01 21:31:57 | 000,000,129 | —- | M] () – C:\Documents and Settings\Lee Edgar\jagex_runescape_preferences2.dat
[2011/05/01 20:28:53 | 003,676,648 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\renault megane 2 user manual.pdf
[2011/05/01 16:40:16 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2011/04/29 17:18:25 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2011/04/29 11:58:37 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/24 20:58:43 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/24 20:58:37 | 000,179,200 | —- | M] () – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/24 13:33:53 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/23 12:26:22 | 010,541,276 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\Lee.zip
[2011/04/22 21:57:18 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/04/20 21:36:09 | 000,110,120 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/04/19 07:42:10 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/04/18 15:34:05 | 000,000,742 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/18 15:34:05 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/16 11:01:37 | 000,001,601 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\esemee prices.rtf
[2011/04/16 03:46:56 | 000,446,904 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/16 03:28:48 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/15 09:08:51 | 002,359,681 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\Router manual.pdf
[2011/04/12 22:29:12 | 000,006,203 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\Router_Setup.html
[2011/04/12 17:39:31 | 000,000,640 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\TweetDeck.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\BookSmart.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BookSmart.lnk
[7 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/01 20:28:11 | 003,676,648 | —- | C] () – C:\Documents and Settings\Lee Edgar\My Documents\renault megane 2 user manual.pdf
[2011/05/01 12:12:43 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/05/01 12:12:43 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/05/01 12:12:43 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/05/01 12:12:43 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/05/01 12:12:43 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/04/18 15:34:05 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/04/18 15:34:05 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/16 11:01:37 | 000,001,601 | —- | C] () – C:\Documents and Settings\Lee Edgar\My Documents\esemee prices.rtf
[2011/04/15 09:08:51 | 002,359,681 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Router manual.pdf
[2011/04/12 22:29:14 | 000,000,172 | R— | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Router Login.url
[2011/04/12 22:29:11 | 000,006,203 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Router_Setup.html
[2011/04/12 17:39:31 | 000,000,640 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\TweetDeck.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\BookSmart.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BookSmart.lnk
[2011/02/28 18:45:32 | 000,057,845 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\Lee Edgar3SQLite3.dll
[2011/02/25 14:24:42 | 000,000,000 | —- | C] () – C:\WINDOWS\Protector Eclipse.ini
[2011/02/20 08:19:06 | 001,970,176 | —- | C] () – C:\WINDOWS\System32\d3dx9.dll
[2011/01/01 14:36:58 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2010/12/06 14:58:56 | 002,496,715 | —- | C] () – C:\WINDOWS\System32\abgx360.exe
[2010/09/08 15:57:47 | 000,000,053 | —- | C] () – C:\WINDOWS\webica.ini
[2010/06/13 17:39:17 | 000,000,125 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/03/19 09:02:26 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\FppLicense3.ini
[2010/03/19 09:01:51 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\fppent3a.dll
[2009/12/28 21:18:54 | 000,110,120 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/21 00:51:22 | 000,001,353 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2009/11/19 20:57:14 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\dm.ini
[2009/09/10 20:16:37 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/09/04 17:35:54 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2009/09/04 17:35:51 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2009/05/29 20:40:06 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2009/05/29 19:50:27 | 000,111,932 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2009/05/29 19:50:27 | 000,001,146 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2009/05/29 19:50:27 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2009/05/29 19:50:27 | 000,001,120 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2009/05/29 19:50:27 | 000,001,107 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2009/05/29 19:50:27 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009/05/29 19:50:27 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/05/29 19:50:26 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2009/05/29 19:50:26 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2009/05/29 19:50:26 | 000,026,154 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2009/05/29 19:50:26 | 000,024,903 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2009/05/29 19:50:26 | 000,021,390 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2009/05/29 19:50:26 | 000,020,148 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2009/05/29 19:50:26 | 000,011,811 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2009/05/29 19:50:26 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2009/05/29 19:50:26 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2009/05/29 19:50:26 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2009/05/29 19:50:26 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2009/05/29 19:50:26 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2009/05/29 19:45:51 | 000,000,025 | —- | C] () – C:\WINDOWS\CDE SX400DEFGIPS.ini
