Aylyese
Topic Starter
Thank you to my helper.
OTL logfile created on: 18/03/2012 7:54:37 PM - Run 1 OTL by OldTimer - Version 3.2.39.1 Folder = C:\Users\Margarita\Downloads 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy 3.75 Gb Total Physical Memory | 2.77 Gb Available Physical Memory | 74.03% Memory free 7.49 Gb Paging File | 6.50 Gb Available in Paging File | 86.78% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 360.94 Gb Total Space | 284.29 Gb Free Space | 78.77% Space Free | Partition Type: NTFS Drive D: | 4.26 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF Computer Name: MARGARITA-LAP | User Name: Margarita | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Margarita\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (Wajam) PRC - C:\Users\Margarita\AppData\Local\RavenBleuSA\bin\1.0.11.0\RavenBleuSA.exe () PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) ========== Modules (No Company Name) ========== MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll () MOD - C:\Users\Margarita\AppData\Roaming\Mozilla\Firefox\Profiles\bxsj0jx0.default\extensions\{2d922b81-34c7-4aab-9c5d-433e79fc9445}\components\RadioWMPCoreGecko10.dll () MOD - c:\Users\Margarita\AppData\Local\RavenBleuSA\bin\1.0.11.0\RavenBleuSAHook.dll () MOD - C:\Users\Margarita\AppData\Local\RavenBleuSA\bin\1.0.11.0\RavenBleuSA.exe () ========== Win32 Services (SafeList) ========== SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SRV - (WajamUpdater) – C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (Wajam) SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.) SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp) DRV:64bit: - (RTL8187Se) – C:\Windows\SysNative\drivers\RTL8187Se.sys (Realtek Semiconductor Corporation ) DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation ) DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com.au/ [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?AF=108714&b...000701a0429e9cc IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 01 E4 F0 F7 D8 F5 CC 01 [binary data] IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}...amp;FORM=IE8SRC IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}...000701a0429e9cc IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)" FF - prefs.js..browser.search.defaultthis.engineName: "LokeBar Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3177532&SearchSource;=3&q;={searchTerms}" FF - prefs.js..browser.search.order.1: "Search the web (Babylon)" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?AF=108714&babsrc;=HP_ss&mntrId;=e6ecb9fd000000000000701a0429e9cc" FF - prefs.js..network.proxy.type: 0 FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/03 00:42:33 | 000,000,000 | —D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/04 16:16:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Margarita\AppData\Roaming\Mozilla\Extensions [2012/03/03 00:41:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Margarita\AppData\Roaming\Mozilla\Firefox\Profiles\bxsj0jx0.default\extensions [2012/02/07 17:34:03 | 000,000,000 | —D | M] (LokeBar Community Toolbar) – C:\Users\Margarita\AppData\Roaming\Mozilla\Firefox\Profiles\bxsj0jx0.default\extensions\{2d922b81-34c7-4aab-9c5d-433e79fc9445} [2012/03/03 00:41:37 | 000,000,000 | —D | M] (Babylon) – C:\Users\Margarita\AppData\Roaming\Mozilla\Firefox\Profiles\bxsj0jx0.default\extensions\[removed] [2012/01/31 21:08:26 | 000,000,917 | —- | M] () – C:\Users\Margarita\AppData\Roaming\Mozilla\Firefox\Profiles\bxsj0jx0.default\searchplugins\conduit.xml [2012/03/03 00:54:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions [2012/03/03 00:54:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} () (No name found) – C:\USERS\MARGARITA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BXSJ0JX0.DEFAULT\EXTENSIONS\{5A95A9E0-59DD-4314-BD84-4D18CA83A0E2}.XPI [2012/03/03 00:42:33 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012/03/03 00:41:37 | 000,002,310 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml [2012/03/03 00:42:30 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012/03/03 00:42:30 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml O1 HOSTS File: ([2009/06/11 07:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\wajam.dll (Wajam) O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.) O4 - HKCU..