[2009/05/03 17:18:19 | 000,081,110 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/12/17 21:51:13 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/12/16 21:58:54 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/12/16 21:50:56 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLgFT.dll
[2008/05/15 19:40:21 | 000,163,840 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\fontdb.mdb
[2008/05/15 19:40:21 | 000,000,130 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/03/12 20:28:43 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/03/02 14:54:08 | 000,001,057 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\vso_ts_preview.xml
[2007/12/07 22:19:24 | 000,001,298 | —- | C] () – C:\WINDOWS\ARCHPR.INI
[2007/11/12 17:12:54 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2007/11/10 15:14:20 | 000,015,840 | —- | C] () – C:\WINDOWS\System32\Machnm1.exe
[2007/11/10 15:14:20 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2007/05/08 14:26:59 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/02/25 13:48:02 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2006/12/03 12:04:03 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat_BAK_13980
[2006/12/03 12:04:03 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat
[2006/10/28 16:10:13 | 000,087,608 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\ezpinst.exe
[2006/10/28 16:10:13 | 000,007,824 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.cat
[2006/10/28 16:10:12 | 000,001,144 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.inf
[2006/09/26 20:37:54 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2006/09/07 21:58:16 | 000,696,320 | —- | C] () – C:\Program Files\Common Files\XCMHook.dll
[2006/09/07 21:58:16 | 000,024,576 | —- | C] () – C:\Program Files\Common Files\XCPCMenu.exe
[2006/08/19 12:21:38 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/08/19 11:56:35 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/07/29 22:23:21 | 000,737,280 | —- | C] () – C:\WINDOWS\dbplugin.exe
[2006/07/29 22:23:20 | 000,933,888 | —- | C] () – C:\WINDOWS\npdbplug.dll
[2006/07/29 22:23:20 | 000,346,624 | —- | C] () – C:\WINDOWS\dwbreader.exe
[2006/07/25 22:57:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/07/11 21:05:58 | 000,278,528 | —- | C] () – C:\Program Files\Common Files\FDEUnInstaller.exe
[2006/06/11 14:52:50 | 000,118,784 | R— | C] () – C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe
[2006/05/09 19:46:51 | 000,118,784 | —- | C] () – C:\WINDOWS\ShowBmp.exe
[2006/05/09 19:46:51 | 000,001,325 | —- | C] () – C:\WINDOWS\Remove.ini
[2006/04/20 20:13:52 | 000,000,959 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/04/20 19:34:17 | 000,002,215 | —- | C] () – C:\WINDOWS\CDPR.INI
[2006/03/05 14:51:06 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/10/03 19:14:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/10/03 09:16:04 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/09/23 23:43:24 | 003,596,288 | R— | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/09/23 23:43:24 | 000,159,744 | R— | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/09/23 23:43:22 | 000,831,488 | R— | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/09/23 23:43:22 | 000,524,288 | R— | C] () – C:\WINDOWS\System32\divxsm.exe
[2005/09/23 23:43:22 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\dtu100.dll
[2005/05/11 21:46:12 | 000,001,001 | —- | C] () – C:\WINDOWS\psmplay.ini
[2005/05/10 19:57:48 | 000,000,559 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/05/10 18:31:07 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\ESICOMMN.DLL
[2005/02/23 18:37:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlsz.INI
[2005/01/07 23:06:34 | 000,077,824 | —- | C] () – C:\WINDOWS\pysoft_uninstaller.exe
[2004/10/30 10:52:37 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/10/06 17:40:55 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2004/09/16 14:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 14:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/09/09 17:43:14 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/03/10 22:44:19 | 000,179,200 | —- | C] () – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/03/02 23:17:34 | 000,445,604 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/03/02 23:17:34 | 000,072,810 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/03/02 23:17:20 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/03/02 23:17:05 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/03/02 23:06:12 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/03/09 21:31:04 | 000,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2002/09/03 10:05:08 | 000,446,904 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2002/09/03 09:56:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/08/29 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2002/08/29 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2002/08/29 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2002/08/29 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2002/08/29 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2002/08/29 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/08/29 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2000/06/29 17:24:14 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\drivers\DLPORTIO.SYS
[1996/04/03 20:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52B72A7C
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AFFC859A
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48A9EADC

< End of report >
Hi,

Quite a bit of remnants to be taken care of.

Please uninstall the following Programs using the Add/Remove Programs utility if they exist.
Windows iLivid Toolbar

Detailed steps below :-
On the Windows XP taskbar:
Click Start > Control Panel.
In the Control Panel window, double-click Add or Remove Programs.

===================================================

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Settings… button
  • Click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
    • Trace and log files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - prefs.js..browser.search.defaultengine: "Yahoo-Mp3Tube"
    FF - prefs.js..browser.search.defaultenginename: "Web Search"
    FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q="
    FF - prefs.js..browser.search.order.1: "Web Search"
    FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbarsearch.com/?tmp=toolbar_mp3tube_results&prt=pinballtb01ff&clid=591a699985204c28835e93a02489f74a&subid=&Keywords={searchTerms}"
    [2011/04/24 14:09:00 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
    [2010/12/14 13:27:53 | 000,001,215 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\Mp3Tube.xml
    [2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\SearchquWebSearch.xml
    [2011/01/22 16:36:49 | 000,001,583 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\web-search.xml
    [2010/12/13 13:36:54 | 000,002,035 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchddr.xml
    [2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DC59A0D4-0ED6-4A73-B356-1B977F2A7725} - No CLSID value found.
    O4 - HKCU..\Run: [LDM] File not found
    
    :Files
    c:\program files\Common Files\FDEUnInstaller.exe
    C:\Documents and Settings\Lee Edgar\Desktop\Radio decoders\BPcalc v1[1].0 .exe
    C:\Documents and Settings\Lee Edgar\Desktop\Radio decoders\Ford ALC.exe
    C:\Program Files\Halo Tool Box\Addons\screenies.exe
    C:\Program Files\Halo Tool Box\h3filmtools\MirageBETA.95.exe
    C:\Program Files\Orange\setup\Orange_icons.EXE
    C:\WINDOWS\dbplugin.ocx
    G:\dans stuff\Ebook.rar
    
    :Commands
    [EMPTYFLASH]
    [EMPTYTEMP]
    [CLEARALLRESTOREPOINTS]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script and( don't check the boxes beside LOP Check or Purity this time )
===================================================

On your next reply please post :
Fix OTL log
Fresh OTL log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
hi again

Uninstalled the program you asked and deleted the Java temp files without any problems

Had some trouble running the OTL fix - when it finished it did nothing and the computer became unstable, i left it for quite some time incase it was still running but it seemed to stop. Nothing seemed to be responding, I tried to close down OTL but it would not, I tried to click on Start> turn off computer > restart ………………………but it would not. I tried alt+ctrl+delete to launch task manger but it would not, I had to hold the power switch on the front of the machine to shut it down and restart.

It loaded back up normally so i ran the OTL fix again, This time it ran to the end and asked me to click on ok to reboot. I clicked and it shut down, it started up very very slowly i did not think it was going to dispaly anything but eventually after quite some time it loaded up. The 1st thing to pop up was OTL asking me if it was ok to launch i clicked on yes and it eventually produced the following log - i'm not sure if this was what you wanted and if this was what you expected ? Then ran OTL again and have posted log fo this.

Thanks ED

FIX LOG ??