\Run: [RavenBleuSA] C:\Users\Margarita\AppData\Local\RavenBleuSA\bin\1.0.11.0\RavenBleuSA.exe () O4 - Startup: C:\Users\Margarita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files (x86)\Xfire\xfire.exe (Xfire Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_30) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed] O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{46FF88D9-06D4-4440-A638-C47F987CDDBF}: DhcpNameServer = [removed] [removed] [removed] O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ] O32 - AutoRun File - [2007/01/24 09:48:51 | 000,000,041 | R— | M] () - D:\autorun.inf – [ UDF ] O33 - MountPoints2\{8e1b6cb8-23b5-11e1-9f85-00262240f6b7}\Shell - "" = AutoRun O33 - MountPoints2\{8e1b6cb8-23b5-11e1-9f85-00262240f6b7}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O33 - MountPoints2\{df4a1ba0-05e3-11e1-b53d-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{df4a1ba0-05e3-11e1-b53d-806e6f6e6963}\Shell\AutoRun\command - "" = D:\launch.exe – [2004/10/22 08:38:02 | 000,126,976 | R— | M] (Macrovision Corporation) O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] – "%1" %* O35:64bit: - HKLM\..exefile [open] – "%1" %* O35 - HKLM\..comfile [open] – "%1" %* O35 - HKLM\..exefile [open] – "%1" %* O37:64bit: - HKLM\…com [@ = comfile] – "%1" %* O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %* O37 - HKLM\…com [@ = comfile] – "%1" %* O37 - HKLM\…exe [@ = exefile] – "%1" %* NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012/03/18 17:53:14 | 000,000,000 | —D | C] – C:\Users\Margarita\Desktop\harry [2012/03/15 18:21:40 | 000,000,000 | —D | C] – C:\Users\Margarita\Desktop\gohan [2012/03/15 15:35:51 | 000,000,000 | —D | C] – C:\Users\Margarita\Desktop\powder-71.3-win32 [2012/03/14 19:02:36 | 000,000,000 | —D | C] – C:\Users\Margarita\Desktop\dragon age franter [2012/03/07 01:25:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ [2012/03/07 01:25:34 | 000,000,000 | –SD | C] – C:\Program Files (x86)\Xfire [2012/03/07 01:25:34 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\Xfire [2012/03/07 01:25:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire [2012/03/07 01:24:45 | 001,060,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc71.dll [2012/03/07 01:17:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\THQ [2012/03/07 00:22:30 | 000,000,000 | —D | C] – C:\Users\Margarita\Desktop\Project3 [2012/03/03 00:54:55 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll [2012/03/03 00:54:55 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe [2012/03/03 00:54:55 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe [2012/03/03 00:54:55 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe [2012/03/03 00:42:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2012/03/03 00:42:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\7-Zip [2012/03/03 00:41:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\PricePeep [2012/03/03 00:41:15 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\blinkx beat [2012/03/03 00:41:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Blinkx [2012/03/03 00:40:43 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\RavenBleuSA [2012/03/03 00:40:25 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\Wajam [2012/03/03 00:40:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wajam [2012/02/17 20:13:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton PC Checkup [2012/02/17 20:13:59 | 000,000,000 | —D | C] – C:\ProgramData\Norton [2012/02/17 20:13:57 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller [2012/02/17 20:13:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller ========== Files - Modified Within 30 Days ========== [2012/03/18 19:32:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat [2012/03/18 17:53:06 | 000,001,890 | -HS- | M] () – C:\ProgramData\KGyGaAvL.sys [2012/03/18 17:33:59 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/03/18 17:33:59 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/03/18 17:33:16 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI [2012/03/18 17:33:16 | 000,619,642 | —- | M] () – C:\Windows\SysNative\perfh009.dat [2012/03/18 17:33:16 | 000,107,792 | —- | M] () – C:\Windows\SysNative\perfc009.dat [2012/03/18 17:30:47 | 000,000,356 | —- | M] () – C:\Users\Margarita\Desktop\powder.pref [2012/03/18 17:28:46 | 3018,608,640 | -HS- | M] () – C:\hiberfil.sys [2012/03/17 10:37:41 | 000,421,820 | —- | M] () – C:\Users\Margarita\Desktop\gohan.exe [2012/03/16 20:19:45 | 000,000,767 | —- | M] () – C:\Users\Margarita\Desktop\Dark - Shortcut.lnk [2012/03/16 20:16:22 | 000,000,776 | —- | M] () – C:\Users\Margarita\Desktop\gohan - Shortcut.lnk [2012/03/15 18:16:44 | 000,001,131 | —- | M] () – C:\Users\Margarita\Desktop\RPG Maker VX.lnk [2012/03/07 01:32:05 | 000,002,133 | —- | M] () – C:\Users\Public\Desktop\Titan Quest - Immortal Throne.lnk [2012/03/07 01:25:45 | 000,002,042 | —- | M] () – C:\Users\Public\Desktop\Titan Quest.lnk [2012/03/07 01:25:34 | 000,001,010 | —- | M] () – C:\Users\Margarita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk [2012/03/07 01:25:34 | 000,000,998 | —- | M] () – C:\Users\Margarita\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk [2012/03/07 01:25:34 | 000,000,974 | —- | M] () – C:\Users\Public\Desktop\Xfire.lnk [2012/03/03 00:54:47 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll [2012/03/03 00:54:47 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe [2012/03/03 00:54:47 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe [2012/03/03 00:54:47 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe [2012/03/03 00:41:52 | 000,000,237 | —- | M] () – C:\user.js [2012/02/28 15:51:49 | 000,002,152 | —- | M] () – C:\Users\Margarita\Desktop\Age of Mythology - The Titans Expansion.lnk ========== Files Created - No Company Name ========== [2012/03/17 10:37:41 | 000,421,820 | —- | C] () – C:\Users\Margarita\Desktop\gohan.exe [2012/03/16 20:19:45 | 000,000,767 | —- | C] () – C:\Users\Margarita\Desktop\Dark - Shortcut.lnk [2012/03/16 20:16:22 | 000,000,776 | —- | C] () – C:\Users\Margarita\Desktop\gohan - Shortcut.lnk [2012/03/15 18:16:44 | 000,001,131 | —- | C] () – C:\Users\Margarita\Desktop\RPG Maker VX.lnk [2012/03/15 18:02:38 | 000,000,356 | —- | C] () – C:\Users\Margarita\Desktop\powder.pref [2012/03/07 01:32:04 | 000,002,133 | —- | C] () – C:\Users\Public\Desktop\Titan Quest - Immortal Throne.lnk [2012/03/07 01:25:44 | 000,002,042 | —- | C] () – C:\Users\Public\Desktop\Titan Quest.lnk [2012/03/07 01:25:34 | 000,001,010 | —- | C] () – C:\Users\Margarita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk [2012/03/07 01:25:34 | 000,000,998 | —- | C] () – C:\Users\Margarita\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk [2012/03/07 01:25:34 | 000,000,974 | —- | C] () – C:\Users\Public\Desktop\Xfire.lnk [2012/03/07 01:24:45 | 000,040,960 | R— | C] () – C:\Windows\SysWow64\psfind.dll [2012/03/03 00:41:52 | 000,000,237 | —- | C] () – C:\user.js [2012/02/28 15:51:49 | 000,002,152 | —- | C] () – C:\Users\Margarita\Desktop\Age of Mythology - The Titans Expansion.lnk [2011/12/11 20:16:24 | 000,001,890 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys [2011/12/11 20:16:24 | 000,000,088 | RHS- | C] () – C:\ProgramData\DDFA8AB85C.sys [2011/11/03 16:22:40 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin [2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat ========== LOP Check ========== [2012/02/14 16:40:23 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\.minecraft [2012/02/14 