All processes killed
========== OTL ==========
Prefs.js: "Yahoo-Mp3Tube" removed from browser.search.defaultengine
Prefs.js: "Web Search" removed from browser.search.defaultenginename
Prefs.js: "http://www.bing.com/search?FORM=IEFM1&q=" removed from browser.search.defaulturl
Prefs.js: "Web Search" removed from browser.search.order.1
Prefs.js: "http://mp3tubetoolbarsearch.com/?tmp=toolbar_mp3tube_results&prt=pinballtb01ff&clid=591a699985204c28835e93a02489f74a&subid=&Keywords={searchTerms}" removed from browser.search.selectedEngineURL
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\searchbar folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\options folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton\panels folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton\icons folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\uwa folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\radio\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\radio\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\radio folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default\scripts folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\scripts folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\skin folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\js folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2 folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\skin\scripts folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\skin\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\skin\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\skin folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\js folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.PPCBully folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\js folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\scripts folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\js folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\images folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\css folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2 folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\modules folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\lib folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\data\search folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\data folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} folder moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\Mp3Tube.xml moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\SearchquWebSearch.xml moved successfully.
C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\web-search.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchddr.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-A1FB-F862B587B57D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-A1FB-F862B587B57D}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DC59A0D4-0ED6-4A73-B356-1B977F2A7725} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DC59A0D4-0ED6-4A73-B356-1B977F2A7725}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\LDM deleted successfully.
========== FILES ==========
c:\program files\Common Files\FDEUnInstaller.exe moved successfully.
C:\Documents and Settings\Lee Edgar\Desktop\Radio decoders\BPcalc v1[1].0 .exe moved successfully.
C:\Documents and Settings\Lee Edgar\Desktop\Radio decoders\Ford ALC.exe moved successfully.
C:\Program Files\Halo Tool Box\Addons\screenies.exe moved successfully.
C:\Program Files\Halo Tool Box\h3filmtools\MirageBETA.95.exe moved successfully.
C:\Program Files\Orange\setup\Orange_icons.EXE moved successfully.
C:\WINDOWS\dbplugin.ocx moved successfully.
G:\dans stuff\Ebook.rar moved successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User
->Flash cache emptied: 56466 bytes

User: Guest
->Flash cache emptied: 41620 bytes

User: Lee Edgar
->Flash cache emptied: 2008982 bytes

User: LocalService

User: NetworkService

User: Owner

User: Suzanne Edgar

User: suzanne edgar.MAINCOMPUTER
->Flash cache emptied: 41620 bytes

Total Flash Files Cleaned = 2.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes

User: Lee Edgar
->Temp folder emptied: 125004288 bytes
->Temporary Internet Files folder emptied: 134110451 bytes
->Java cache emptied: 82096996 bytes
->FireFox cache emptied: 83062884 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->FireFox cache emptied: 3909690 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 65670 bytes

User: Owner

User: Suzanne Edgar
->Temporary Internet Files folder emptied: 0 bytes

User: suzanne edgar.MAINCOMPUTER
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 126128 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33726 bytes
RecycleBin emptied: 154552 bytes

Total Files Cleaned = 409.00 mb

Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.22.3 log created on 05022011_161336

Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\Lee Edgar\Local Settings\Temp\~DF7BDF.tmp not found!
File\Folder C:\Documents and Settings\Lee Edgar\Local Settings\Temp\~DF7C03.tmp not found!
File\Folder C:\Documents and Settings\Lee Edgar\Local Settings\Temp\~DF7CD5.tmp not found!
File\Folder C:\Documents and Settings\Lee Edgar\Local Settings\Temp\~DF7CF5.tmp not found!
File\Folder C:\Documents and Settings\Lee Edgar\Local Settings\Temp\~DF7D79.tmp not found!
File\Folder C:\Documents and Settings\Lee Edgar\Local Settings\Temp\~DF7D9F.tmp not found!
C:\Documents and Settings\Lee Edgar\Local Settings\Temporary Internet Files\Content.IE5\J2BHRKZH\index[2].htm moved successfully.
C:\Documents and Settings\Lee Edgar\Local Settings\Temporary Internet Files\Content.IE5\J2BHRKZH\like[1].htm moved successfully.
C:\Documents and Settings\Lee Edgar\Local Settings\Temporary Internet Files\Content.IE5\BYB5KM77\iframe[1].htm moved successfully.
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot…


NEW OTL LOG


OTL logfile created on: 02/05/2011 16:31:09 - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Lee Edgar\Desktop\What the Tech
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 250.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.45 Gb Total Space | 31.61 Gb Free Space | 42.45% Space Free | Partition Type: NTFS
Drive G: | 149.05 Gb Total Space | 125.26 Gb Free Space | 84.04% Space Free | Partition Type: NTFS

Computer Name: MAINCOMPUTER | User Name: Lee Edgar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Documents and Settings\Lee Edgar\Desktop\What the Tech\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\PrinterShare\paConsole.exe (PrinterAnywhere)
PRC - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)
PRC - C:\Program Files\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Lee Edgar\Desktop\What the Tech\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\Program Files\Unlocker\UnlockerHook.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SecureSrv) – File not found
SRV - (Pml Driver HPZ12) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (pdfFactory Pro Dispatcher v3) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (LBTServ) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (UxTuneUp) – C:\WINDOWS\SYSTEM32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (BVRPMPR5) – C:\WINDOWS\SYSTEM32\DRIVERS\BVRPMPR5.SYS (Avanquest Software)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (fssfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (nmwcd) – C:\WINDOWS\SYSTEM32\DRIVERS\ccdcmb.sys (Nokia)
DRV - (WinDriver6) – C:\WINDOWS\SYSTEM32\DRIVERS\windrvr6.sys (Jungo)
DRV - (LUsbFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouKE) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (LMouFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (L8042mou) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (L8042Kbd) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (PCANDIS5) – C:\WINDOWS\SYSTEM32\PCANDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (FilterService) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam E3500(UVC) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys ()
DRV - (pccsmcfd) – C:\WINDOWS\SYSTEM32\DRIVERS\pccsmcfd.sys (Nokia)
DRV - (s117obex) – C:\WINDOWS\SYSTEM32\DRIVERS\s117obex.sys (MCCI Corporation)
DRV - (s117mdm) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mdm.sys (MCCI Corporation)
DRV - (s117mgmt) Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mgmt.sys (MCCI Corporation)
DRV - (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117unic.sys (MCCI Corporation)
DRV - (s117nd5) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS) – C:\WINDOWS\SYSTEM32\DRIVERS\s117nd5.sys (MCCI Corporation)
DRV - (s117mdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mdfl.sys (MCCI Corporation)
DRV - (s117bus) Sony Ericsson Device 117 driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117bus.sys (MCCI Corporation)
DRV - (vaxscsi) – C:\WINDOWS\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (SE27mdm) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27mdm.sys (MCCI)
DRV - (SE27mdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27mdfl.sys (MCCI)
DRV - (SE27bus) Sony Ericsson Device 039 Driver driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27bus.sys (MCCI)
DRV - (LHidKe) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LHidUsbK) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidUsbK.sys (Logitech, Inc.)
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (Amps2prt) – C:\WINDOWS\SYSTEM32\DRIVERS\Amps2prt.sys (A4Tech Co.,Ltd.)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) – C:\WINDOWS\SYSTEM32\DRIVERS\alcan5wn.sys (THOMSON)
DRV - (alcaudsl) – C:\WINDOWS\SYSTEM32\DRIVERS\alcaudsl.sys (THOMSON)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (Machnm32) – C:\WINDOWS\SYSTEM32\Machnm32.sys ()
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (DCamUSBSQTECH) Dual-Mode DSC(2770) – C:\WINDOWS\SYSTEM32\DRIVERS\SQCaptur.sys (Service & Quality Technology.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (DLPortIO) – C:\WINDOWS\SYSTEM32\DRIVERS\DLPORTIO.SYS ()
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngineURL: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 44
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:[removed]
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {34EFA911-B536-4C08-BECE-CD5E55C875B0}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: {40a1f5d7-afc2-498f-b264-02668d616ff6}:1.1
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.1.3

FF - user.js..keyword.enabled: 1

FF - HKLM\software\mozilla\Firefox\extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010/04/15 23:15:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/18 15:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/24 13:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010/04/15 23:15:54 | 000,000,000 | —D | M]