18:28:09 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\Babylon [2011/12/19 09:18:52 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\BitLord [2011/12/11 20:08:17 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\Python-Eggs [2011/12/06 18:19:53 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\Ubisoft [2009/07/14 15:08:49 | 000,017,992 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* > [2009/06/11 07:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat [2009/07/14 11:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr [2011/11/04 11:19:01 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK [2009/06/11 07:42:20 | 000,000,010 | —- | M] () – C:\config.sys [2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt [2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt [2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt [2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt [2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt [2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt [2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt [2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt [2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt [2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini [2012/03/18 17:28:46 | 3018,608,640 | -HS- | M] () – C:\hiberfil.sys [2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe [2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini [2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll [2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll [2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll [2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll [2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll [2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll [2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll [2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll [2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll [2012/03/18 17:28:53 | 4024,811,520 | -HS- | M] () – C:\pagefile.sys [2012/03/03 00:41:52 | 000,000,237 | —- | M] () – C:\user.js [2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp [2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab [2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI [2011/11/03 17:42:02 | 000,171,136 | RHS- | M] () – C:\w7ldr < %systemroot%\Fonts\*.com > [2009/07/14 15:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont [2009/07/14 15:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont [2009/07/14 15:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont [2009/07/14 15:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont < %systemroot%\Fonts\*.dll > < %systemroot%\Fonts\*.ini > [2009/06/11 06:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini < %systemroot%\Fonts\*.ini2 > < %systemroot%\Fonts\*.exe > < %systemroot%\system32\spool\prtprocs\w32x86\*.* > < %systemroot%\REPAIR\*.bak1 > < %systemroot%\REPAIR\*.ini > < %systemroot%\system32\*.jpg > < %systemroot%\*.jpg > < %systemroot%\*.png > < %systemroot%\*.scr > < %systemroot%\*._sy > < %APPDATA%\Adobe\Update\*.* > < %ALLUSERSPROFILE%\Favorites\*.* > < %APPDATA%\Microsoft\*.* > < %PROGRAMFILES%\*.* > [2009/07/14 14:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini < %APPDATA%\Update\*.* > < %systemroot%\*. /mp /s > < %systemroot%\System32\config\*.sav > < %PROGRAMFILES%\bak. /s > < %systemroot%\system32\bak. /s > < %ALLUSERSPROFILE%\Start Menu\*.lnk /x > < %systemroot%\system32\config\systemprofile\*.dat /x > < %systemroot%\*.config > < %systemroot%\system32\*.db > < %PROGRAMFILES%\Internet Explorer\*.dat > < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x > [2011/11/03 16:54:52 | 000,000,221 | -HS- | M] () – C:\Users\Margarita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini < %USERPROFILE%\Desktop\*.exe > [2001/11/21 01:03:08 | 000,788,480 | —- | M] () – C:\Users\Margarita\Desktop\D2Editor.exe [2012/03/17 10:37:41 | 000,421,820 | —- | M] () – C:\Users\Margarita\Desktop\gohan.exe [2012/01/29 18:05:46 | 001,721,856 | —- | M] () – C:\Users\Margarita\Desktop\Powder-legacy.exe [2012/01/29 18:05:16 | 001,733,632 | —- | M] () – C:\Users\Margarita\Desktop\Powder.exe < %PROGRAMFILES%\Common Files\*.