[2011/04/24 14:09:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Extensions
[2011/05/02 16:13:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions
[2010/05/11 11:20:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/15 21:29:02 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/01/22 16:34:08 | 000,000,000 | —D | M] (Mega Manager Integration) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{40a1f5d7-afc2-498f-b264-02668d616ff6}
[2011/02/08 13:52:50 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/01/16 20:18:29 | 000,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/09/15 19:29:11 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/02/08 13:53:02 | 000,000,000 | —D | M] (Page Speed) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2011/01/18 20:28:06 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/03/30 17:43:52 | 000,000,000 | —D | M] (Babylon) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\[removed]
[2010/12/31 15:35:08 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\[removed]
[2011/04/18 15:39:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\staged
[2011/01/22 16:35:54 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\vshare@toolbar
[2010/05/14 15:53:24 | 000,001,819 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\bing.xml
[2011/04/24 14:09:21 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/15 08:58:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/05 17:44:12 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/26 10:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/19 12:33:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/24 20:14:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
[2010/05/15 08:57:36 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
[2011/03/18 18:57:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/03/30 17:43:56 | 000,002,428 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 09:00:00 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/05/01 16:40:16 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - No CLSID value found.
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] File not found
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [iKeyWorks] C:\Program Files\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [pdfFactory Pro Dispatcher v3] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)
O4 - HKCU..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [LDM] File not found
O4 - HKCU..\Run: [Mega Manager] C:\Program Files\Megaupload\Mega Manager\MegaManager.exe (Megaupload Limited)
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [PrinterShare] C:\Program Files\PrinterShare\paConsole.exe (PrinterAnywhere)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: securesuite.co.uk ([www] https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} http://pcpitstop.com/internet/pcpConnCheck.cab (iCC Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} http://launcher.station.sony.com/weblaunch…ebInstaller.cab (SonyOnlineInstallerX)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} https://secure.footprint.net/kingsisle/stat…ameLauncher.CAB (Wizard101GameLauncher)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} http://u3.sandisk.com/download/apps/LPInstaller.CAB (CInstallLPCtrl Object)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.microsoft.com/download/Pow…N-US/msorun.cab (IEAnimBehaviorFactory Class)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\bw+0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\offline-8876480 {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/02 16:13:36 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/02 09:15:29 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/05/02 06:55:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2011/05/01 20:31:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Media Get LLC
[2011/05/01 20:27:44 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/05/01 20:27:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\MediaGet2
[2011/05/01 12:12:43 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/05/01 12:12:43 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/05/01 12:12:43 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/05/01 12:12:43 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/05/01 12:11:53 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/01 09:41:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Desktop\What the Tech
[2011/04/30 18:40:24 | 000,000,000 | —D | C] – C:\DunhelCache
[2011/04/30 14:14:18 | 000,000,000 | —D | C] – C:\exorted_new_cache
[2011/04/24 14:11:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Ilivid Player
[2011/04/24 14:08:41 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/04/12 23:21:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\MetaGeek,_LLC
[2011/04/12 21:04:28 | 000,049,904 | R— | C] (Avanquest Software) – C:\WINDOWS\System32\drivers\BVRPMPR5.SYS
[2011/04/12 20:59:22 | 000,000,000 | —D | C] – C:\Netgear
[2011/04/12 12:23:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Application Data\BabylonToolbar
[2011/04/05 20:24:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\My Documents\EpicBot
[2011/04/05 20:23:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Yahoo
[2011/04/05 20:22:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\PackageAware
[2011/04/05 20:21:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2011/04/05 20:21:07 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2011/04/04 11:21:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\My Documents\BookSmartData
[2011/04/04 11:20:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\.blurb
[2011/04/04 11:19:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\BookSmart
[2011/04/04 11:18:21 | 000,000,000 | —D | C] – C:\Program Files\BookSmart
[2006/10/28 16:10:12 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011/05/02 16:29:41 | 000,445,604 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2011/05/02 16:29:41 | 000,072,810 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2011/05/02 16:26:52 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/05/02 16:25:24 | 000,000,164 | —- | M] () – C:\WINDOWS\System32\FppLicense3.ini
[2011/05/02 16:23:40 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2011/05/02 16:04:39 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/05/02 15:43:33 | 000,000,129 | —- | M] () – C:\Documents and Settings\Lee Edgar\jagex_runescape_preferences2.dat
[2011/05/02 15:40:32 | 000,000,046 | —- | M] () – C:\Documents and Settings\Lee Edgar\jagex_runescape_preferences.dat
[2011/05/02 11:11:34 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job
[2011/05/01 20:28:53 | 003,676,648 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\renault megane 2 user manual.pdf
[2011/05/01 16:40:16 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2011/04/29 17:18:25 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2011/04/29 11:58:37 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/24 20:58:43 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/24 20:58:37 | 000,179,200 | —- | M] () – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/24 13:33:53 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/23 12:26:22 | 010,541,276 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\Lee.zip
[2011/04/22 21:57:18 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/04/20 21:36:09 | 000,110,120 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/04/18 15:34:05 | 000,000,742 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/18 15:34:05 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/16 11:01:37 | 000,001,601 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\esemee prices.rtf
[2011/04/16 03:46:56 | 000,446,904 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/16 03:28:48 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/15 09:08:51 | 002,359,681 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\Router manual.pdf
[2011/04/12 22:29:12 | 000,006,203 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\Router_Setup.html
[2011/04/12 17:39:31 | 000,000,640 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\TweetDeck.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\BookSmart.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BookSmart.lnk

========== Files Created - No Company Name ==========

[2011/05/01 20:28:11 | 003,676,648 | —- | C] () – C:\Documents and Settings\Lee Edgar\My Documents\renault megane 2 user manual.pdf
[2011/05/01 12:12:43 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/05/01 12:12:43 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/05/01 12:12:43 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/05/01 12:12:43 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/05/01 12:12:43 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/04/18 15:34:05 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/04/18 15:34:05 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/16 11:01:37 | 000,001,601 | —- | C] () – C:\Documents and Settings\Lee Edgar\My Documents\esemee prices.rtf
[2011/04/15 09:08:51 | 002,359,681 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Router manual.pdf
[2011/04/12 22:29:14 | 000,000,172 | R— | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Router Login.url
[2011/04/12 22:29:11 | 000,006,203 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Router_Setup.html
[2011/04/12 17:39:31 | 000,000,640 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\TweetDeck.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\BookSmart.lnk
[2011/04/04 11:19:58 | 000,001,570 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BookSmart.lnk
[2011/02/28 18:45:32 | 000,057,845 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\Lee Edgar3SQLite3.dll
[2011/02/25 14:24:42 | 000,000,000 | —- | C] () – C:\WINDOWS\Protector Eclipse.ini
[2011/02/20 08:19:06 | 001,970,176 | —- | C] () – C:\WINDOWS\System32\d3dx9.dll
[2011/01/01 14:36:58 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2010/12/06 14:58:56 | 002,496,715 | —- | C] () – C:\WINDOWS\System32\abgx360.exe
[2010/09/08 15:57:47 | 000,000,053 | —- | C] () – C:\WINDOWS\webica.ini
[2010/06/13 17:39:17 | 000,000,125 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/03/19 09:02:26 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\FppLicense3.ini
[2010/03/19 09:01:51 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\fppent3a.dll
[2009/12/28 21:18:54 | 000,110,120 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/21 00:51:22 | 000,001,353 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2009/11/19 20:57:14 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\dm.ini
[2009/09/10 20:16:37 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/09/04 17:35:54 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2009/09/04 17:35:51 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2009/05/29 20:40:06 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2009/05/29 19:50:27 | 000,111,932 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2009/05/29 19:50:27 | 000,001,146 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2009/05/29 19:50:27 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2009/05/29 19:50:27 | 000,001,120 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2009/05/29 19:50:27 | 000,001,107 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2009/05/29 19:50:27 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009/05/29 19:50:27 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/05/29 19:50:26 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2009/05/29 19:50:26 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2009/05/29 19:50:26 | 000,026,154 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2009/05/29 19:50:26 | 000,024,903 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2009/05/29 19:50:26 | 000,021,390 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2009/05/29 19:50:26 | 000,020,148 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2009/05/29 19:50:26 | 000,011,811 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2009/05/29 19:50:26 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2009/05/29 19:50:26 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2009/05/29 19:50:26 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2009/05/29 19:50:26 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2009/05/29 19:50:26 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2009/05/29 19:45:51 | 000,000,025 | —- | C] () – C:\WINDOWS\CDE SX400DEFGIPS.ini
[2009/05/03 17:18:19 | 000,081,110 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/12/17 21:51:13 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/12/16 21:58:54 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/12/16 21:50:56 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLgFT.dll
[2008/05/15 19:40:21 | 000,163,840 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\fontdb.mdb
[2008/05/15 19:40:21 | 000,000,130 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/03/12 20:28:43 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/03/02 14:54:08 | 000,001,057 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\vso_ts_preview.xml
[2007/12/07 22:19:24 | 000,001,298 | —- | C] () – C:\WINDOWS\ARCHPR.INI
[2007/11/12 17:12:54 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2007/11/10 15:14:20 | 000,015,840 | —- | C] () – C:\WINDOWS\System32\Machnm1.exe