* > < %systemroot%\*.src > < %systemroot%\install\*.* > < %systemroot%\system32\DLL\*.* > < %systemroot%\system32\HelpFiles\*.* > < %systemroot%\system32\rundll\*.* > < %systemroot%\winn32\*.* > < %systemroot%\Java\*.* > < %systemroot%\system32\test\*.* > < %systemroot%\system32\Rundll32\*.* > < %systemroot%\AppPatch\Custom\*.* > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > < End of report >
OTL Extras logfile created on: 18/03/2012 7:54:37 PM - Run 1 OTL by OldTimer - Version 3.2.39.1 Folder = C:\Users\Margarita\Downloads 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy 3.75 Gb Total Physical Memory | 2.77 Gb Available Physical Memory | 74.03% Memory free 7.49 Gb Paging File | 6.50 Gb Available in Paging File | 86.78% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 360.94 Gb Total Space | 284.29 Gb Free Space | 78.77% Space Free | Partition Type: NTFS Drive D: | 4.26 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF Computer Name: MARGARITA-LAP | User Name: Margarita | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] – "%1" %* cmdfile [open] – "%1" %* comfile [open] – "%1" %* exefile [open] – "%1" %* helpfile [open] – Reg Error: Key error. htmlfile [edit] – Reg Error: Key error. htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] – "%1" %* regfile [merge] – Reg Error: Key error. scrfile [config] – "%1" scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] – "%1" /S txtfile [edit] – Reg Error: Key error. Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] – Reg Error: Value error. Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] – "%1" %* cmdfile [open] – "%1" %* comfile [open] – "%1" %* cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] – "%1" %* helpfile [open] – Reg Error: Key error. htmlfile [edit] – Reg Error: Key error. htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] – "%1" %* regfile [merge] – Reg Error: Key error. scrfile [config] – "%1" scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] – "%1" /S txtfile [edit] – Reg Error: Key error. Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] – Reg Error: Value error. Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser "{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™ "{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30 "{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion "{412B69AF-C352-4F6F-A318-B92B3CB9ACC6}" = Titan Quest "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace "{4D530FA3-9B89-4186-98B7-F51000008100}" = Age of Empires Online "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable "{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{B5C5C17E-FEF6-4062-8151-A427AE8AF9D7}" = Titan Quest Immortal Throne "{E24A0015-C73F-4B57-B8DF-5EB84D2E9685}" = Adobe Flash Player 10 ActiveX "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "7-Zip" = 7-Zip 9.20 "Age of Mythology 1.0" = Age of Mythology "Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion "BabylonToolbar" = Babylon toolbar on IE "BitLord" = BitLord 2.0 "GameSpy Arcade" = GameSpy Arcade "GFWL_{4D530FA3-9B89-4186-98B7-F51000008100}" = Age of Empires Online "McAfee Security Scan" = McAfee Security Scan Plus "Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US) "PricePeep" = PricePeep for FireFox "RPG Maker VX RTP_is1" = RPG Maker VX RTP "RPG Maker VX_is1" = RPG Maker VX "Xfire" = Xfire (remove only) "Ycopy_is1" = Ycopy 1.0d ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "blinkx beat" = blinkx beat "RavenBleuSA" = RavenBleu "Wajam" = Wajam ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 8/03/2012 2:39:55 AM | Computer Name = Margarita-Lap | Source = Application Error | ID = 1000 Description = Faulting application name: RavenBleuSACB.exe, version: 1.0.11.0, time stamp: 0x4ed3f301 Faulting module name: Flash10x.ocx, version: 10.3.183.10, time stamp: 0x4e764622 Exception code: 0xc0000005 Fault offset: 0x0042be31 Faulting process id: 0x414 Faulting application start time: 0x01ccfcf61b2a20f8 Faulting application path: C:\Users\Margarita\AppData\Local\RavenBleuSA\bin\1.0.11.0\RavenBleuSACB.exe Faulting module path: C:\Windows\SysWOW64\Macromed\Flash\Flash10x.ocx Report Id: 83d04793-68e9-11e1-9473-00262240f6b7 Error - 9/03/2012 1:27:39 AM | Computer Name = Margarita-Lap | Source = Application Hang | ID = 1002 Description = The program Explorer.EXE version 6.1.7600.16385 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 648 Start Time: 01ccfdb4e5f925eb Termination Time: 940 Application Path: C:\Windows\Explorer.EXE Report Id: 898b0175-69a8-11e1-ab5b-00262240f6b7 Error - 9/03/2012 7:23:23 PM | Computer Name = Margarita-Lap | Source = Application Error | ID = 1000 Description = Faulting application name: aom.exe, version: 3.2002.10.700, time stamp: 0x21544c66 Faulting module name: d3d8.dll, version: 6.1.7600.16385, time stamp: 0x4a5bd9a7 Exception code: 0xc0000005 Fault offset: 0x0001b264 Faulting process id: 0xf94 Faulting application start time: 0x01ccfde36bd83061 Faulting application path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\aom.exe Faulting module path: C:\Windows\system32\d3d8.dll Report Id: dd32dce4-6a3e-11e1-ab5b-00262240f6b7 Error - 9/03/2012 7:23:29 PM | Computer Name = Margarita-Lap | Source = Application Error | ID = 1000 Description = Faulting application name: aom.exe, version: 3.2002.10.700, time stamp: 0x21544c66 Faulting module name: d3d8.dll, version: 6.1.7600.16385, time stamp: 0x4a5bd9a7 Exception code: 0xc0000005 Fault offset: 0x0001b264 Faulting process id: 0xf94 Faulting application start time: 0x01ccfde36bd83061 Faulting application path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\aom.exe Faulting module path: C:\Windows\system32\d3d8.dll Report Id: e089b187-6a3e-11e1-ab5b-00262240f6b7 Error - 9/03/2012 8:14:14 PM | Computer Name = Margarita-Lap | Source = Application Error | ID = 1000 Description = Faulting application name: moviePlayer.exe, version: 0.0.0.0, time stamp: 0x3d9a40ff Faulting module name: binkw32.dll, version: 1.5.10.0, time stamp: 0x3d189f64 Exception code: 0xc0000005 Fault offset: 0x00010338 Faulting process id: 0xa74 Faulting application start time: 0x01ccfe52a3eaee26 Faulting application path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\moviePlayer.exe Faulting module path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\binkw32.dll Report Id: f77e49f1-6a45-11e1-ab5b-00262240f6b7 Error - 10/03/2012 8:33:50 PM | Computer Name = Margarita-Lap | Source = Application Error | ID = 1000 Description = Faulting application name: moviePlayer.exe, version: 0.0.0.0, time stamp: 0x3d9a40ff Faulting module name: binkw32.dll, version: 1.5.10.0, time stamp: 0x3d189f64 Exception code: 0xc0000005 Fault offset: 0x00010338 Faulting process id: 0x968 Faulting application start time: 0x01ccff1e8b5412c5 Faulting application path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\moviePlayer.exe Faulting module path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\binkw32.dll Report Id: df1bc438-6b11-11e1-98b7-00262240f6b7 Error - 13/03/2012 3:04:55 AM | Computer Name = Margarita-Lap | Source = Application Error | ID = 1000 Description = Faulting application name: moviePlayer.exe, version: 0.0.0.0, time stamp: 0x3d9a40ff Faulting module name: binkw32.dll, version: 1.5.10.0, time stamp: 0x3d189f64 Exception code: 0xc0000005 Fault offset: 0x00010338 Faulting process id: 0xa14 Faulting application start time: 0x01cd00e780c45ecf Faulting application path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\moviePlayer.exe Faulting module path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\binkw32.dll Report Id: d6079063-6cda-11e1-a737-00262240f6b7 Error - 14/03/2012 2:10:01 AM | Computer Name = Margarita-Lap | Source = Application Error | ID = 1000 Description = Faulting application name: aomx.exe, version: 4.2003.9.200, time stamp: 0x21544c66 Faulting module name: d3d8.dll, version: 6.1.7600.16385, time stamp: 0x4a5bd9a7 Exception code: 0xc0000005 Fault offset: 0x0001b264 Faulting process id: 0x9a0 Faulting application start time: 0x01cd00e7802b9fc2 Faulting application path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\aomx.exe Faulting module path: C:\Windows\system32\d3d8.dll Report Id: 54fe2c86-6d9c-11e1-a737-00262240f6b7 Error - 14/03/2012 7:00:37 AM | Computer Name = Margarita-Lap | Source = Application Error | ID = 1000 Description = Faulting application name: aomx.exe, version: 4.2003.9.200, time stamp: 0x21544c66 Faulting module name: d3d8.dll, version: 6.1.7600.16385, time stamp: 0x4a5bd9a7 Exception code: 0xc0000005 Fault offset: 0x0001b264 Faulting process id: 0xb70 Faulting application start time: 0x01cd01c926d2dc56 Faulting application path: C:\Program Files (x86)\Microsoft Games\Age of Mythology\aomx.exe Faulting module path: C:\Windows\system32\d3d8.dll Report Id: ed53c36c-6dc4-11e1-a737-00262240f6b7 Error - 15/03/2012 3:28:38 AM | Computer Name = Margarita-Lap | Source = Application Error | ID = 1000 Description = Faulting application name: RavenBleuSACB.exe, version: 1.0.11.0, time stamp: 0x4ed3f301 Faulting module name: Flash10x.ocx, version: 10.3.183.10, time stamp: 0x4e764622 Exception code: 0xc0000005 Fault offset: 0x0042be31 Faulting process id: 0x170 Faulting application start time: 0x01cd027d3620e6c3 Faulting application path: C:\Users\Margarita\AppData\Local\RavenBleuSA\bin\1.0.11.0\RavenBleuSACB.exe Faulting module path: C:\Windows\SysWOW64\Macromed\Flash\Flash10x.ocx Report Id: 7ae02ef1-6e70-11e1-be1f-00262240f6b7 [ System Events ] Error - 11/03/2012 3:30:00 AM | Computer Name = Margarita-Lap | Source = NetBT | ID = 4321 Description = The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.0.14. The computer with the IP address 192.168.0.16 did not allow the name to be claimed by this computer. Error - 11/03/2012 3:59:18 AM | Computer Name = Margarita-Lap | Source = EventLog | ID = 6008 Description = The previous system shutdown at 5:57:36 PM on ?11/?03/?2012 was unexpected. Error - 13/03/2012 1:26:34 AM | Computer Name = Margarita-Lap | Source = NetBT | ID = 4321 Description = The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.0.14. The computer with the IP address 192.168.0.16 did not allow the name to be claimed by this computer. Error - 13/03/2012 5:22:17 AM | Computer Name = Margarita-Lap | Source = NetBT | ID = 4321 Description = The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.0.14. The computer with the IP address 192.168.0.16 did not allow the name to be claimed by this computer. Error - 15/03/2012 12:50:17 AM | Computer Name = Margarita-Lap | Source = EventLog | ID = 6008 Description = The previous system shutdown at 9:49:27 PM on ?14/?03/?2012 was unexpected. Error - 15/03/2012 1:43:21 AM | Computer Name = Margarita-Lap | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk1\DR1. Error - 15/03/2012 1:43:23 AM | Computer Name = Margarita-Lap | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk1\DR1. Error - 16/03/2012 3:00:09 AM | Computer Name = Margarita-Lap | Source = EventLog | ID = 6008 Description = The previous system shutdown at 4:58:42 PM on ?16/?03/?2012 was unexpected. Error - 18/03/2012 3:28:53 AM | Computer Name = Margarita-Lap | Source = EventLog | ID = 6008 Description = The previous system shutdown at 6:01:38 PM on ?17/?03/?2012 was unexpected. Error - 18/03/2012 5:33:18 AM | Computer Name = Margarita-Lap | Source = NetBT | ID = 4321 Description = The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.0.17. The computer with the IP address 192.168.0.16 did not allow the name to be claimed by this computer. < End of report >