[2007/11/10 15:14:20 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2007/05/08 14:26:59 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/02/25 13:48:02 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2006/12/03 12:04:03 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat_BAK_13980
[2006/12/03 12:04:03 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat
[2006/10/28 16:10:13 | 000,087,608 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\ezpinst.exe
[2006/10/28 16:10:13 | 000,007,824 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.cat
[2006/10/28 16:10:12 | 000,001,144 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.inf
[2006/09/26 20:37:54 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2006/09/07 21:58:16 | 000,696,320 | —- | C] () – C:\Program Files\Common Files\XCMHook.dll
[2006/09/07 21:58:16 | 000,024,576 | —- | C] () – C:\Program Files\Common Files\XCPCMenu.exe
[2006/08/19 12:21:38 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/08/19 11:56:35 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/07/29 22:23:21 | 000,737,280 | —- | C] () – C:\WINDOWS\dbplugin.exe
[2006/07/29 22:23:20 | 000,933,888 | —- | C] () – C:\WINDOWS\npdbplug.dll
[2006/07/29 22:23:20 | 000,346,624 | —- | C] () – C:\WINDOWS\dwbreader.exe
[2006/07/25 22:57:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/06/11 14:52:50 | 000,118,784 | R— | C] () – C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe
[2006/05/09 19:46:51 | 000,118,784 | —- | C] () – C:\WINDOWS\ShowBmp.exe
[2006/05/09 19:46:51 | 000,001,325 | —- | C] () – C:\WINDOWS\Remove.ini
[2006/04/20 20:13:52 | 000,000,959 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/04/20 19:34:17 | 000,002,215 | —- | C] () – C:\WINDOWS\CDPR.INI
[2006/03/05 14:51:06 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/10/03 19:14:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/10/03 09:16:04 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/09/23 23:43:24 | 003,596,288 | R— | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/09/23 23:43:24 | 000,159,744 | R— | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/09/23 23:43:22 | 000,831,488 | R— | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/09/23 23:43:22 | 000,524,288 | R— | C] () – C:\WINDOWS\System32\divxsm.exe
[2005/09/23 23:43:22 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\dtu100.dll
[2005/05/11 21:46:12 | 000,001,001 | —- | C] () – C:\WINDOWS\psmplay.ini
[2005/05/10 19:57:48 | 000,000,559 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/05/10 18:31:07 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\ESICOMMN.DLL
[2005/02/23 18:37:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlsz.INI
[2005/01/07 23:06:34 | 000,077,824 | —- | C] () – C:\WINDOWS\pysoft_uninstaller.exe
[2004/10/30 10:52:37 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/10/06 17:40:55 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2004/09/16 14:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 14:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/09/09 17:43:14 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/03/10 22:44:19 | 000,179,200 | —- | C] () – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/03/02 23:17:34 | 000,445,604 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/03/02 23:17:34 | 000,072,810 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/03/02 23:17:20 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/03/02 23:17:05 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/03/02 23:06:12 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/03/09 21:31:04 | 000,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2002/09/03 10:05:08 | 000,446,904 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2002/09/03 09:56:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/08/29 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2002/08/29 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2002/08/29 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2002/08/29 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2002/08/29 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2002/08/29 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/08/29 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2000/06/29 17:24:14 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\drivers\DLPORTIO.SYS
[1996/04/03 20:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52B72A7C
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AFFC859A
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48A9EADC

< End of report >
The computer Seems to boot fine now it was just when I ran the OTL fix that it went very slow. I think you are correct regarding spyware guard as every time I run OTL a window pops up from spyware saying a program is trying to change my ie home page and should I let it of not. Each time I just close the warning down.
Can you identify what the program is and the website link that it is trying to set? The program that I asked you to uninstall still appears to be there, so I just want to make sure.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI