0

Hey. I keep getting AVG popping up with a message that tells me that cookies.sqlite in the Firefox folder of my Document and Settings, within Application Data, folder is infected. I've followed the sticky and here are the results:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

02/04/2011 19:39:41
mbam-log-2011-04-02 (19-39-41).txt

Scan type: Full scan (C:\|)
Objects scanned: 224292
Time elapsed: 1 hour(s), 56 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


GMER 1.0.15.15570 - http://www.gmer.net
Rootkit quick scan 2011-04-02 16:49:20
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 WDC_WD740GD-00FLA0 rev.21.08U21
Running: 7327fcpt.exe; Driver: C:\DOCUME~1\Waka\LOCALS~1\Temp\fxtdqpob.sys


---- System - GMER 1.0.15 ----

SSDT spjc.sys ZwEnumerateKey [0xB7ECDDA4]
SSDT spjc.sys ZwEnumerateValueKey [0xB7ECE132]

---- Devices - GMER 1.0.15 ----

Device \Driver\atapi \Device\Ide\IdePort0 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\aekhnxez \Device\Scsi\aekhnxez1 898181F8
Device \Driver\aekhnxez \Device\Scsi\aekhnxez1Port5Path0Target0Lun0 898181F8
Device \Driver\mv61xx \Device\Scsi\mv61xx1Port4Path0Target14Lun0 8A71E1F8
Device \Driver\mv61xx \Device\Scsi\mv61xx1 8A71E1F8
Device \FileSystem\Ntfs \Ntfs 8A7901F8

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

Device \FileSystem\Fastfat \Fat 893DF500

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

---- EOF - GMER 1.0.15 ----


GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-02 19:39:03
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 WDC_WD740GD-00FLA0 rev.21.08U21
Running: 7327fcpt.exe; Driver: C:\DOCUME~1\Waka\LOCALS~1\Temp\fxtdqpob.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0xB42ED534]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0xB42E7782]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateKey [0xB43066DC]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0xB42EDCC0]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcess [0xB4300EB4]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0xB43012A2]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateSection [0xB430A916]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xB42EDDF6]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xB42E8398]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteKey [0xB4307FE4]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0xB430793C]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0xB42FFDF0]
SSDT spjc.sys ZwEnumerateKey [0xB7ECDDA4]
SSDT spjc.sys ZwEnumerateValueKey [0xB7ECE132]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0xB430893C]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xB4308B44]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0xB42E7FAA]
SSDT spjc.sys ZwOpenKey [0xB7EB50C0]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xB2E3A6C0]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenThread [0xB4302DF8]
SSDT spjc.sys ZwQueryKey [0xB7ECE20A]
SSDT spjc.sys ZwQueryValueKey [0xB7ECE08A]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0xB43098D2]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0xB4309208]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xB42ED0F4]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0xB430A2A4]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0xB42ED7DC]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xB42E875C]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0xB4309E12]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetValueKey [0xB43070C4]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0xB4301F0A]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xB2E3A770]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xB2E3A810]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xB2E3A8B0]

INT 0x63 ? 8A792BF8
INT 0x63 ? 8A792BF8
INT 0x63 ? 8A792BF8
INT 0x63 ? 8A792BF8
INT 0x63 ? 8A791BF8
INT 0x83 ? 8A795BF8
INT 0x83 ? 8A791BF8
INT 0x83 ? 8A795BF8
INT 0x94 ? 8A791BF8
INT 0xA4 ? 8A791BF8
INT 0xA4 ? 8A791BF8
INT 0xA4 ? 8A791BF8
INT 0xA4 ? 8A791BF8
INT 0xB4 ? 8A791BF8

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 8A7901F8

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

Device \FileSystem\Fastfat \FatCdrom 893DF500
Device \FileSystem\Udfs \UdfsCdRom 893D9500
Device \FileSystem\Udfs \UdfsDisk 893D9500
Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\NetBT \Device\NetBT_Tcpip_{2811BF5D-11CF-4874-80E0-7B75362D2023} 89735500
Device \Driver\usbuhci \Device\USBPDO-0 89865500
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A71F1F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A71F1F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A71F1F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A71F1F8
Device \Driver\usbuhci \Device\USBPDO-1 89865500
Device \Driver\usbuhci \Device\USBPDO-2 89865500
Device \Driver\usbehci \Device\USBPDO-3 898561F8
Device \Driver\usbuhci \Device\USBPDO-4 89865500
Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBPDO-5 89865500
Device \Driver\usbuhci \Device\USBPDO-6 89865500
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A7931F8
Device \Driver\sptd \Device\2277987298 spjc.sys
Device \Driver\usbehci \Device\USBPDO-7 898561F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A7931F8
Device \Driver\Cdrom \Device\CdRom0 898221F8
Device \Driver\atapi \Device\Ide\IdePort0 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 898221F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 89735500
Device \Driver\NetBT \Device\NetbiosSmb 89735500
Device \Driver\PCI_PNP3548 \Device\0000004e spjc.sys
Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBFDO-0 89865500
Device \Driver\usbuhci \Device\USBFDO-1 89865500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89802500
Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
Device \Driver\usbuhci \Device\USBFDO-2 89865500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89802500
Device \Driver\usbehci \Device\USBFDO-3 898561F8
Device \Driver\usbuhci \Device\USBFDO-4 89865500
Device \Driver\Ftdisk \Device\FtControl 8A7931F8
Device \Driver\usbuhci \Device\USBFDO-5 89865500
Device \Driver\usbuhci \Device\USBFDO-6 89865500
Device \Driver\usbehci \Device\USBFDO-7 898561F8
Device \Driver\aekhnxez \Device\Scsi\aekhnxez1 898181F8
Device \Driver\aekhnxez \Device\Scsi\aekhnxez1Port5Path0Target0Lun0 898181F8
Device \Driver\mv61xx \Device\Scsi\mv61xx1Port4Path0Target14Lun0 8A71E1F8
Device \Driver\mv61xx \Device\Scsi\mv61xx1 8A71E1F8
Device \FileSystem\Fastfat \Fat 893DF500

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

Device \FileSystem\Cdfs \Cdfs 8849D500

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9B 0x3F 0xF7 0xEB ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDF 0xD1 0xEF 0x6F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x30 0xD4 0xC3 0xD8 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9B 0x3F 0xF7 0xEB ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDF 0xD1 0xEF 0x6F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x30 0xD4 0xC3 0xD8 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1

---- Files - GMER 1.0.15 ----

File C:\Program Files\Steam\appcache\httpcache\dd\dd6f7c0153e1b2e42960aa2c87d229bf01d94d63_da39a3ee5e6b4b0d3255bfef95601890afd80709 2690 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd039f2cc5a505ba0d985ed5b793f1b6e2ae4887_da39a3ee5e6b4b0d3255bfef95601890afd80709 2750 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd049c0280ce46d23f1b3c22a276e7a4297c171b_da39a3ee5e6b4b0d3255bfef95601890afd80709 1644 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd072193bde2caed970ce0d83f6552d9f5abbdb8_da39a3ee5e6b4b0d3255bfef95601890afd80709 3125 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd0895d586a65ca8dcc480e2298447e6315c6b14_da39a3ee5e6b4b0d3255bfef95601890afd80709 1693 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd0aa6399e9c258f74a7ff876386aa050e442b28_da39a3ee5e6b4b0d3255bfef95601890afd80709 1702 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd0ccc718a0c9fbf6180f1512be8fbdded77f49a_da39a3ee5e6b4b0d3255bfef95601890afd80709 1898 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd0cd716978f174dfa4aa541f5b292574701ac7f_da39a3ee5e6b4b0d3255bfef95601890afd80709 2423 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd82d9afb5ea08233cbc8d0176ebfebd49f5a6e2_da39a3ee5e6b4b0d3255bfef95601890afd80709 2295 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd84d1866eaf8fecade7ce4ddc137d8cbce799eb_da39a3ee5e6b4b0d3255bfef95601890afd80709 3138 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd86033a65276af19f5859ee567a14f120518000_da39a3ee5e6b4b0d3255bfef95601890afd80709 2717 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd862121bf8bd36c8d3d360afa408262cd71c35b_da39a3ee5e6b4b0d3255bfef95601890afd80709 1894 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd876b32de490ce7e0e289ff65b8bb44ebf0fe4c_da39a3ee5e6b4b0d3255bfef95601890afd80709 2281 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd8877620b0546c7450386951e6a472c94786999_da39a3ee5e6b4b0d3255bfef95601890afd80709 2668 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd8902d953fc2196fe8ed8554056b71fbc661fb6_da39a3ee5e6b4b0d3255bfef95601890afd80709 2510 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd8a4a69f9b61a039d05dffa6d246983cd41a033_da39a3ee5e6b4b0d3255bfef95601890afd80709 1947 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd8b0afd1c2046f740cf2d62ec12b76dad7c8ba7_da39a3ee5e6b4b0d3255bfef95601890afd80709 1608 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd4b3167323a1e30688a2d7349f2cd2202b5deb5_da39a3ee5e6b4b0d3255bfef95601890afd80709 3078 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd517086f52b33adf1d900b35d4d9c790f355b7b_da39a3ee5e6b4b0d3255bfef95601890afd80709 1741 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd51cb889806e6f08f393a7ef3201785332df8b4_da39a3ee5e6b4b0d3255bfef95601890afd80709 2263 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd527bf87024dd20902cee2d673aa64919773e03_da39a3ee5e6b4b0d3255bfef95601890afd80709 2392 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd52e65a322bcb269df0f6e5596d88e48ed56f9b_da39a3ee5e6b4b0d3255bfef95601890afd80709 1922 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd53923029222efcd26e4356f6703d50ae488f88_da39a3ee5e6b4b0d3255bfef95601890afd80709 1586 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddddd6ede1c696a9f09a96a99c87b37b24af864d_da39a3ee5e6b4b0d3255bfef95601890afd80709 3074 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dde0ac1a3fd22e8b046609c87ce1f2e5a00d1937_da39a3ee5e6b4b0d3255bfef95601890afd80709 1685 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dde393853b9d3204e05900e95eff60d7441722f7_da39a3ee5e6b4b0d3255bfef95601890afd80709 1844 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dde3d6ec934c5eb420f668e652265a5bd18ae729_da39a3ee5e6b4b0d3255bfef95601890afd80709 3056 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dde4ca33767f42f51781092661019e00a9f4f919_da39a3ee5e6b4b0d3255bfef95601890afd80709 2154 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd0cfa86b2c9fea05ee7bfd705a396948d96a2b6_da39a3ee5e6b4b0d3255bfef95601890afd80709 1865 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd2251b509962e3bfaa06a33b7152c704e2c107b_da39a3ee5e6b4b0d3255bfef95601890afd80709 2718 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd333b6772fa596d06e39574c55252f66c256dcb_da39a3ee5e6b4b0d3255bfef95601890afd80709 2010 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd3c0ca3d07739508f8284dfb10bf6f144cd163b_da39a3ee5e6b4b0d3255bfef95601890afd80709 2362 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd4a5970ac591c9f3bcb2c73e92098ca275d76db_da39a3ee5e6b4b0d3255bfef95601890afd80709 1733 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd55ff0472b60c384209f3bd022b81c1c9591838_da39a3ee5e6b4b0d3255bfef95601890afd80709 2464 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd5fd6c957c597d4e3a1b20d02ab4e8e461c624a_da39a3ee5e6b4b0d3255bfef95601890afd80709 3010 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd1e4237e370ec268944ae3f06cda6622d50045a_da39a3ee5e6b4b0d3255bfef95601890afd80709 2142 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd1e9ac91dec6eea119836cb7fa545b6439c6284_da39a3ee5e6b4b0d3255bfef95601890afd80709 2630 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd20882ce101f0e94b80c0cc4ab737373d2bc965_da39a3ee5e6b4b0d3255bfef95601890afd80709 2464 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd213a9166cfed0df3fd6d9aa07689331fa90fab_da39a3ee5e6b4b0d3255bfef95601890afd80709 2327 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd22274e74f65751f9db3e3a9e310068d7467e0f_da39a3ee5e6b4b0d3255bfef95601890afd80709 2071 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd6168304610a69b96d0bca2ea27a59e7a32a5a2_da39a3ee5e6b4b0d3255bfef95601890afd80709 3416 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd61e0ee5d44cbd7cacf0abc9783170481edc7b5_da39a3ee5e6b4b0d3255bfef95601890afd80709 1898 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd62d5eabf944c16c1c9411d3b0395887f44d223_da39a3ee5e6b4b0d3255bfef95601890afd80709 1905 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd6320bf427e590dad3852e3011c4c5a6f295581_da39a3ee5e6b4b0d3255bfef95601890afd80709 2420 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd6383363b6551e83d8b27e344120b9f14a7c921_da39a3ee5e6b4b0d3255bfef95601890afd80709 1886 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddc818293cb662a901c4afcd8d88a9e0e80a7e2c_da39a3ee5e6b4b0d3255bfef95601890afd80709 1768 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddc85428a2c8563481ea69daa432ac6f53b55cd2_da39a3ee5e6b4b0d3255bfef95601890afd80709 1884 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddca9d3a2c9b25dad76845961b4f416b8f6f57cf_da39a3ee5e6b4b0d3255bfef95601890afd80709 2525 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddcaf4d5fa2f4b437cd5df9aa9b7bb12da50063d_da39a3ee5e6b4b0d3255bfef95601890afd80709 1693 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddcb152d577a8940deae7cd549dfc16a698275fc_da39a3ee5e6b4b0d3255bfef95601890afd80709 2773 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd8fd765a2e2f9493277431d1e4a83a336e6b87c_da39a3ee5e6b4b0d3255bfef95601890afd80709 2507 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd91eb36d40bd2192521fef7e36738e4a9624b63_da39a3ee5e6b4b0d3255bfef95601890afd80709 1793 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd935224cf11f6422458be954d66db35e8a992be_da39a3ee5e6b4b0d3255bfef95601890afd80709 1883 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd94941ccb6fd8c4493f7da3633f08a5e441dc9f_da39a3ee5e6b4b0d3255bfef95601890afd80709 1940 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddec293efbccfd948a0a11c772100afb277b2339_da39a3ee5e6b4b0d3255bfef95601890afd80709 1723 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dded415ec8586d693d0b9c4ae2d2753a8f714988_da39a3ee5e6b4b0d3255bfef95601890afd80709 2873 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddedb5a307a82a6d8206204e45367cc9faaf65e7_da39a3ee5e6b4b0d3255bfef95601890afd80709 2057 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf049c809840fcb7c4a9fe774aed0372539413f_da39a3ee5e6b4b0d3255bfef95601890afd80709 3005 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf0d293655ebd63fcca40598d7372dcff4e1a2f_da39a3ee5e6b4b0d3255bfef95601890afd80709 1934 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf3799ed2266467a1f59cc898c42f6f67f1af3f_da39a3ee5e6b4b0d3255bfef95601890afd80709 2337 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd25be274510711ebd6e2c49098d6bbd87debae9_da39a3ee5e6b4b0d3255bfef95601890afd80709 1738 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd25ec459b001e17a6d0a87f8342319b9efb8c32_da39a3ee5e6b4b0d3255bfef95601890afd80709 1830 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd27aacfc12b71abaff181eef963d1324db6fbea_da39a3ee5e6b4b0d3255bfef95601890afd80709 1654 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd2821564bfa0bf64ef9b5d0d703e6a5f1aad834_da39a3ee5e6b4b0d3255bfef95601890afd80709 1889 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd282c6ae51d8049850e9a5bcb7c043ebc07cbdb_da39a3ee5e6b4b0d3255bfef95601890afd80709 2056 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd299c2bec1b606dfed7b97c9ac235678b0bd37e_da39a3ee5e6b4b0d3255bfef95601890afd80709 2789 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd2bfe0e7e182a495b5ad9aceb430e9e4d3d9967_da39a3ee5e6b4b0d3255bfef95601890afd80709 3089 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd303d485fdfd3bbb49cf16661baf9bc76dc5210_da39a3ee5e6b4b0d3255bfef95601890afd80709 1729 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd70e3155fc715cf6a16bf7074edde30794299d7_da39a3ee5e6b4b0d3255bfef95601890afd80709 2621 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd7798c7bc8d99f0bf2dd62ecdc3260019a64eb4_da39a3ee5e6b4b0d3255bfef95601890afd80709 1764 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd7aaaef6dfed2e2cd7c1fea138516dbc52c99bd_da39a3ee5e6b4b0d3255bfef95601890afd80709 2514 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd7d26a9e2b115895361655424dcaa6c4f867f4b_da39a3ee5e6b4b0d3255bfef95601890afd80709 1907 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd7d379af4ce7b2254c5f4698dce339160d3f33b_da39a3ee5e6b4b0d3255bfef95601890afd80709 2672 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd801df65c93cb4ab5969ad3b09b60648dc95733_da39a3ee5e6b4b0d3255bfef95601890afd80709 2362 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddab9e02c5a315fe4a69c5ead4d9fbf018a14034_da39a3ee5e6b4b0d3255bfef95601890afd80709 2046 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddb31dfa7a953cd47fbfb1fbcf0529ebc2835ad4_da39a3ee5e6b4b0d3255bfef95601890afd80709 2498 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddb3bf7043cff7b76cb64892df607a0ad71bda8d_da39a3ee5e6b4b0d3255bfef95601890afd80709 2533 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddbd097237c029a3d20a7503455cc769e4a53438_da39a3ee5e6b4b0d3255bfef95601890afd80709 2491 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddbe2baaece5c6cbe4701ae3f60b0e2651fce109_da39a3ee5e6b4b0d3255bfef95601890afd80709 2998 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddbf8799ea464337a2c666666bfacdc6412c68b1_da39a3ee5e6b4b0d3255bfef95601890afd80709 1797 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddc2a577ac3cf93b702ce38acfb0e3d397a676f7_da39a3ee5e6b4b0d3255bfef95601890afd80709 1930 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd372a73355c216e8eb825369e43e2ff584d6e77_da39a3ee5e6b4b0d3255bfef95601890afd80709 1876 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd378b0deae4e89d54c56d3d189edff4a924fc8b_da39a3ee5e6b4b0d3255bfef95601890afd80709 2453 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd3a759edfc322f74e8f39897f77fa63fa496414_da39a3ee5e6b4b0d3255bfef95601890afd80709 1885 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd3acf24e309c55281cc9a3566e55853d17aae02_da39a3ee5e6b4b0d3255bfef95601890afd80709 3428 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd3b98b9c84c551d2d61b13b8ef0f4e6517870e3_da39a3ee5e6b4b0d3255bfef95601890afd80709 1876 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd3b9ea2de66c73640e6290b7153552013f7d561_da39a3ee5e6b4b0d3255bfef95601890afd80709 2503 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf61703ceb66a73b38cc31d4abb988e1ce07a23_da39a3ee5e6b4b0d3255bfef95601890afd80709 1658 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf86aa17cc0aee2c912d265e982f3d7eac2a2d1_da39a3ee5e6b4b0d3255bfef95601890afd80709 2601 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf8761b7855b923b82eb0663e3d55a40df3c64b_da39a3ee5e6b4b0d3255bfef95601890afd80709 2352 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf95ad8c446adb0e6d1f02370ce8f8d33755fdf_da39a3ee5e6b4b0d3255bfef95601890afd80709 1890 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf963e8312cefd53419033daf09632849baebe8_da39a3ee5e6b4b0d3255bfef95601890afd80709 2482 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf99a53ff0b67d9274585de90931af71b1d9cf2_da39a3ee5e6b4b0d3255bfef95601890afd80709 2828 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddfc70d32ce2c460d0306fbe5028cc650d7bb2a8_da39a3ee5e6b4b0d3255bfef95601890afd80709 1619 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddfe6ae78a21db73fe5c2f7fa15c20350cc657f1_da39a3ee5e6b4b0d3255bfef95601890afd80709 1867 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd0f589c92b5758260a30f38fc1d63fa1c7cf6e8_da39a3ee5e6b4b0d3255bfef95601890afd80709 1860 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd1134473e270aac9f397121e1ddd6d1e6c020a8_da39a3ee5e6b4b0d3255bfef95601890afd80709 2153 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd1508cc64a35eeebed7374cbe599cd3dfb38504_da39a3ee5e6b4b0d3255bfef95601890afd80709 1743 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd17d14a6e818df569d8540748351425058ef472_da39a3ee5e6b4b0d3255bfef95601890afd80709 2790 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd19604d8e57174cd5149912cfcfa62f8165aec8_da39a3ee5e6b4b0d3255bfef95601890afd80709 1930 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd1b817bc9c75a41248afb4730b7159fc9dab7ad_da39a3ee5e6b4b0d3255bfef95601890afd80709 2963 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd568e4ee61a148d5ba4f7d5dea57c140a526a43_da39a3ee5e6b4b0d3255bfef95601890afd80709 1613 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd5766548d5cf5c6b185e1aef2f40029f5922a7b_da39a3ee5e6b4b0d3255bfef95601890afd80709 1927 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd57857619e1cc42f66919c1b60230bca48a828d_da39a3ee5e6b4b0d3255bfef95601890afd80709 1837 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd58cbf3f863b9361f585876d975d3c9b1153677_da39a3ee5e6b4b0d3255bfef95601890afd80709 2301 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd593940ed7dddef14489fa4589e5e692cd01cf9_da39a3ee5e6b4b0d3255bfef95601890afd80709 3261 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd5a0d26a5f5254e8d16e97f04043538c6edc7e8_da39a3ee5e6b4b0d3255bfef95601890afd80709 1722 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd5c56666efe4bf90b57cd8e8b5ef973c568ee54_da39a3ee5e6b4b0d3255bfef95601890afd80709 3032 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd5e86c753fbd1727464159b655eb5b30ada0f34_da39a3ee5e6b4b0d3255bfef95601890afd80709 1773 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd5f6dfe7db529f4bfeb34cea77824463b52797e_da39a3ee5e6b4b0d3255bfef95601890afd80709 1799 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd63a26d3905faedda616bbf858b891b48b9d273_da39a3ee5e6b4b0d3255bfef95601890afd80709 1798 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd69e0e620212a0f5c359fa694ddbad54b2089da_da39a3ee5e6b4b0d3255bfef95601890afd80709 2307 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd6be1422ad91fb0dcc2e161fb4171cef7e0c5bf_da39a3ee5e6b4b0d3255bfef95601890afd80709 1916 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd6bfcf1942c35950a5bf08c45f0d3929b91446b_da39a3ee5e6b4b0d3255bfef95601890afd80709 1979 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd6e07276f02317fb5aa76b5d8957ecc3357078c_da39a3ee5e6b4b0d3255bfef95601890afd80709 1724 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd82d07368723a6cbbe853afdcf7483e272f0b3e_da39a3ee5e6b4b0d3255bfef95601890afd80709 2107 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd8b2f44e5ef1b9a2e56c5b983e2b4f10583c797_da39a3ee5e6b4b0d3255bfef95601890afd80709 2306 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dda887e2706b9ca89b10eef9e8d65cb50f0b2988_da39a3ee5e6b4b0d3255bfef95601890afd80709 2778 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddc5ad7198cc4eff7c5b877debabf0717f951de5_da39a3ee5e6b4b0d3255bfef95601890afd80709 2547 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddcb5ceaba3a02edca0d21e74de9e1c203925731_da39a3ee5e6b4b0d3255bfef95601890afd80709 2435 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddddba31875941bcc4b03d21d8550dddc2e7c496_da39a3ee5e6b4b0d3255bfef95601890afd80709 1948 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dde58a47697eb1f3fdde9795be5e804f69756ac7_da39a3ee5e6b4b0d3255bfef95601890afd80709 1702 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddebc29d1e45ad5a88079b27f77f4843644d089a_da39a3ee5e6b4b0d3255bfef95601890afd80709 1874 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddf4e51fe9803b60be0587298cf3c38729b2be66_da39a3ee5e6b4b0d3255bfef95601890afd80709 2955 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddd3a0735a9ae7ead37d731c8322a44d31b359d9_da39a3ee5e6b4b0d3255bfef95601890afd80709 2367 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddd3e44282aab13e2a11e0768c56b64fc43ab41e_da39a3ee5e6b4b0d3255bfef95601890afd80709 1859 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddd668f520530b9202438d29e262617db94f1ba1_da39a3ee5e6b4b0d3255bfef95601890afd80709 1785 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddd7904e21281b4d4df856776e5be3907037eab3_da39a3ee5e6b4b0d3255bfef95601890afd80709 1614 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddd926eec74f79e15ef2aa7cc2d9a1d9084dd1ba_da39a3ee5e6b4b0d3255bfef95601890afd80709 2334 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddd9e2b0c3fb2a171fba27a6c908ad2a5abe7fed_da39a3ee5e6b4b0d3255bfef95601890afd80709 1914 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dddacff53fecefb9b18315c3cfc00dc0cc2ff38e_da39a3ee5e6b4b0d3255bfef95601890afd80709 2611 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd9aa8dd487bbbb9b8d476733b9eec33cdd4a3a5_da39a3ee5e6b4b0d3255bfef95601890afd80709 2012 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd9b96124cf0d72d0eea4d12f12779f919faddbd_da39a3ee5e6b4b0d3255bfef95601890afd80709 1919 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd9c6e9ca8192bd8242c70404ddc7e9dbb88b93e_da39a3ee5e6b4b0d3255bfef95601890afd80709 2571 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dda0bedcf3a570d1f81ee45493a35c3e3e25efdb_da39a3ee5e6b4b0d3255bfef95601890afd80709 1898 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dda237d0cc7f263d368e14c21551b8e16cd8284b_da39a3ee5e6b4b0d3255bfef95601890afd80709 2339 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dda393d8eef4f2c9a9bcb3820352c7035bffa424_da39a3ee5e6b4b0d3255bfef95601890afd80709 2369 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dda808a57c6a4d6b4b6d354330f214545878308d_da39a3ee5e6b4b0d3255bfef95601890afd80709 2081 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dda811246c303efb8439b50f5d175490e15209bf_da39a3ee5e6b4b0d3255bfef95601890afd80709 1721 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dde6b87bbde247d0f6c6e39b09b71910531186b6_da39a3ee5e6b4b0d3255bfef95601890afd80709 1607 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dde8d67a8f469b922f026ba2c1c034eff8539596_da39a3ee5e6b4b0d3255bfef95601890afd80709 2233 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dde9f7282a7e2047b33a57d9837e7154e5b95fbf_da39a3ee5e6b4b0d3255bfef95601890afd80709 2248 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\ddeae7889891be9532c1d5dd315f8441a57db6dd_da39a3ee5e6b4b0d3255bfef95601890afd80709 1859 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd3e23235a7a353b889bb02a6bedfaef9b7a9424_da39a3ee5e6b4b0d3255bfef95601890afd80709 2389 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd3e64db9c8670a2cfeaf4636599959d81c144d2_da39a3ee5e6b4b0d3255bfef95601890afd80709 2045 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd3f1768cb5b5529a0b8f7bce49174c11e0e0914_da39a3ee5e6b4b0d3255bfef95601890afd80709 1662 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd408df31c5e3b9acc593393f7568d530c96786c_da39a3ee5e6b4b0d3255bfef95601890afd80709 2877 bytes
File C:\Program Files\Steam\appcache\httpcache\dd\dd48360eefccba51a7a58dbf7d1a23dcc38c5709_da39a3ee5e6b4b0d3255bfef95601890afd80709 1764 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de8f2e04fcec90f52ef074c8214cb831309448e0_da39a3ee5e6b4b0d3255bfef95601890afd80709 1777 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de007ac367b7c23f0fff81dd75c1eb48bc2191c2_da39a3ee5e6b4b0d3255bfef95601890afd80709 1869 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de00afa88b62cc08a2dee87a963c223d5a206e91_da39a3ee5e6b4b0d3255bfef95601890afd80709 1934 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de02c7b8291a6c519ad18a405eed1fec01b84c72_da39a3ee5e6b4b0d3255bfef95601890afd80709 1957 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de0305920125479c5a83d4f66cbf9ce908a4d024_da39a3ee5e6b4b0d3255bfef95601890afd80709 2788 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de0854eb68048cd94514c8ebc2003a8816c0f8c2_da39a3ee5e6b4b0d3255bfef95601890afd80709 1830 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de091bd5295d8824447ef41adf1a4a1c9dfc4dec_da39a3ee5e6b4b0d3255bfef95601890afd80709 1962 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de0d52f709049b079e882903f70dd045e7a0bb21_da39a3ee5e6b4b0d3255bfef95601890afd80709 2842 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de0e181d2e093965d865c251db80ed0017767e8b_da39a3ee5e6b4b0d3255bfef95601890afd80709 1969 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de1236497387924805914c0584d3c774ab6b320c_da39a3ee5e6b4b0d3255bfef95601890afd80709 1926 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dea3b451d2fbc02cd5c6eda12f2a888a3068efe5_da39a3ee5e6b4b0d3255bfef95601890afd80709 2876 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dea42f98023fc9b3d8fffd7cd678502d95df556f_da39a3ee5e6b4b0d3255bfef95601890afd80709 1867 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dea4ffe2e9b0093d89ea39235649e9799acde504_da39a3ee5e6b4b0d3255bfef95601890afd80709 1801 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dea735a9e22568616d08fd65cb72d4b8a747b011_da39a3ee5e6b4b0d3255bfef95601890afd80709 2693 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dea7f4efc2c20ca6f5302989816d76a2840b7429_da39a3ee5e6b4b0d3255bfef95601890afd80709 1810 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deab0ce0bf383ce2ab214b3183f895b6c33b2e6e_da39a3ee5e6b4b0d3255bfef95601890afd80709 2713 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de3596f9627979d04fe5e4bf1591c3d7f6037ac4_da39a3ee5e6b4b0d3255bfef95601890afd80709 1952 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de3ac4e139ef7686add59647813fcb8305f1d8d4_da39a3ee5e6b4b0d3255bfef95601890afd80709 2460 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de3b372d86b28f0e7ce5693f0ae7010418458808_da39a3ee5e6b4b0d3255bfef95601890afd80709 2583 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de3cbe11657e31c33500dd342ba0a4be38f9522b_da39a3ee5e6b4b0d3255bfef95601890afd80709 2691 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de42ef6bb820c2d1d18546736a5055673b3b6ba9_da39a3ee5e6b4b0d3255bfef95601890afd80709 1913 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de467bbf4feb9857ddfc83d6fbb58bedf3d4cf26_da39a3ee5e6b4b0d3255bfef95601890afd80709 1948 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de4768ad749d25c843d82f93605e85b4369af572_da39a3ee5e6b4b0d3255bfef95601890afd80709 1850 bytes
File C:\Program Files\Steam\appcache\httpcache\de\ded4fc6952fc52d7f1049a85b7d1f780ddae6127_da39a3ee5e6b4b0d3255bfef95601890afd80709 2435 bytes
File C:\Program Files\Steam\appcache\httpcache\de\ded5b54a0d83f96dca69543bc11d440ef810ccbb_da39a3ee5e6b4b0d3255bfef95601890afd80709 2702 bytes
File C:\Program Files\Steam\appcache\httpcache\de\ded5b75942b62311e684a01709604506ce92e266_da39a3ee5e6b4b0d3255bfef95601890afd80709 2451 bytes
File C:\Program Files\Steam\appcache\httpcache\de\ded6d70e4c0d35d5d0b4fdff041c166ba701c52a_da39a3ee5e6b4b0d3255bfef95601890afd80709 1914 bytes
File C:\Program Files\Steam\appcache\httpcache\de\ded792178b926e09272e2be2fe192236c888214c_da39a3ee5e6b4b0d3255bfef95601890afd80709 1853 bytes
File C:\Program Files\Steam\appcache\httpcache\de\ded7cd154314647fd538d2653722df4f0fb3ae3e_da39a3ee5e6b4b0d3255bfef95601890afd80709 2798 bytes
File C:\Program Files\Steam\appcache\httpcache\de\ded8a2f832fe8e9c60274f6c1171c9132ecbe3ff_da39a3ee5e6b4b0d3255bfef95601890afd80709 2740 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de1552c6d0fb7728ba2523fc1c1acd9818bbabf4_da39a3ee5e6b4b0d3255bfef95601890afd80709 1817 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de212753e73ebd937ae5c6ec4f4ae0909fec84f2_da39a3ee5e6b4b0d3255bfef95601890afd80709 1819 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de33c060de2f2b249a187f693c72fa9f54357025_da39a3ee5e6b4b0d3255bfef95601890afd80709 1871 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de48f4a2da2400523441aa8d166865bccc86924d_da39a3ee5e6b4b0d3255bfef95601890afd80709 2265 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de5456745c2b712f9ed7bf73a0c1f8ce89d94807_da39a3ee5e6b4b0d3255bfef95601890afd80709 1910 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de648941784c74a3c4d45f161dbf5e859ef29a52_da39a3ee5e6b4b0d3255bfef95601890afd80709 2328 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de70f4beca9d30f0157cffd6430667c8630b099e_da39a3ee5e6b4b0d3255bfef95601890afd80709 1831 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de782d633c2ed7b33f232a503555d32c32317bc8_da39a3ee5e6b4b0d3255bfef95601890afd80709 2801 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de7bcfd59a1d4412fbc82adbaa7ddf1ff0e96362_da39a3ee5e6b4b0d3255bfef95601890afd80709 2228 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de7f1102bd3b7e2699d5ede0c6b4564df0d68adb_da39a3ee5e6b4b0d3255bfef95601890afd80709 1583 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de84ead19b941156c89aafc66240b4a59fecf256_da39a3ee5e6b4b0d3255bfef95601890afd80709 2159 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de885a83b31840b6f2c775bcb7f337d7bb4da9f4_da39a3ee5e6b4b0d3255bfef95601890afd80709 2427 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de8897a2b018de51ef89697c539e7beb8a533e24_da39a3ee5e6b4b0d3255bfef95601890afd80709 2752 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de8d7024c7d63cbd4dc594ff89003faed91367aa_da39a3ee5e6b4b0d3255bfef95601890afd80709 2253 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de64fcb2ab0ec29d251b2a28af6ac6c51eec9bfd_da39a3ee5e6b4b0d3255bfef95601890afd80709 2800 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de683c9e527e5a1098b18b3310b19961e93cf222_da39a3ee5e6b4b0d3255bfef95601890afd80709 1681 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de68e283c808bba30c1a33da5e9757c70bba5f2c_da39a3ee5e6b4b0d3255bfef95601890afd80709 1872 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de6a6b0095acb287287ef415541b1f5c3381f330_da39a3ee5e6b4b0d3255bfef95601890afd80709 3020 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de6bd275eb5b68acfc8dc8af50a23f4ac9ec794f_da39a3ee5e6b4b0d3255bfef95601890afd80709 2857 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de6d9101c0f627dacbd4b475134acf65c5c19f9e_da39a3ee5e6b4b0d3255bfef95601890afd80709 2342 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de6e5e602ed8964141bf1adc6581d2fa91ebb016_da39a3ee5e6b4b0d3255bfef95601890afd80709 2595 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de22ec650a473675a5da92b92b0425c00f3038cc_da39a3ee5e6b4b0d3255bfef95601890afd80709 1894 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de232922267a001dcf57c861503ec3b52616fc98_da39a3ee5e6b4b0d3255bfef95601890afd80709 1874 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de242b4ddaee7f2046a552a5c8f6cb57402398b4_da39a3ee5e6b4b0d3255bfef95601890afd80709 2616 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de2511bd5ab1eb61062d5cbea2426a7de4a85eef_da39a3ee5e6b4b0d3255bfef95601890afd80709 2306 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de2712f4bca68d5eefdd0fad9f599a40aeed7441_da39a3ee5e6b4b0d3255bfef95601890afd80709 2494 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de2df588f7a96eaa73448d988c910f7eb37f405e_da39a3ee5e6b4b0d3255bfef95601890afd80709 2250 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de2ea5df44dccbcd50b9877ca60d3497ea8f8838_da39a3ee5e6b4b0d3255bfef95601890afd80709 2020 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de2f81962099d6bfa50010f56ddf5b4618666859_da39a3ee5e6b4b0d3255bfef95601890afd80709 1862 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de30069f5009498299e681ce3d4049632f98a732_da39a3ee5e6b4b0d3255bfef95601890afd80709 2379 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deedb42c40e021cc658053d1e49e13384f1743f8_da39a3ee5e6b4b0d3255bfef95601890afd80709 2299 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deedd05777cd0b5ae771ef84f75ffcba7bfbe6d4_da39a3ee5e6b4b0d3255bfef95601890afd80709 2039 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deee9c3398202cb33b9b45a04dcc63a3b60cd65b_da39a3ee5e6b4b0d3255bfef95601890afd80709 2604 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deef48796c6313b1d3bb406c90979acc12a71a15_da39a3ee5e6b4b0d3255bfef95601890afd80709 1762 bytes
File C:\Program Files\Steam\appcache\httpcache\de\def1d7b6ab0331d391457ec7e71f69093e936c5d_da39a3ee5e6b4b0d3255bfef95601890afd80709 1911 bytes
File C:\Program Files\Steam\appcache\httpcache\de\def52a6a1dd6e28b93c75620ebb7b038f4763aea_da39a3ee5e6b4b0d3255bfef95601890afd80709 3210 bytes
File C:\Program Files\Steam\appcache\httpcache\de\def66f15a538c3ade0d43234bb4ec79afc6a373d_da39a3ee5e6b4b0d3255bfef95601890afd80709 3065 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deb47d95ee06fdf9cef22a180a74653ea0709398_da39a3ee5e6b4b0d3255bfef95601890afd80709 2360 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deb4b0b8870ca894003d583a6f8f38044b422c70_da39a3ee5e6b4b0d3255bfef95601890afd80709 2621 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deb4d5f8f6e65359a9e1ba884c836da6621a82ce_da39a3ee5e6b4b0d3255bfef95601890afd80709 1911 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deb9098461fec336a18f1c758a7e4d6659f2280e_da39a3ee5e6b4b0d3255bfef95601890afd80709 1724 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deb9ed0565c0ec40e7624db5aa3ecbf95706826a_da39a3ee5e6b4b0d3255bfef95601890afd80709 1872 bytes
File C:\Program Files\Steam\appcache\httpcache\de\debae6eebea8756cb5046fa8e3f8c54e625572e3_da39a3ee5e6b4b0d3255bfef95601890afd80709 1949 bytes
File C:\Program Files\Steam\appcache\httpcache\de\debc4e244308b1b11e7b7a6c3bed0f222b1d0219_da39a3ee5e6b4b0d3255bfef95601890afd80709 2632 bytes
File C:\Program Files\Steam\appcache\httpcache\de\debc782840bf8ffcd597fc6eba17042c89324d02_da39a3ee5e6b4b0d3255bfef95601890afd80709 2769 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de96c8e80612d24220304a7d82e155d87166e89c_da39a3ee5e6b4b0d3255bfef95601890afd80709 1698 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de971b52b5cd09e85b38d2e6e5b44f4e4f2da606_da39a3ee5e6b4b0d3255bfef95601890afd80709 2914 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de9bffc2c63efcaacabc385704064cd13fa83a1a_da39a3ee5e6b4b0d3255bfef95601890afd80709 2738 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de9ea8a38f4d77ebf382c5499c7b64564a5ad2c0_da39a3ee5e6b4b0d3255bfef95601890afd80709 1967 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de9eff8e1619dea197b1b6467eaa3105812ec64f_da39a3ee5e6b4b0d3255bfef95601890afd80709 2562 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de9f32eb62595539c52855ec3b9e5c59e4becf8c_da39a3ee5e6b4b0d3255bfef95601890afd80709 1752 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de178131dbe955e3b0e1f24af96087254e31da07_da39a3ee5e6b4b0d3255bfef95601890afd80709 2473 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de19fd6ec9ca9e9e27600ba382983e52ea345aff_da39a3ee5e6b4b0d3255bfef95601890afd80709 1829 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de1b08db62d7665c9501ffea3c8f37f730dd35c1_da39a3ee5e6b4b0d3255bfef95601890afd80709 2501 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de1bbd3e5644cab8cc9609b51a40a7040aaa152c_da39a3ee5e6b4b0d3255bfef95601890afd80709 1910 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de1ee92d48e7c5ac03e965648289432e02d44949_da39a3ee5e6b4b0d3255bfef95601890afd80709 2764 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de1f399a235315145678ac6a2037d0edbdef0f33_da39a3ee5e6b4b0d3255bfef95601890afd80709 2378 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de71a898976e61a869cb9c8450f43e512f0232a8_da39a3ee5e6b4b0d3255bfef95601890afd80709 1839 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de75f4d277592ee9355fbf289874eb15923b24dc_da39a3ee5e6b4b0d3255bfef95601890afd80709 1910 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de767112b68c9c8246e5dd4120d7feb0982a45f5_da39a3ee5e6b4b0d3255bfef95601890afd80709 3148 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de76e6436e01b845439e0bcbf5a3d1d5bdb78aee_da39a3ee5e6b4b0d3255bfef95601890afd80709 2259 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de77bf6d835de77df5d207528fb9b454abe83d92_da39a3ee5e6b4b0d3255bfef95601890afd80709 2503 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de494f8959b03c9db272a2314071338a76c9e79a_da39a3ee5e6b4b0d3255bfef95601890afd80709 1822 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de49593f5916e3e21f3cc25ba5a0dd0d99ec2b66_da39a3ee5e6b4b0d3255bfef95601890afd80709 1816 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de4ab66ef833f7cb568440fcf401e391dfe416d7_da39a3ee5e6b4b0d3255bfef95601890afd80709 1837 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de4f0c0d7fac5f3cb30425fdb93095e8057083fb_da39a3ee5e6b4b0d3255bfef95601890afd80709 1762 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dec2506f67ec31872b8a11f1f4101d8891484c88_da39a3ee5e6b4b0d3255bfef95601890afd80709 1814 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dec2b56f649f033db6e10d83f1f2ffc8cdd18c82_da39a3ee5e6b4b0d3255bfef95601890afd80709 1619 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dec4e64b197aaee9183fff6a662a4714f256a64f_da39a3ee5e6b4b0d3255bfef95601890afd80709 2212 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dec5deb20755f64ba6f1f009dd571b85366bde87_da39a3ee5e6b4b0d3255bfef95601890afd80709 2039 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dec6a44db7d35ff0ce01ed08f4a689205b01e9c8_da39a3ee5e6b4b0d3255bfef95601890afd80709 2029 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dec99b66349990607a3833dc5f599c3f5f645261_da39a3ee5e6b4b0d3255bfef95601890afd80709 2013 bytes
File C:\Program Files\Steam\appcache\httpcache\de\ded056610751716dbbab0116de1e875d8a1dc6a9_da39a3ee5e6b4b0d3255bfef95601890afd80709 2413 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deda9f23a0ed84abd9889fa9fa3d1488f23460b3_da39a3ee5e6b4b0d3255bfef95601890afd80709 2580 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dedb08546617346f962da134b19e1a61abcf7bec_da39a3ee5e6b4b0d3255bfef95601890afd80709 2522 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dedd798d71680fe79c0dfbfe39875cd7d1642782_da39a3ee5e6b4b0d3255bfef95601890afd80709 2080 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dede3445a4eb21ab4a985c3b1bfb4ee311db7653_da39a3ee5e6b4b0d3255bfef95601890afd80709 2587 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dee2600f522b236189daf1233f1a61d39464ad1d_da39a3ee5e6b4b0d3255bfef95601890afd80709 2199 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de9055893fc771ec548ac8f933a6904a095c0ffd_da39a3ee5e6b4b0d3255bfef95601890afd80709 2546 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de929855212987a1154dabb1b2839818ccff8b82_da39a3ee5e6b4b0d3255bfef95601890afd80709 2354 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de93a366926017f7a2f0d07776aaef4c65acf9ae_da39a3ee5e6b4b0d3255bfef95601890afd80709 2800 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de94a39adba094f123b90904439f8490e7d88da1_da39a3ee5e6b4b0d3255bfef95601890afd80709 1790 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deab8659ba832ffd0b1e11c17ec2a12cba653348_da39a3ee5e6b4b0d3255bfef95601890afd80709 2641 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deabec94a0ede3801f7104dcbd00583136389844_da39a3ee5e6b4b0d3255bfef95601890afd80709 1757 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deac204ea2f17802171dd642dd9a69f18d3d0c96_da39a3ee5e6b4b0d3255bfef95601890afd80709 2015 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deacf06506571b56007dbc2a0b06dd4889c151fd_da39a3ee5e6b4b0d3255bfef95601890afd80709 2918 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deafa1a2756848e727023e1b9c3954bfb13d2a0f_da39a3ee5e6b4b0d3255bfef95601890afd80709 2333 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deb20081c3b7d6997cade88fc944ad0315acc32e_da39a3ee5e6b4b0d3255bfef95601890afd80709 1747 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de9544f941dd089c07d2f6d12188e67d67583dbf_da39a3ee5e6b4b0d3255bfef95601890afd80709 1830 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dea0c2e6c839a67e9079ee95dcade5d870d21bb5_da39a3ee5e6b4b0d3255bfef95601890afd80709 1894 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deb2b8f20d175f4074ad1941c8790c291205c542_da39a3ee5e6b4b0d3255bfef95601890afd80709 2278 bytes
File C:\Program Files\Steam\appcache\httpcache\de\debde14b00883dad0726fb02ec5a8191b30890ec_da39a3ee5e6b4b0d3255bfef95601890afd80709 1880 bytes
File C:\Program Files\Steam\appcache\httpcache\de\ded33625219316451850c51fca84a1896fcbb017_da39a3ee5e6b4b0d3255bfef95601890afd80709 2511 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deda284cbaa18fb0af465b0a519c3c5a9de1c593_da39a3ee5e6b4b0d3255bfef95601890afd80709 1762 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dee2966c7f1f50855810014f9c14a2e06c91e8f5_da39a3ee5e6b4b0d3255bfef95601890afd80709 1740 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deecd2ec7ea266408a3e3fe6aadcfd391db40c37_da39a3ee5e6b4b0d3255bfef95601890afd80709 1948 bytes
File C:\Program Files\Steam\appcache\httpcache\de\def8ba31ef066ca40ff610cfdf8a891c4d2f90e9_da39a3ee5e6b4b0d3255bfef95601890afd80709 3024 bytes
File C:\Program Files\Steam\appcache\httpcache\de\defafee9383c8fff078b9e770163b2dab26c3c4c_da39a3ee5e6b4b0d3255bfef95601890afd80709 2941 bytes
File C:\Program Files\Steam\appcache\httpcache\de\defb78cda1b270acededdd49d4780e7df53dd0bb_da39a3ee5e6b4b0d3255bfef95601890afd80709 3002 bytes
File C:\Program Files\Steam\appcache\httpcache\de\defbe0b12ab429d38886861ba5013e0fd64285cb_da39a3ee5e6b4b0d3255bfef95601890afd80709 1889 bytes
File C:\Program Files\Steam\appcache\httpcache\de\defc3e8edfcec2e38d80a4b795ae9f7684c80826_da39a3ee5e6b4b0d3255bfef95601890afd80709 2168 bytes
File C:\Program Files\Steam\appcache\httpcache\de\defee4c4136a2c17d377ac4a1b15d8a0067ef176_da39a3ee5e6b4b0d3255bfef95601890afd80709 2183 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deff3b40ef29e4807801bf71060d78c4aca4e620_da39a3ee5e6b4b0d3255bfef95601890afd80709 2972 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de5f04a0378726b5ff9214cb83f77738635da922_da39a3ee5e6b4b0d3255bfef95601890afd80709 1808 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de5f3d5586fd384bb343bbe9eea3f38befc0ac77_da39a3ee5e6b4b0d3255bfef95601890afd80709 2077 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de60477754f0fa23f664c84dc8b751c9fdf175ba_da39a3ee5e6b4b0d3255bfef95601890afd80709 2375 bytes
File C:\Program Files\Steam\appcache\httpcache\de\de60eb8c2cbbaa86e6ebc1f4053d29e1f0c23c6a_da39a3ee5e6b4b0d3255bfef95601890afd80709 1799 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dee494eb83bac56df36a30fa775113d312865988_da39a3ee5e6b4b0d3255bfef95601890afd80709 3177 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dee53c97eb0d1de2d8d5531e55a472f5f2d2100a_da39a3ee5e6b4b0d3255bfef95601890afd80709 1825 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dee848be769700c783bb2840d5bf214a05c98b55_da39a3ee5e6b4b0d3255bfef95601890afd80709 1905 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dee8cb97f5fee07b4a8ae56a94303180ef02790a_da39a3ee5e6b4b0d3255bfef95601890afd80709 3124 bytes
File C:\Program Files\Steam\appcache\httpcache\de\dee9f00fd8872bd16bde771fe8bc0dad217bb6cf_da39a3ee5e6b4b0d3255bfef95601890afd80709 2470 bytes
File C:\Program Files\Steam\appcache\httpcache\de\deec53ace6247c6c89a2fdf7e739164b1a556704_da39a3ee5e6b4b0d3255bfef95601890afd80709 2719 bytes

---- EOF - GMER 1.0.15 ----


.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Waka at 19:40:21.18 on 02/04/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2047.1022 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *Enabled*
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
svchost.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\ASUS\AASP\1.00.88\aaCenter.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Steam\Steam.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Waka\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [ASUS Update Checker] c:\program files\asus\asusupdate\updatechecker\UpdateChecker.exe
mRun: [SPIRun] Rundll32 SPIRun.dll,RunDLLEntry
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [QFan Help] "c:\program files\asus\ai suite\qfan3\QFanHelp.exe"
mRun: [Cpu Level Up help] "c:\program files\asus\ai suite\CpuLevelUpHelp.exe"
mRun: [Ai Nap] "c:\program files\asus\ai suite\ainap\AiNap.exe"
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVZOVgtTlNWVkwtTzRCWlEtUUlNQ0wtUVREQ0gtNElKTUg"&"inst=NzctNDc1NTA1NTkyLUJBKzEtS1YzKzctWEwrMS1UMi1GUDkyKzYtVEI5KzItRkwrOS1RSVgxKzQtWDIwMTArMi1GMTBNMTBDKzE"&"prod=90"&"ver=10.0.1204
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\waka\applic~1\mozilla\firefox\profiles\ldfpmils.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - component: c:\documents and settings\waka\application data\mozilla\firefox\profiles\ldfpmils.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCoreGecko19.dll
FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg10\Firefox
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg10\Firefox4
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Zynga Community Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R0 mrdd;Marvell Removable Disk Control Driver;c:\windows\system32\drivers\mrdd.sys [2009-6-18 18984]
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2009-4-12 152616]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 299984]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-6-18 532224]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192]
R3 DCamUSBNovatek;USB2.0 HD UVC Camera;c:\windows\system32\drivers\nvtcam.sys [2010-8-3 2697728]
R3 hidusbf;USB Mouse Rate Adjuster Lower Filter by SweetLow;c:\windows\system32\drivers\hidusbf.sys [2009-6-18 4544]
R3 hxctlflt;hxctlflt;c:\windows\system32\drivers\hxctlflt.sys [2010-8-3 99968]
R3 t3;Sound Blaster X-Fi Xtreme Audio;c:\windows\system32\drivers\t3.sys [2009-6-18 742936]
R3 t3filt;t3filt;c:\windows\system32\drivers\t3filt.sys [2009-6-18 1803136]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\waka\locals~1\temp\sas_selfextract\sasdifsv.sys --> c:\docume~1\waka\locals~1\temp\sas_selfextract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\waka\locals~1\temp\sas_selfextract\saskutil.sys --> c:\docume~1\waka\locals~1\temp\sas_selfextract\SASKUTIL.SYS [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\ambfilt.sys --> c:\windows\system32\drivers\Ambfilt.sys [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-9-24 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\common files\creative labs shared\service\MT6Licensing.exe [2010-12-11 79360]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2009-6-18 22784]
S3 guillflt;Guillemot Audio Lower Filter;c:\windows\system32\drivers\guillflt.sys [2010-8-3 54784]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2008-4-14 14336]
S3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [2007-4-11 45440]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-04-02 13:24:53 -------- d-----w- c:\docume~1\waka\applic~1\SUPERAntiSpyware.com
2011-04-02 13:24:53 -------- d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2011-04-01 19:22:37 3954 ----a-w- c:\windows\system32\tmp.reg
2011-04-01 19:14:27 82944 ----a-w- c:\program files\mozilla firefox\aproposfix\sed.exe
2011-04-01 19:14:27 126976 ----a-w- c:\program files\mozilla firefox\aproposfix\zip.exe
2011-04-01 19:14:27 103424 ----a-w- c:\program files\mozilla firefox\aproposfix\grep.exe
2011-04-01 18:20:31 -------- d-----w- c:\program files\FileASSASSIN
2011-03-14 05:29:45 -------- d-----w- c:\docume~1\waka\locals~1\applic~1\ApplicationHistory
2011-03-14 05:18:28 -------- d-----w- c:\docume~1\waka\applic~1\Windows Search
2011-03-14 05:14:16 -------- d-----w- c:\windows\system32\winrm
2011-03-14 05:14:12 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2011-03-14 05:13:00 -------- d-----w- c:\docume~1\waka\applic~1\Windows Desktop Search
2011-03-14 05:12:43 -------- d-----w- c:\program files\Windows Desktop Search
2011-03-14 05:11:07 -------- d-----w- c:\windows\system32\URTTEMP
2011-03-14 04:40:15 -------- d-----w- c:\windows\system32\XPSViewer
2011-03-14 03:59:48 -------- d-----w- c:\program files\VS Revo Group
2011-03-12 12:28:40 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-03-12 12:28:40 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2011-03-07 12:28:09 -------- d-----w- c:\documents and settings\waka\.android
.
==================== Find3M ====================
.
2011-03-30 04:59:52 266400 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-03-30 04:59:52 266400 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-03-30 04:47:26 270904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-03-28 22:27:30 241440 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-03-28 22:27:30 241440 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-03-28 22:27:30 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-02-19 23:03:12 421200 ----a-w- c:\windows\system32\msvcp100.dll
2011-02-19 00:40:50 773968 ----a-w- c:\windows\system32\msvcr100.dll
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-03 23:43:09 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-02-02 21:40:23 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-02 19:19:39 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
.
============= FINISH: 19:41:09.32 ===============

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 17/06/2009 23:39:20
System Uptime: 02/04/2011 15:37:43 (4 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P5Q
Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz | LGA 775 | 3204/358mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 69 GiB total, 11.357 GiB free.
D: is CDROM (UDF)
E: is FIXED (NTFS) - 932 GiB total, 731.973 GiB free.
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\17AC4251E8C00
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\17AC4251E8C00
Service: NIC1394
.
==== System Restore Points ===================
.
RP551: 14/03/2011 15:26:12 - Installed Mumble 1.2.4
RP552: 15/03/2011 22:39:32 - System Checkpoint
RP553: 19/03/2011 19:44:27 - System Checkpoint
RP554: 22/03/2011 17:35:51 - System Checkpoint
RP555: 23/03/2011 22:48:54 - System Checkpoint
RP556: 25/03/2011 00:42:20 - System Checkpoint
RP557: 25/03/2011 03:00:15 - Software Distribution Service 3.0
RP558: 25/03/2011 06:35:35 - Software Distribution Service 3.0
RP559: 26/03/2011 19:15:04 - System Checkpoint
RP560: 28/03/2011 11:04:17 - System Checkpoint
RP561: 29/03/2011 18:16:20 - System Checkpoint
RP562: 31/03/2011 17:49:46 - System Checkpoint
RP563: 01/04/2011 22:01:06 - System Checkpoint
RP564: 01/04/2011 23:33:35 - Restore Operation
RP565: 02/04/2011 14:09:48 - Removed AVG 2011
RP566: 02/04/2011 14:10:23 - Removed AVG 2011
RP567: 02/04/2011 14:43:38 - Installed AVG 2011
RP568: 02/04/2011 14:44:20 - Installed AVG 2011
.
==== Installed Programs ======================
.
7-Zip 4.65
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.3
Apple Application Support
Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
µTorrent
AVG 2011
Battlefield: Bad Company™ 2
CCleaner
Compatibility Pack for the 2007 Office system
Counter-Strike
Counter-Strike: Source
Counter-Strike: Source Beta
Creative Audio Control Panel
Creative Console Launcher
Creative Diagnostics
Creative Media Toolbox 6
Creative Media Toolbox 6 (Shared Components)
Creative MediaSource 5
Creative Software AutoUpdate
Creative WaveStudio 7
DivX Setup
FileASSASSIN
GIMP 2.6.11
HLSW v1.3.2.1
Host OpenAL
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
ImgBurn
Java Auto Updater
Java DB 10.5.3.0
Java(TM) 6 Update 16
Java(TM) 6 Update 24
Java(TM) SE Development Kit 6 Update 18
K-Lite Codec Pack 6.0.0 (Basic)
League of Legends
Left 4 Dead 2
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB24164

3
Contributors
37
Replies
40
Views
6 Years
Discussion Span
Last Post by crunchie
0

Btw, the Steam cache files I've deleted them and that's sorted my Steam problems out. Sorry for spam. :)

0

I've followed the sticky and here are the results:

Hi and welcome to the Daniweb forums :).

==========

You sort of followed the instructions, but you failed to update MBA-M. The latest database version is 6251 which makes your version ancient.
Please update and run again. Post the log when done.

0

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6253

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

03/04/2011 06:53:47
mbam-log-2011-04-03 (06-53-47).txt

Scan type: Full scan (C:\|)
Objects scanned: 260816
Time elapsed: 52 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Here you go. :)

0

Still nothing.

Download and Run ATF Cleaner
Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.

========

See if AVG still warns you.

Edited by crunchie: n/a

0

As soon as I re-initiated the broswer, I got the infection alert notification again.

Edited by Kingy1337: n/a

0

I've done the above and /so far/ I haven't recieved the message. Hopefully it'll stay like this. I'll give it until the end of the day before being sure it's solved. Thank you much in advance. :D

0

You are obviously going to a site that is infecting that file.
Delete the file again and take note of where you are when you get the warning.

0

You are obviously going to a site that is infecting that file.
Delete the file again and take note of where you are when you get the warning.

I agreed with what crunchie said, the site obviously contains harmful materials and may harm your computer. Follow crunchie advise and next time beware of website that looks suspicious, someimes it may seem that the website is not suspicious but just looking at the URL you can tell from a fake website to a real website. Good luck, try turning on your firewall

0

I closed the browser down, navigated my way to the file and the message popped up again. I deleted it through Fileassassin this time and it popped up again straight away. I've only been visiting mainstream sites such as Facebook. My firewall is running, just my Program Control is off through Zone Alarm. :(

Edited by Kingy1337: n/a

0

You mean after you delete the file, it still appears from nowwhere. The files may be download to your conputer without you knowing. Have you done a virus scan and try to remove the file?

0

Yes, exactly that. I did as it says in my first post. Both SUPERAntiSpyware and SpyBot picked up results. 99 and 6 respectively in Safemode. I Quarentined these and it recursively seems to have come back.

0

You said you q quarantine it, quarantine does not delete the threat have your select the oftion clean up threat or delete threat. Try these options first

0

Please Run the ESET Online Scanner and post the ScanLog with your post for assistance.

  • You will need to use Internet Explorer to complete this scan.
  • You will need to temporarily Disable your current Anti-virus program.
  • Be sure the option to Remove found threats is Un-checked at this time (we may have it clean what it finds at a later time), and the option to Scan unwanted applications is Checked.
  • When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.

NOTE: If you are unable to complete the ESET scan, please try another from the list below:

Kaspersky Online Scanner Panda Active Scan Trend Micro HouseCall F-Secure Online Virus Scanner

0

I ran SUPERAntiSpyware and Spybot in safe mode like 4 times and each times there would be threats after quarentining and removing the files which they were bing done already. Also there were threats in the: /application Settings/Cookies folder files. Even though this folder wouldn't show in the explorer view with 'show hidden folders' set to on. And had to be seen through the command/search line manually. Running ESET now btw.

0

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=09258a90bf732a4a884b4d1b7b4199b6
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-04-04 12:57:16
# local_time=2011-04-04 01:57:16 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1032 16777189 100 97 10094 59594612 0 0
# compatibility_mode=8192 67108863 100 0 111 111 0 0
# compatibility_mode=9217 16777214 75 70 14913932 24620636 0 0
# scanned=254840
# found=13
# cleaned=0
# scan_time=5277
C:\Documents and Settings\Waka\Desktop\SmitfraudFix.exe multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Waka\Desktop\SmitfraudFix\Process.exe Win32/PrcView application (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Waka\Desktop\SmitfraudFix\restart.exe Win32/Shutdown.NAA application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Mozilla Firefox\SmitfraudFix\Process.exe Win32/PrcView application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Mozilla Firefox\SmitfraudFix\restart.exe Win32/Shutdown.NAA application (unable to clean) 00000000000000000000000000000000 I
C:\WINDOWS\system32\Process.exe Win32/PrcView application (unable to clean) 00000000000000000000000000000000 I
E:\desktoppp\KingAMD\ccccc\usbmrs11.exe a variant of Win32/HackTool.Patcher.B application (unable to clean) 00000000000000000000000000000000 I
E:\desktoppp\KingAMD\Mouse-Settings\MOUSEHZ\xp\sp2\usbmrs11.exe a variant of Win32/HackTool.Patcher.B application (unable to clean) 00000000000000000000000000000000 I
E:\desktoppp\Sony Vegas Pro 8.0b Build 217-AVCHD-MPG-AC3 FIXED\Keygen.exe a variant of Win32/Keygen.AR application (unable to clean) 00000000000000000000000000000000 I
E:\My Documents\Downloads\SmitfraudFix.exe multiple threats (unable to clean) 00000000000000000000000000000000 I
E:\My Documents\Downloads\SmitfraudFix\Process.exe Win32/PrcView application (unable to clean) 00000000000000000000000000000000 I
E:\My Documents\Downloads\SmitfraudFix\restart.exe Win32/Shutdown.NAA application (unable to clean) 00000000000000000000000000000000 I
E:\My Documents\rknguiv102-standard\MOUSEHZ\xp\sp2\usbmrs11.exe a variant of Win32/HackTool.Patcher.B application (unable to clean) 00000000000000000000000000000000 I

0

See if you can delete this one:

E:\desktoppp\Sony Vegas Pro 8.0b Build 217-AVCHD-MPG-AC3 FIXED\Keygen.exe

Let me know if you deleted it ok.

Delete that file again and then immediately run ATF cleaner again.

0

Nope. I've had that .exe for over a year so I doubted it was that. Still getting the threat. Also, I swear it's throttling my 'net. My average ping ingame is around 80 now since this occured.

0

Download OTL to your Desktop.

* Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
* Under the Custom Scan box paste this in:


netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\System32\config\*.sav
CREATERESTOREPOINT

* Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
0

OTL logfile created on: 05/04/2011 11:03:32 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Waka\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.23 Gb Total Space | 11.70 Gb Free Space | 16.90% Space Free | Partition Type: NTFS
Drive D: | 5.40 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 931.51 Gb Total Space | 733.31 Gb Free Space | 78.72% Space Free | Partition Type: NTFS

Computer Name: KINGY | User Name: Waka | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/05 10:42:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
PRC - [2011/04/02 19:32:52 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2011/01/07 02:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/01/07 02:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/01/07 02:22:12 | 001,052,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2011/01/06 16:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/01/06 16:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/12/05 17:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 17:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/10/22 05:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/10/22 05:56:58 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2010/09/16 21:04:06 | 001,164,584 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/06/23 13:52:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2010/06/23 13:51:30 | 001,043,968 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2009/01/02 23:51:42 | 001,427,968 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2011/04/05 10:42:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
MOD - [2010/08/23 17:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/02/02 11:57:54 | 000,052,288 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus(R)
SRV - [2011/01/06 16:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/12/11 21:41:48 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe -- (Creative Media Toolbox 6 Licensing Service)
SRV - [2010/10/22 05:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/09/24 05:38:36 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010/06/23 13:52:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
SRV - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)


========== Driver Services (SafeList) ==========

DRV - [2011/04/04 17:50:41 | 000,140,248 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK)
DRV - [2010/12/08 05:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/11/12 14:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/13 16:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/19 21:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/08/19 21:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/19 21:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/05/13 10:02:32 | 000,532,224 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2009/11/03 15:57:47 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/07/30 19:53:54 | 002,697,728 | ---- | M] (NTK) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvtcam.sys -- (DCamUSBNovatek)
DRV - [2009/06/18 03:46:11 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009/06/04 10:34:06 | 000,054,784 | ---- | M] (Guillemot Corp S.A.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\guillflt.sys -- (guillflt)
DRV - [2009/05/06 03:36:12 | 000,742,936 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\t3.sys -- (t3)
DRV - [2009/04/12 13:08:22 | 000,209,200 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\Si3114r5.sys -- (Si3114r5)
DRV - [2009/02/27 10:45:30 | 000,171,008 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctusfsyn.sys -- (CTUSFSYN)
DRV - [2009/02/09 03:30:00 | 000,152,616 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mv61xx.sys -- (mv61xx)
DRV - [2009/02/08 23:42:42 | 000,099,968 | ---- | M] (Guillemot Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hxctlflt.sys -- (hxctlflt)
DRV - [2009/02/05 09:34:16 | 001,803,136 | ---- | M] (Creative) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\t3filt.sys -- (t3filt)
DRV - [2009/01/14 10:47:24 | 000,142,336 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2009/01/14 10:47:24 | 000,114,688 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2009/01/14 03:47:24 | 000,008,704 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Pfmodnt.sys -- (PfModNT)
DRV - [2008/11/12 07:52:36 | 000,018,984 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mrdd.sys -- (mrdd)
DRV - [2008/06/26 00:47:00 | 000,036,864 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1e51x86.sys -- (L1e)
DRV - [2007/12/17 17:14:06 | 000,012,400 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2007/08/02 17:32:26 | 000,022,784 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dadder.sys -- (DAdderFltr)
DRV - [2007/04/11 17:23:48 | 000,045,440 | ---- | M] (Razer USA Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\UsbFltr.sys -- (TarFltr)
DRV - [2006/11/08 21:19:18 | 000,004,544 | ---- | M] (SweetLow) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hidusbf.sys -- (hidusbf)
DRV - [2004/08/13 10:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:3.3.3.2

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/30 23:12:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/04/02 14:45:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/29 03:53:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 03:34:02 | 000,000,000 | ---D | M]

[2009/08/25 03:23:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Extensions
[2009/08/25 03:23:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Extensions\{2f1e6a90-e99e-11dd-ba2f-0800200c9a66}
[2009/06/29 20:49:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2011/04/04 17:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Firefox\Profiles\ldfpmils.default\extensions
[2010/08/23 21:10:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Firefox\Profiles\ldfpmils.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/25 00:30:22 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Firefox\Profiles\ldfpmils.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/04/04 17:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/15 22:39:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/16 02:11:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/15 22:51:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/15 21:55:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/15 23:56:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/15 22:39:39 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/12 16:35:56 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/12 16:35:56 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/12 16:35:56 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/12 16:35:56 | 000,000,831 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/04/04 11:27:17 | 000,431,524 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14855 more lines...
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe ()
O4 - HKLM..\Run: [ASUS Update Checker] C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QFan Help] C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe ()
O4 - HKLM..\Run: [SPIRun] C:\WINDOWS\System32\SPIRun.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Waka\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Waka\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/17 23:37:54 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/02/10 02:55:59 | 000,423,304 | R--- | M] (Electronic Arts) - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 07:21:09 | 000,000,000 | R--D | M] - D:\Autorun -- [ CDFS ]
O32 - AutoRun File - [2010/01/31 09:21:13 | 000,367,686 | R--- | M] () - D:\Autorun.ico -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 03:55:03 | 009,965,568 | R--- | M] () - D:\autorun.dat -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 03:54:55 | 000,000,155 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{096a3f4b-5b95-11de-b73f-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{096a3f4b-5b95-11de-b73f-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{096a3f4b-5b95-11de-b73f-806d6172696f}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- [2010/02/10 02:55:59 | 000,423,304 | R--- | M] (Electronic Arts)
O33 - MountPoints2\{6f2086a6-d3e3-11df-b31d-001d0fb062cc}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Installer.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/05 10:42:33 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
[2011/04/04 13:15:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\AVG
[2011/04/04 13:12:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011
[2011/04/04 12:27:27 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/04/04 11:02:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\SmitfraudFix
[2011/04/03 04:24:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\practical9
[2011/04/02 14:35:34 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW
[2011/04/02 14:28:54 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\TFC.exe
[2011/04/02 14:24:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\SUPERAntiSpyware.com
[2011/04/02 14:24:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/04/02 14:07:20 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/01 20:19:17 | 000,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2011/04/01 20:19:16 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe
[2011/04/01 20:19:16 | 000,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe
[2011/04/01 20:19:16 | 000,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe
[2011/04/01 20:19:15 | 000,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe
[2011/04/01 20:19:15 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe
[2011/04/01 20:19:14 | 000,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe
[2011/04/01 20:19:14 | 000,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe
[2011/04/01 20:19:13 | 000,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe
[2011/04/01 20:19:11 | 000,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe
[2011/04/01 20:19:10 | 000,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe
[2011/04/01 19:20:31 | 000,000,000 | ---D | C] -- C:\Program Files\FileASSASSIN
[2011/04/01 19:20:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FileASSASSIN
[2011/04/01 17:38:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/03/30 06:06:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Start Menu\Programs\StarCraft II
[2011/03/30 00:22:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\practical8
[2011/03/27 02:02:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\ImgBurn
[2011/03/27 01:57:32 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2011/03/27 01:57:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn
[2011/03/21 17:56:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\practical7
[2011/03/19 04:35:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\hoes_files
[2011/03/18 01:54:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\Exec
[2011/03/16 00:06:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\testjava
[2011/03/14 06:53:15 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Waka\Start Menu\Programs\Administrative Tools
[2011/03/14 06:40:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/03/14 06:39:45 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2011/03/14 06:29:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Local Settings\Application Data\ApplicationHistory
[2011/03/14 06:18:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\Windows Search
[2011/03/14 06:18:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2011/03/14 06:15:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2011/03/14 06:14:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm
[2011/03/14 06:14:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell
[2011/03/14 06:14:12 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$
[2011/03/14 06:13:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\Windows Desktop Search
[2011/03/14 06:12:43 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2011/03/14 06:11:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2011/03/14 05:40:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2011/03/14 04:59:48 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2011/03/14 04:59:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Start Menu\Programs\Revo Uninstaller
[2011/03/14 02:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\prac6
[2011/03/07 23:53:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\prac5
[2011/03/07 13:28:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\.android
[1 C:\Documents and Settings\Waka\Desktop\*.tmp files -> C:\Documents and Settings\Waka\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/05 10:42:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
[2011/04/05 09:51:23 | 111,693,519 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/04/05 08:13:26 | 000,000,543 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2011/04/05 07:49:05 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/05 07:36:40 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2011/04/04 17:50:41 | 000,140,248 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/04/04 17:50:36 | 000,266,400 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr
[2011/04/04 16:42:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/04 16:42:16 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2011/04/04 16:42:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/04 13:12:45 | 000,000,848 | ---- | M] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2011/04/04 13:12:45 | 000,000,830 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/04 11:27:17 | 000,431,524 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/04 11:06:40 | 000,003,954 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2011/04/04 11:06:37 | 000,431,398 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110404-112717.backup
[2011/04/03 15:15:31 | 000,236,661 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\RelativeResourceManager.pdf
[2011/04/03 06:02:14 | 000,266,400 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.ex0
[2011/04/02 16:47:44 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\7327fcpt.exe
[2011/04/02 16:42:45 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\w4bjdjhx.exe
[2011/04/02 16:42:35 | 000,625,664 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\dds.scr
[2011/04/02 14:45:23 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/04/02 14:28:55 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\TFC.exe
[2011/04/02 14:24:36 | 014,336,632 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\SAS_7751.COM
[2011/04/02 05:23:22 | 000,266,328 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\gifts-year-old-girl-800X800.jpg
[2011/04/01 20:17:42 | 001,885,088 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\SmitfraudFix.exe
[2011/04/01 19:20:31 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FileASSASSIN.lnk
[2011/04/01 17:38:04 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/04/01 17:38:04 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\Spybot - Search & Destroy.lnk
[2011/03/30 23:21:03 | 000,921,654 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\untitled.bmp
[2011/03/30 23:04:59 | 000,050,198 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\practical7.rar
[2011/03/30 15:53:31 | 000,587,158 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/30 15:53:31 | 000,123,580 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/30 04:58:40 | 000,022,683 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\practical8.rar
[2011/03/30 03:49:28 | 000,009,006 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\binarypic1.PNG
[2011/03/29 18:50:38 | 000,083,484 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\wakkaaa11.jpg
[2011/03/28 23:27:30 | 000,241,440 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/03/28 23:27:30 | 000,241,440 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/03/28 23:27:30 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/03/27 01:57:37 | 000,001,546 | ---- | M] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/27 01:57:36 | 000,001,528 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/03/25 06:50:22 | 002,574,294 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94707__x_2ch-games-with-nice-oppai-oshiri-part-2-033.gif
[2011/03/25 06:50:18 | 003,151,846 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94706__x_2ch-games-with-nice-oppai-oshiri-part-2-032.gif
[2011/03/25 06:50:10 | 002,328,932 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94702__x_2ch-games-with-nice-oppai-oshiri-part-2-030.gif
[2011/03/25 06:50:07 | 003,350,884 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94700__x_2ch-games-with-nice-oppai-oshiri-part-2-029.gif
[2011/03/25 03:34:02 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/03/19 04:35:52 | 000,083,869 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\hoes.htm
[2011/03/18 22:54:15 | 000,137,515 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\259760527.jpg
[2011/03/18 06:31:40 | 000,000,239 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\2.java
[2011/03/18 03:54:17 | 000,052,936 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\wakaela1.jpg
[2011/03/15 06:10:49 | 000,137,856 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\MathsCW1.pdf
[2011/03/14 23:40:22 | 000,004,823 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\maths1111.PNG
[2011/03/14 16:26:25 | 000,000,656 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mumble.lnk
[2011/03/14 06:30:18 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/03/14 06:12:47 | 000,001,787 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/03/14 05:44:01 | 000,232,776 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/14 04:59:48 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\Revo Uninstaller.lnk
[2011/03/14 02:20:05 | 000,017,018 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\prac6.zip
[2011/03/09 01:25:23 | 000,015,889 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\prac5.rar
[2011/03/08 05:45:26 | 000,735,866 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\lonely-risa-wanko-to-kurasou.png
[2011/03/08 05:36:22 | 000,057,901 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\34071.jpg
[1 C:\Documents and Settings\Waka\Desktop\*.tmp files -> C:\Documents and Settings\Waka\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/04 13:12:45 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2011/04/04 13:12:45 | 000,000,830 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/02 16:47:44 | 000,301,568 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\7327fcpt.exe
[2011/04/02 16:42:44 | 000,301,568 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\w4bjdjhx.exe
[2011/04/02 16:42:34 | 000,625,664 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\dds.scr
[2011/04/02 16:13:09 | 001,885,088 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\SmitfraudFix.exe
[2011/04/02 14:23:32 | 014,336,632 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\SAS_7751.COM
[2011/04/02 05:23:20 | 000,266,328 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\gifts-year-old-girl-800X800.jpg
[2011/04/01 20:22:37 | 000,003,954 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2011/04/01 20:19:15 | 000,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe
[2011/04/01 20:19:13 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe
[2011/04/01 20:19:12 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe
[2011/04/01 19:20:31 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\FileASSASSIN.lnk
[2011/04/01 17:38:04 | 000,000,951 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/04/01 17:38:04 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\Spybot - Search & Destroy.lnk
[2011/03/30 23:20:49 | 000,921,654 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\untitled.bmp
[2011/03/30 04:22:16 | 000,022,683 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\practical8.rar
[2011/03/30 03:49:28 | 000,009,006 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\binarypic1.PNG
[2011/03/29 18:50:37 | 000,083,484 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\wakkaaa11.jpg
[2011/03/27 05:09:48 | 001,839,104 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\mt420.iso
[2011/03/27 01:57:37 | 000,001,546 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/27 01:57:36 | 000,001,528 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/03/25 06:50:22 | 002,574,294 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94707__x_2ch-games-with-nice-oppai-oshiri-part-2-033.gif
[2011/03/25 06:50:17 | 003,151,846 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94706__x_2ch-games-with-nice-oppai-oshiri-part-2-032.gif
[2011/03/25 06:50:10 | 002,328,932 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94702__x_2ch-games-with-nice-oppai-oshiri-part-2-030.gif
[2011/03/25 06:50:06 | 003,350,884 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94700__x_2ch-games-with-nice-oppai-oshiri-part-2-029.gif
[2011/03/23 08:16:41 | 018,604,442 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\Fire In The Booth _Charlie Sloth_ Radio.mp3
[2011/03/23 08:16:37 | 002,865,849 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\22 - Subzero & Pyper - Audio Music Star - Bassline Mix CD.mp3
[2011/03/23 02:12:16 | 000,050,198 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\practical7.rar
[2011/03/19 04:35:50 | 000,083,869 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\hoes.htm
[2011/03/18 22:54:15 | 000,137,515 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\259760527.jpg
[2011/03/18 06:31:40 | 000,000,239 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\2.java
[2011/03/18 03:54:16 | 000,052,936 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\wakaela1.jpg
[2011/03/14 23:40:22 | 000,004,823 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\maths1111.PNG
[2011/03/14 23:38:24 | 000,137,856 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\MathsCW1.pdf
[2011/03/14 06:15:35 | 000,001,077 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live ID.lnk
[2011/03/14 06:12:47 | 000,001,803 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Search.lnk
[2011/03/14 06:12:47 | 000,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/03/14 04:59:48 | 000,000,917 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\Revo Uninstaller.lnk
[2011/03/14 02:20:04 | 000,017,018 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\prac6.zip
[2011/03/10 03:32:48 | 000,236,661 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\RelativeResourceManager.pdf
[2011/03/09 01:25:23 | 000,015,889 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\prac5.rar
[2011/03/08 05:45:25 | 000,735,866 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\lonely-risa-wanko-to-kurasou.png
[2011/03/08 05:36:21 | 000,057,901 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\34071.jpg
[2011/03/06 04:50:31 | 000,000,075 | ---- | C] () -- C:\WINDOWS\System32\nvUnsupRes.dat
[2011/02/18 23:17:07 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Waka\Local Settings\Application Data\PUTTY.RND
[2010/10/29 01:10:14 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/10/29 01:10:14 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/10/14 02:36:44 | 000,179,263 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2010/10/13 22:06:27 | 000,241,440 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/10/13 22:06:01 | 000,241,440 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/10/13 22:06:01 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/10/13 22:05:33 | 002,293,194 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/09/18 14:03:52 | 000,669,184 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2010/08/03 14:30:33 | 000,002,278 | ---- | C] () -- C:\WINDOWS\System32\Cam122.ini
[2010/07/17 21:02:51 | 000,000,004 | -H-- | C] () -- C:\WINDOWS\ujspa.sys
[2010/06/02 00:49:58 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/05/14 23:29:15 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/04/17 20:19:26 | 000,047,204 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/04/02 16:14:15 | 000,140,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/04/02 16:13:45 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\PnkBstrK.sys
[2010/04/02 16:12:56 | 000,266,400 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2010/04/02 16:12:26 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
[2010/04/02 16:12:26 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2010/03/02 07:51:08 | 000,000,080 | RHS- | C] () -- C:\WINDOWS\System32\60F61203DC.dll
[2009/11/03 16:07:30 | 000,000,219 | ---- | C] () -- C:\WINDOWS\ACTIVEJP.INI
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/11 19:20:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/07/07 02:23:10 | 000,018,944 | ---- | C] () -- C:\Documents and Settings\Waka\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/04 02:18:13 | 000,781,312 | ---- | C] () -- C:\WINDOWS\System32\RGSS102J.dll
[2009/07/04 02:18:13 | 000,778,752 | ---- | C] () -- C:\WINDOWS\System32\RGSS102E.dll
[2009/07/04 02:18:13 | 000,771,584 | ---- | C] () -- C:\WINDOWS\System32\RGSS100J.dll
[2009/07/04 02:18:13 | 000,685,056 | ---- | C] () -- C:\WINDOWS\System32\RGSS103J.dll
[2009/07/01 03:40:03 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/06/29 20:57:47 | 000,133,632 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2009/06/18 16:24:43 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/06/18 13:03:52 | 000,032,914 | ---- | C] () -- C:\WINDOWS\System32\t3.ini
[2009/06/18 13:03:52 | 000,000,049 | R--- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2009/06/18 13:03:11 | 000,145,920 | ---- | C] () -- C:\WINDOWS\System32\OemSpi.dll
[2009/06/18 13:03:11 | 000,118,850 | ---- | C] () -- C:\WINDOWS\System32\CTPcie.dll
[2009/06/18 13:03:11 | 000,008,535 | ---- | C] () -- C:\WINDOWS\sfsyn.ini
[2009/06/18 03:44:31 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/18 03:26:11 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2009/06/18 03:26:11 | 000,012,400 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2009/06/18 03:26:10 | 000,011,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2009/06/18 03:26:10 | 000,010,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2009/06/18 03:25:50 | 000,005,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/06/18 03:11:30 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2009/06/18 00:58:10 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/06/18 00:58:08 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2009/06/18 00:25:57 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/06/18 00:22:50 | 000,232,776 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/18 00:22:00 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2009/06/17 23:39:23 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/06/17 23:35:34 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/05/26 22:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 22:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 05:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007/09/27 11:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/12/31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/18 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/18 12:00:00 | 000,587,158 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/18 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/18 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/18 12:00:00 | 000,123,580 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/18 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/18 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/18 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2009/10/18 03:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2DBoy
[2011/04/02 14:45:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/19 12:14:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/19 12:19:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2009/11/03 15:57:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/04/02 14:41:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/02/03 16:15:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nHancer
[2011/01/19 07:43:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/04/04 15:11:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/18 01:52:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
[2011/01/30 00:36:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\.minecraft
[2011/04/04 14:16:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\AVG
[2010/10/19 12:21:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\AVG10
[2009/11/03 16:06:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\DAEMON Tools Lite
[2010/03/02 07:54:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\DJJava
[2011/02/27 15:48:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\gtk-2.0
[2010/07/10 03:35:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\HLSW
[2011/03/27 02:03:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\ImgBurn
[2011/01/21 02:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\LolClient
[2011/04/05 00:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Mumble
[2010/02/03 16:15:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\nHancer
[2010/02/23 23:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Notepad++
[2009/12/17 01:24:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\OpenOffice.org
[2009/11/18 18:45:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Processing
[2009/08/25 03:23:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Scendix Software
[2010/12/08 16:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\SmartDraw
[2011/03/05 04:44:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Spotify
[2010/10/13 21:35:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\SystemRequirementsLab
[2010/07/14 00:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\TS3Client
[2010/12/11 20:46:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Uniblue
[2011/03/19 07:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\uTorrent
[2011/03/14 06:13:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Windows Desktop Search
[2011/03/14 06:18:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Windows Search
[2011/04/04 16:42:16 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: AHCIX86.SYS >
[2009/04/12 13:08:20 | 000,113,152 | ---- | M] (ATI Technologies Inc.) MD5=9FACB9D43EC53F54386DAE74A175AE53 -- C:\WINDOWS\NLDRV\007\ahcix86.sys

< MD5 for: ATAPI.SYS >
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\system32\DRIVERS\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2009/04/12 13:08:15 | 000,874,240 | ---- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B -- C:\WINDOWS\NLDRV\005\iastor.sys
[2009/04/12 13:08:18 | 000,308,248 | ---- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F -- C:\WINDOWS\NLDRV\006\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: NVATABUS.SYS >
[2009/04/12 13:08:07 | 000,105,472 | ---- | M] (NVIDIA Corporation) MD5=6B37162E91A7005BAA753CB611ACEA2D -- C:\WINDOWS\NLDRV\003\nvatabus.sys

< MD5 for: NVGTS.SYS >
[2009/04/12 13:08:11 | 000,102,400 | ---- | M] (NVIDIA Corporation) MD5=1F790624AB1619CAE0C78597BD33615B -- C:\WINDOWS\NLDRV\004\nvgts.sys
[2009/04/12 13:08:03 | 000,107,520 | ---- | M] (NVIDIA Corporation) MD5=20E15B182DE3EFDFEA3AECB86A04E5CA -- C:\WINDOWS\NLDRV\002\nvgts.sys

< MD5 for: SCECLI.DLL >
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: VIAMRAID.SYS >
[2009/04/12 13:08:30 | 000,116,688 | ---- | M] (VIA Technologies inc,.ltd) MD5=68B41DFA083C2734340BA254532700F3 -- C:\WINDOWS\NLDRV\013\viamraid.sys
[2009/04/12 13:08:28 | 000,102,912 | ---- | M] (VIA Technologies inc,.ltd) MD5=7DC3E1DC6E4F8BE381C31BFEA578412A -- C:\WINDOWS\NLDRV\012\viamraid.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/06/18 00:22:04 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/06/18 00:22:04 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/06/18 00:22:04 | 000,950,272 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

========== Files - Unicode (All) ==========
[2011/02/22 22:37:50 | 000,411,905 | ---- | M] ()(C:\Documents and Settings\Waka\Desktop\QQ?????.png) -- C:\Documents and Settings\Waka\Desktop\QQ截图未命名.png
[2011/02/22 22:37:42 | 000,411,905 | ---- | C] ()(C:\Documents and Settings\Waka\Desktop\QQ?????.png) -- C:\Documents and Settings\Waka\Desktop\QQ截图未命名.png

========== Alternate Data Streams ==========

@Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:4E17D6D2B619558D
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

I kind of messed up and ran it the first time with FireFox and WoW open and it created the primary file and the extra files. I shut down everything properly and reloaded the program yet this time, after the scan, it didn't create an Extras.txt file. :(

0

OTL logfile created on: 05/04/2011 11:03:32 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Waka\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.23 Gb Total Space | 11.70 Gb Free Space | 16.90% Space Free | Partition Type: NTFS
Drive D: | 5.40 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 931.51 Gb Total Space | 733.31 Gb Free Space | 78.72% Space Free | Partition Type: NTFS

Computer Name: KINGY | User Name: Waka | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/05 10:42:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
PRC - [2011/04/02 19:32:52 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2011/01/07 02:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/01/07 02:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/01/07 02:22:12 | 001,052,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2011/01/06 16:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/01/06 16:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/12/05 17:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 17:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/10/22 05:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/10/22 05:56:58 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2010/09/16 21:04:06 | 001,164,584 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/06/23 13:52:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2010/06/23 13:51:30 | 001,043,968 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2009/01/02 23:51:42 | 001,427,968 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2011/04/05 10:42:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
MOD - [2010/08/23 17:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/02/02 11:57:54 | 000,052,288 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus(R)
SRV - [2011/01/06 16:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/12/11 21:41:48 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe -- (Creative Media Toolbox 6 Licensing Service)
SRV - [2010/10/22 05:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/09/24 05:38:36 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010/06/23 13:52:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
SRV - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)


========== Driver Services (SafeList) ==========

DRV - [2011/04/04 17:50:41 | 000,140,248 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK)
DRV - [2010/12/08 05:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/11/12 14:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/13 16:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/19 21:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/08/19 21:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/19 21:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/05/13 10:02:32 | 000,532,224 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2009/11/03 15:57:47 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/07/30 19:53:54 | 002,697,728 | ---- | M] (NTK) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvtcam.sys -- (DCamUSBNovatek)
DRV - [2009/06/18 03:46:11 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009/06/04 10:34:06 | 000,054,784 | ---- | M] (Guillemot Corp S.A.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\guillflt.sys -- (guillflt)
DRV - [2009/05/06 03:36:12 | 000,742,936 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\t3.sys -- (t3)
DRV - [2009/04/12 13:08:22 | 000,209,200 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\Si3114r5.sys -- (Si3114r5)
DRV - [2009/02/27 10:45:30 | 000,171,008 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctusfsyn.sys -- (CTUSFSYN)
DRV - [2009/02/09 03:30:00 | 000,152,616 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mv61xx.sys -- (mv61xx)
DRV - [2009/02/08 23:42:42 | 000,099,968 | ---- | M] (Guillemot Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hxctlflt.sys -- (hxctlflt)
DRV - [2009/02/05 09:34:16 | 001,803,136 | ---- | M] (Creative) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\t3filt.sys -- (t3filt)
DRV - [2009/01/14 10:47:24 | 000,142,336 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2009/01/14 10:47:24 | 000,114,688 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2009/01/14 03:47:24 | 000,008,704 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Pfmodnt.sys -- (PfModNT)
DRV - [2008/11/12 07:52:36 | 000,018,984 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mrdd.sys -- (mrdd)
DRV - [2008/06/26 00:47:00 | 000,036,864 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1e51x86.sys -- (L1e)
DRV - [2007/12/17 17:14:06 | 000,012,400 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2007/08/02 17:32:26 | 000,022,784 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dadder.sys -- (DAdderFltr)
DRV - [2007/04/11 17:23:48 | 000,045,440 | ---- | M] (Razer USA Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\UsbFltr.sys -- (TarFltr)
DRV - [2006/11/08 21:19:18 | 000,004,544 | ---- | M] (SweetLow) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hidusbf.sys -- (hidusbf)
DRV - [2004/08/13 10:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:3.3.3.2

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/30 23:12:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/04/02 14:45:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/29 03:53:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 03:34:02 | 000,000,000 | ---D | M]

[2009/08/25 03:23:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Extensions
[2009/08/25 03:23:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Extensions\{2f1e6a90-e99e-11dd-ba2f-0800200c9a66}
[2009/06/29 20:49:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2011/04/04 17:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Firefox\Profiles\ldfpmils.default\extensions
[2010/08/23 21:10:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Firefox\Profiles\ldfpmils.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/25 00:30:22 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Firefox\Profiles\ldfpmils.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/04/04 17:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/15 22:39:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/16 02:11:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/15 22:51:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/15 21:55:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/15 23:56:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/15 22:39:39 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/12 16:35:56 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/12 16:35:56 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/12 16:35:56 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/12 16:35:56 | 000,000,831 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/04/04 11:27:17 | 000,431,524 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14855 more lines...
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe ()
O4 - HKLM..\Run: [ASUS Update Checker] C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QFan Help] C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe ()
O4 - HKLM..\Run: [SPIRun] C:\WINDOWS\System32\SPIRun.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Waka\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Waka\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/17 23:37:54 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/02/10 02:55:59 | 000,423,304 | R--- | M] (Electronic Arts) - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 07:21:09 | 000,000,000 | R--D | M] - D:\Autorun -- [ CDFS ]
O32 - AutoRun File - [2010/01/31 09:21:13 | 000,367,686 | R--- | M] () - D:\Autorun.ico -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 03:55:03 | 009,965,568 | R--- | M] () - D:\autorun.dat -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 03:54:55 | 000,000,155 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{096a3f4b-5b95-11de-b73f-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{096a3f4b-5b95-11de-b73f-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{096a3f4b-5b95-11de-b73f-806d6172696f}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- [2010/02/10 02:55:59 | 000,423,304 | R--- | M] (Electronic Arts)
O33 - MountPoints2\{6f2086a6-d3e3-11df-b31d-001d0fb062cc}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Installer.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/05 10:42:33 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
[2011/04/04 13:15:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\AVG
[2011/04/04 13:12:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011
[2011/04/04 12:27:27 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/04/04 11:02:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\SmitfraudFix
[2011/04/03 04:24:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\practical9
[2011/04/02 14:35:34 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW
[2011/04/02 14:28:54 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\TFC.exe
[2011/04/02 14:24:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\SUPERAntiSpyware.com
[2011/04/02 14:24:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/04/02 14:07:20 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/01 20:19:17 | 000,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2011/04/01 20:19:16 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe
[2011/04/01 20:19:16 | 000,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe
[2011/04/01 20:19:16 | 000,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe
[2011/04/01 20:19:15 | 000,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe
[2011/04/01 20:19:15 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe
[2011/04/01 20:19:14 | 000,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe
[2011/04/01 20:19:14 | 000,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe
[2011/04/01 20:19:13 | 000,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe
[2011/04/01 20:19:11 | 000,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe
[2011/04/01 20:19:10 | 000,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe
[2011/04/01 19:20:31 | 000,000,000 | ---D | C] -- C:\Program Files\FileASSASSIN
[2011/04/01 19:20:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FileASSASSIN
[2011/04/01 17:38:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/03/30 06:06:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Start Menu\Programs\StarCraft II
[2011/03/30 00:22:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\practical8
[2011/03/27 02:02:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\ImgBurn
[2011/03/27 01:57:32 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2011/03/27 01:57:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn
[2011/03/21 17:56:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\practical7
[2011/03/19 04:35:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\hoes_files
[2011/03/18 01:54:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\Exec
[2011/03/16 00:06:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\testjava
[2011/03/14 06:53:15 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Waka\Start Menu\Programs\Administrative Tools
[2011/03/14 06:40:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/03/14 06:39:45 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2011/03/14 06:29:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Local Settings\Application Data\ApplicationHistory
[2011/03/14 06:18:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\Windows Search
[2011/03/14 06:18:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2011/03/14 06:15:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2011/03/14 06:14:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm
[2011/03/14 06:14:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell
[2011/03/14 06:14:12 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$
[2011/03/14 06:13:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\Windows Desktop Search
[2011/03/14 06:12:43 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2011/03/14 06:11:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2011/03/14 05:40:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2011/03/14 04:59:48 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2011/03/14 04:59:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Start Menu\Programs\Revo Uninstaller
[2011/03/14 02:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\prac6
[2011/03/07 23:53:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\prac5
[2011/03/07 13:28:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\.android
[1 C:\Documents and Settings\Waka\Desktop\*.tmp files -> C:\Documents and Settings\Waka\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/05 10:42:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
[2011/04/05 09:51:23 | 111,693,519 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/04/05 08:13:26 | 000,000,543 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2011/04/05 07:49:05 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/05 07:36:40 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2011/04/04 17:50:41 | 000,140,248 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/04/04 17:50:36 | 000,266,400 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr
[2011/04/04 16:42:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/04 16:42:16 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2011/04/04 16:42:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/04 13:12:45 | 000,000,848 | ---- | M] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2011/04/04 13:12:45 | 000,000,830 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/04 11:27:17 | 000,431,524 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/04 11:06:40 | 000,003,954 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2011/04/04 11:06:37 | 000,431,398 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110404-112717.backup
[2011/04/03 15:15:31 | 000,236,661 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\RelativeResourceManager.pdf
[2011/04/03 06:02:14 | 000,266,400 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.ex0
[2011/04/02 16:47:44 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\7327fcpt.exe
[2011/04/02 16:42:45 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\w4bjdjhx.exe
[2011/04/02 16:42:35 | 000,625,664 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\dds.scr
[2011/04/02 14:45:23 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/04/02 14:28:55 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\TFC.exe
[2011/04/02 14:24:36 | 014,336,632 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\SAS_7751.COM
[2011/04/02 05:23:22 | 000,266,328 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\gifts-year-old-girl-800X800.jpg
[2011/04/01 20:17:42 | 001,885,088 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\SmitfraudFix.exe
[2011/04/01 19:20:31 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FileASSASSIN.lnk
[2011/04/01 17:38:04 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/04/01 17:38:04 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\Spybot - Search & Destroy.lnk
[2011/03/30 23:21:03 | 000,921,654 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\untitled.bmp
[2011/03/30 23:04:59 | 000,050,198 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\practical7.rar
[2011/03/30 15:53:31 | 000,587,158 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/30 15:53:31 | 000,123,580 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/30 04:58:40 | 000,022,683 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\practical8.rar
[2011/03/30 03:49:28 | 000,009,006 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\binarypic1.PNG
[2011/03/29 18:50:38 | 000,083,484 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\wakkaaa11.jpg
[2011/03/28 23:27:30 | 000,241,440 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/03/28 23:27:30 | 000,241,440 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/03/28 23:27:30 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/03/27 01:57:37 | 000,001,546 | ---- | M] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/27 01:57:36 | 000,001,528 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/03/25 06:50:22 | 002,574,294 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94707__x_2ch-games-with-nice-oppai-oshiri-part-2-033.gif
[2011/03/25 06:50:18 | 003,151,846 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94706__x_2ch-games-with-nice-oppai-oshiri-part-2-032.gif
[2011/03/25 06:50:10 | 002,328,932 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94702__x_2ch-games-with-nice-oppai-oshiri-part-2-030.gif
[2011/03/25 06:50:07 | 003,350,884 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94700__x_2ch-games-with-nice-oppai-oshiri-part-2-029.gif
[2011/03/25 03:34:02 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/03/19 04:35:52 | 000,083,869 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\hoes.htm
[2011/03/18 22:54:15 | 000,137,515 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\259760527.jpg
[2011/03/18 06:31:40 | 000,000,239 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\2.java
[2011/03/18 03:54:17 | 000,052,936 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\wakaela1.jpg
[2011/03/15 06:10:49 | 000,137,856 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\MathsCW1.pdf
[2011/03/14 23:40:22 | 000,004,823 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\maths1111.PNG
[2011/03/14 16:26:25 | 000,000,656 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mumble.lnk
[2011/03/14 06:30:18 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/03/14 06:12:47 | 000,001,787 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/03/14 05:44:01 | 000,232,776 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/14 04:59:48 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\Revo Uninstaller.lnk
[2011/03/14 02:20:05 | 000,017,018 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\prac6.zip
[2011/03/09 01:25:23 | 000,015,889 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\prac5.rar
[2011/03/08 05:45:26 | 000,735,866 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\lonely-risa-wanko-to-kurasou.png
[2011/03/08 05:36:22 | 000,057,901 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\34071.jpg
[1 C:\Documents and Settings\Waka\Desktop\*.tmp files -> C:\Documents and Settings\Waka\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/04 13:12:45 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2011/04/04 13:12:45 | 000,000,830 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/02 16:47:44 | 000,301,568 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\7327fcpt.exe
[2011/04/02 16:42:44 | 000,301,568 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\w4bjdjhx.exe
[2011/04/02 16:42:34 | 000,625,664 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\dds.scr
[2011/04/02 16:13:09 | 001,885,088 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\SmitfraudFix.exe
[2011/04/02 14:23:32 | 014,336,632 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\SAS_7751.COM
[2011/04/02 05:23:20 | 000,266,328 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\gifts-year-old-girl-800X800.jpg
[2011/04/01 20:22:37 | 000,003,954 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2011/04/01 20:19:15 | 000,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe
[2011/04/01 20:19:13 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe
[2011/04/01 20:19:12 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe
[2011/04/01 19:20:31 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\FileASSASSIN.lnk
[2011/04/01 17:38:04 | 000,000,951 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/04/01 17:38:04 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\Spybot - Search & Destroy.lnk
[2011/03/30 23:20:49 | 000,921,654 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\untitled.bmp
[2011/03/30 04:22:16 | 000,022,683 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\practical8.rar
[2011/03/30 03:49:28 | 000,009,006 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\binarypic1.PNG
[2011/03/29 18:50:37 | 000,083,484 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\wakkaaa11.jpg
[2011/03/27 05:09:48 | 001,839,104 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\mt420.iso
[2011/03/27 01:57:37 | 000,001,546 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/27 01:57:36 | 000,001,528 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/03/25 06:50:22 | 002,574,294 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94707__x_2ch-games-with-nice-oppai-oshiri-part-2-033.gif
[2011/03/25 06:50:17 | 003,151,846 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94706__x_2ch-games-with-nice-oppai-oshiri-part-2-032.gif
[2011/03/25 06:50:10 | 002,328,932 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94702__x_2ch-games-with-nice-oppai-oshiri-part-2-030.gif
[2011/03/25 06:50:06 | 003,350,884 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94700__x_2ch-games-with-nice-oppai-oshiri-part-2-029.gif
[2011/03/23 08:16:41 | 018,604,442 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\Fire In The Booth _Charlie Sloth_ Radio.mp3
[2011/03/23 08:16:37 | 002,865,849 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\22 - Subzero & Pyper - Audio Music Star - Bassline Mix CD.mp3
[2011/03/23 02:12:16 | 000,050,198 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\practical7.rar
[2011/03/19 04:35:50 | 000,083,869 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\hoes.htm
[2011/03/18 22:54:15 | 000,137,515 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\259760527.jpg
[2011/03/18 06:31:40 | 000,000,239 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\2.java
[2011/03/18 03:54:16 | 000,052,936 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\wakaela1.jpg
[2011/03/14 23:40:22 | 000,004,823 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\maths1111.PNG
[2011/03/14 23:38:24 | 000,137,856 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\MathsCW1.pdf
[2011/03/14 06:15:35 | 000,001,077 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live ID.lnk
[2011/03/14 06:12:47 | 000,001,803 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Search.lnk
[2011/03/14 06:12:47 | 000,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/03/14 04:59:48 | 000,000,917 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\Revo Uninstaller.lnk
[2011/03/14 02:20:04 | 000,017,018 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\prac6.zip
[2011/03/10 03:32:48 | 000,236,661 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\RelativeResourceManager.pdf
[2011/03/09 01:25:23 | 000,015,889 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\prac5.rar
[2011/03/08 05:45:25 | 000,735,866 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\lonely-risa-wanko-to-kurasou.png
[2011/03/08 05:36:21 | 000,057,901 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\34071.jpg
[2011/03/06 04:50:31 | 000,000,075 | ---- | C] () -- C:\WINDOWS\System32\nvUnsupRes.dat
[2011/02/18 23:17:07 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Waka\Local Settings\Application Data\PUTTY.RND
[2010/10/29 01:10:14 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/10/29 01:10:14 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/10/14 02:36:44 | 000,179,263 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2010/10/13 22:06:27 | 000,241,440 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/10/13 22:06:01 | 000,241,440 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/10/13 22:06:01 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/10/13 22:05:33 | 002,293,194 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/09/18 14:03:52 | 000,669,184 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2010/08/03 14:30:33 | 000,002,278 | ---- | C] () -- C:\WINDOWS\System32\Cam122.ini
[2010/07/17 21:02:51 | 000,000,004 | -H-- | C] () -- C:\WINDOWS\ujspa.sys
[2010/06/02 00:49:58 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/05/14 23:29:15 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/04/17 20:19:26 | 000,047,204 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/04/02 16:14:15 | 000,140,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/04/02 16:13:45 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\PnkBstrK.sys
[2010/04/02 16:12:56 | 000,266,400 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2010/04/02 16:12:26 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
[2010/04/02 16:12:26 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2010/03/02 07:51:08 | 000,000,080 | RHS- | C] () -- C:\WINDOWS\System32\60F61203DC.dll
[2009/11/03 16:07:30 | 000,000,219 | ---- | C] () -- C:\WINDOWS\ACTIVEJP.INI
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/11 19:20:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/07/07 02:23:10 | 000,018,944 | ---- | C] () -- C:\Documents and Settings\Waka\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/04 02:18:13 | 000,781,312 | ---- | C] () -- C:\WINDOWS\System32\RGSS102J.dll
[2009/07/04 02:18:13 | 000,778,752 | ---- | C] () -- C:\WINDOWS\System32\RGSS102E.dll
[2009/07/04 02:18:13 | 000,771,584 | ---- | C] () -- C:\WINDOWS\System32\RGSS100J.dll
[2009/07/04 02:18:13 | 000,685,056 | ---- | C] () -- C:\WINDOWS\System32\RGSS103J.dll
[2009/07/01 03:40:03 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/06/29 20:57:47 | 000,133,632 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2009/06/18 16:24:43 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/06/18 13:03:52 | 000,032,914 | ---- | C] () -- C:\WINDOWS\System32\t3.ini
[2009/06/18 13:03:52 | 000,000,049 | R--- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2009/06/18 13:03:11 | 000,145,920 | ---- | C] () -- C:\WINDOWS\System32\OemSpi.dll
[2009/06/18 13:03:11 | 000,118,850 | ---- | C] () -- C:\WINDOWS\System32\CTPcie.dll
[2009/06/18 13:03:11 | 000,008,535 | ---- | C] () -- C:\WINDOWS\sfsyn.ini
[2009/06/18 03:44:31 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/18 03:26:11 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2009/06/18 03:26:11 | 000,012,400 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2009/06/18 03:26:10 | 000,011,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2009/06/18 03:26:10 | 000,010,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2009/06/18 03:25:50 | 000,005,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/06/18 03:11:30 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2009/06/18 00:58:10 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/06/18 00:58:08 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2009/06/18 00:25:57 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/06/18 00:22:50 | 000,232,776 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/18 00:22:00 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2009/06/17 23:39:23 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/06/17 23:35:34 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/05/26 22:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 22:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 05:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007/09/27 11:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/12/31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/18 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/18 12:00:00 | 000,587,158 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/18 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/18 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/18 12:00:00 | 000,123,580 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/18 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/18 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/18 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2009/10/18 03:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2DBoy
[2011/04/02 14:45:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/19 12:14:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/19 12:19:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2009/11/03 15:57:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/04/02 14:41:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/02/03 16:15:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nHancer
[2011/01/19 07:43:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/04/04 15:11:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/18 01:52:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
[2011/01/30 00:36:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\.minecraft
[2011/04/04 14:16:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\AVG
[2010/10/19 12:21:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\AVG10
[2009/11/03 16:06:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\DAEMON Tools Lite
[2010/03/02 07:54:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\DJJava
[2011/02/27 15:48:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\gtk-2.0
[2010/07/10 03:35:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\HLSW
[2011/03/27 02:03:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\ImgBurn
[2011/01/21 02:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\LolClient
[2011/04/05 00:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Mumble
[2010/02/03 16:15:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\nHancer
[2010/02/23 23:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Notepad++
[2009/12/17 01:24:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\OpenOffice.org
[2009/11/18 18:45:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Processing
[2009/08/25 03:23:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Scendix Software
[2010/12/08 16:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\SmartDraw
[2011/03/05 04:44:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Spotify
[2010/10/13 21:35:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\SystemRequirementsLab
[2010/07/14 00:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\TS3Client
[2010/12/11 20:46:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Uniblue
[2011/03/19 07:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\uTorrent
[2011/03/14 06:13:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Windows Desktop Search
[2011/03/14 06:18:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Windows Search
[2011/04/04 16:42:16 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: AHCIX86.SYS >
[2009/04/12 13:08:20 | 000,113,152 | ---- | M] (ATI Technologies Inc.) MD5=9FACB9D43EC53F54386DAE74A175AE53 -- C:\WINDOWS\NLDRV\007\ahcix86.sys

< MD5 for: ATAPI.SYS >
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\system32\DRIVERS\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2009/04/12 13:08:15 | 000,874,240 | ---- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B -- C:\WINDOWS\NLDRV\005\iastor.sys
[2009/04/12 13:08:18 | 000,308,248 | ---- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F -- C:\WINDOWS\NLDRV\006\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: NVATABUS.SYS >
[2009/04/12 13:08:07 | 000,105,472 | ---- | M] (NVIDIA Corporation) MD5=6B37162E91A7005BAA753CB611ACEA2D -- C:\WINDOWS\NLDRV\003\nvatabus.sys

< MD5 for: NVGTS.SYS >
[2009/04/12 13:08:11 | 000,102,400 | ---- | M] (NVIDIA Corporation) MD5=1F790624AB1619CAE0C78597BD33615B -- C:\WINDOWS\NLDRV\004\nvgts.sys
[2009/04/12 13:08:03 | 000,107,520 | ---- | M] (NVIDIA Corporation) MD5=20E15B182DE3EFDFEA3AECB86A04E5CA -- C:\WINDOWS\NLDRV\002\nvgts.sys

< MD5 for: SCECLI.DLL >
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: VIAMRAID.SYS >
[2009/04/12 13:08:30 | 000,116,688 | ---- | M] (VIA Technologies inc,.ltd) MD5=68B41DFA083C2734340BA254532700F3 -- C:\WINDOWS\NLDRV\013\viamraid.sys
[2009/04/12 13:08:28 | 000,102,912 | ---- | M] (VIA Technologies inc,.ltd) MD5=7DC3E1DC6E4F8BE381C31BFEA578412A -- C:\WINDOWS\NLDRV\012\viamraid.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/06/18 00:22:04 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/06/18 00:22:04 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/06/18 00:22:04 | 000,950,272 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

========== Files - Unicode (All) ==========
[2011/02/22 22:37:50 | 000,411,905 | ---- | M] ()(C:\Documents and Settings\Waka\Desktop\QQ?????.png) -- C:\Documents and Settings\Waka\Desktop\QQ截图未命名.png
[2011/02/22 22:37:42 | 000,411,905 | ---- | C] ()(C:\Documents and Settings\Waka\Desktop\QQ?????.png) -- C:\Documents and Settings\Waka\Desktop\QQ截图未命名.png

========== Alternate Data Streams ==========

@Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:4E17D6D2B619558D
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

I kind of messed up and ran it the first time with FireFox and WoW open and it created the primary file and the extra files. I shut down everything properly and reloaded the program yet this time, after the scan, it didn't create an Extras.txt file. :(

EDIT: I deleted the files from the first scan sigh.

Edited by Kingy1337: n/a

0

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Commands
    [purity]
    [emptyflash]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot the PC when it is done.
  • Post log from this run.
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

================

When did you run Combofix?

Edited by crunchie: n/a

0

All processes killed
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Waka
->Flash cache emptied: 456 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: Waka
->Temp folder emptied: 138981 bytes
->Temporary Internet Files folder emptied: 877282 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 102611006 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 256 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 99.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 04052011_132537

Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\Waka\Local Settings\Temp\IswTmp\Logs\110405112504656-000002.rsc_tmp not found!
C:\Documents and Settings\Waka\Local Settings\Temp\~DF56E4.tmp moved successfully.
File\Folder C:\WINDOWS\temp\ZLT02d04.TMP not found!

Registry entries deleted on Reboot...

0

OTL logfile created on: 05/04/2011 13:30:14 - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Waka\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 58.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.23 Gb Total Space | 11.73 Gb Free Space | 16.94% Space Free | Partition Type: NTFS
Drive D: | 5.40 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 931.51 Gb Total Space | 733.31 Gb Free Space | 78.72% Space Free | Partition Type: NTFS

Computer Name: KINGY | User Name: Waka | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/05 10:42:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
PRC - [2011/01/07 02:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/01/07 02:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/01/07 02:22:12 | 001,052,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2011/01/06 16:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/01/06 16:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/12/05 17:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 17:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/10/22 05:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/09/16 21:04:06 | 001,164,584 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/06/23 13:52:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2010/06/23 13:51:30 | 001,043,968 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2009/01/02 23:51:42 | 001,427,968 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
PRC - [2008/12/11 13:45:22 | 000,114,688 | ---- | M] () -- C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2011/04/05 10:42:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
MOD - [2010/08/23 17:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/02/02 11:57:54 | 000,052,288 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus(R)
SRV - [2011/01/06 16:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/12/11 21:41:48 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe -- (Creative Media Toolbox 6 Licensing Service)
SRV - [2010/10/22 05:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/09/24 05:38:36 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010/06/23 13:52:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
SRV - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)


========== Driver Services (SafeList) ==========

DRV - [2011/04/04 17:50:41 | 000,140,248 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK)
DRV - [2010/12/08 05:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/11/12 14:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/13 16:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/19 21:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/08/19 21:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/19 21:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/05/13 10:02:32 | 000,532,224 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2009/11/03 15:57:47 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/07/30 19:53:54 | 002,697,728 | ---- | M] (NTK) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvtcam.sys -- (DCamUSBNovatek)
DRV - [2009/06/18 03:46:11 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009/06/04 10:34:06 | 000,054,784 | ---- | M] (Guillemot Corp S.A.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\guillflt.sys -- (guillflt)
DRV - [2009/05/06 03:36:12 | 000,742,936 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\t3.sys -- (t3)
DRV - [2009/04/12 13:08:22 | 000,209,200 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\Si3114r5.sys -- (Si3114r5)
DRV - [2009/02/27 10:45:30 | 000,171,008 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctusfsyn.sys -- (CTUSFSYN)
DRV - [2009/02/09 03:30:00 | 000,152,616 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mv61xx.sys -- (mv61xx)
DRV - [2009/02/08 23:42:42 | 000,099,968 | ---- | M] (Guillemot Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hxctlflt.sys -- (hxctlflt)
DRV - [2009/02/05 09:34:16 | 001,803,136 | ---- | M] (Creative) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\t3filt.sys -- (t3filt)
DRV - [2009/01/14 10:47:24 | 000,142,336 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2009/01/14 10:47:24 | 000,114,688 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2009/01/14 03:47:24 | 000,008,704 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Pfmodnt.sys -- (PfModNT)
DRV - [2008/11/12 07:52:36 | 000,018,984 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mrdd.sys -- (mrdd)
DRV - [2008/06/26 00:47:00 | 000,036,864 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1e51x86.sys -- (L1e)
DRV - [2007/12/17 17:14:06 | 000,012,400 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2007/08/02 17:32:26 | 000,022,784 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dadder.sys -- (DAdderFltr)
DRV - [2007/04/11 17:23:48 | 000,045,440 | ---- | M] (Razer USA Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\UsbFltr.sys -- (TarFltr)
DRV - [2006/11/08 21:19:18 | 000,004,544 | ---- | M] (SweetLow) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hidusbf.sys -- (hidusbf)
DRV - [2004/08/13 10:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:3.3.3.2

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/30 23:12:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/04/02 14:45:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/29 03:53:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 03:34:02 | 000,000,000 | ---D | M]

[2009/08/25 03:23:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Extensions
[2009/08/25 03:23:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Extensions\{2f1e6a90-e99e-11dd-ba2f-0800200c9a66}
[2009/06/29 20:49:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2011/04/04 17:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Firefox\Profiles\ldfpmils.default\extensions
[2010/08/23 21:10:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Firefox\Profiles\ldfpmils.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/25 00:30:22 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Documents and Settings\Waka\Application Data\Mozilla\Firefox\Profiles\ldfpmils.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/04/04 17:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/15 22:39:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/16 02:11:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/15 22:51:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/15 21:55:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/15 23:56:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/15 22:39:39 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/12 16:35:56 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/12 16:35:56 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/12 16:35:56 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/12 16:35:56 | 000,000,831 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/04/04 11:27:17 | 000,431,524 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14855 more lines...
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe ()
O4 - HKLM..\Run: [ASUS Update Checker] C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QFan Help] C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe ()
O4 - HKLM..\Run: [SPIRun] C:\WINDOWS\System32\SPIRun.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Waka\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Waka\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/17 23:37:54 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/02/10 02:55:59 | 000,423,304 | R--- | M] (Electronic Arts) - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 07:21:09 | 000,000,000 | R--D | M] - D:\Autorun -- [ CDFS ]
O32 - AutoRun File - [2010/01/31 09:21:13 | 000,367,686 | R--- | M] () - D:\Autorun.ico -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 03:55:03 | 009,965,568 | R--- | M] () - D:\autorun.dat -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 03:54:55 | 000,000,155 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{6f2086a6-d3e3-11df-b31d-001d0fb062cc}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Installer.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/05 13:25:37 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/04/05 10:42:33 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
[2011/04/04 13:15:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\AVG
[2011/04/04 13:12:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011
[2011/04/04 12:27:27 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/04/04 11:02:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\SmitfraudFix
[2011/04/03 04:24:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\practical9
[2011/04/02 14:35:34 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW
[2011/04/02 14:28:54 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\TFC.exe
[2011/04/02 14:24:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\SUPERAntiSpyware.com
[2011/04/02 14:24:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/04/02 14:07:20 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/01 20:19:17 | 000,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2011/04/01 20:19:16 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe
[2011/04/01 20:19:16 | 000,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe
[2011/04/01 20:19:16 | 000,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe
[2011/04/01 20:19:15 | 000,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe
[2011/04/01 20:19:15 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe
[2011/04/01 20:19:14 | 000,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe
[2011/04/01 20:19:14 | 000,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe
[2011/04/01 20:19:13 | 000,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe
[2011/04/01 20:19:11 | 000,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe
[2011/04/01 20:19:10 | 000,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe
[2011/04/01 19:20:31 | 000,000,000 | ---D | C] -- C:\Program Files\FileASSASSIN
[2011/04/01 19:20:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FileASSASSIN
[2011/04/01 17:38:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/03/30 06:06:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Start Menu\Programs\StarCraft II
[2011/03/30 00:22:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\practical8
[2011/03/27 02:02:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\ImgBurn
[2011/03/27 01:57:32 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2011/03/27 01:57:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn
[2011/03/21 17:56:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\practical7
[2011/03/19 04:35:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\hoes_files
[2011/03/18 01:54:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\Exec
[2011/03/16 00:06:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\testjava
[2011/03/14 06:53:15 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Waka\Start Menu\Programs\Administrative Tools
[2011/03/14 06:40:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/03/14 06:39:45 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2011/03/14 06:29:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Local Settings\Application Data\ApplicationHistory
[2011/03/14 06:18:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\Windows Search
[2011/03/14 06:18:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2011/03/14 06:15:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2011/03/14 06:14:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm
[2011/03/14 06:14:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell
[2011/03/14 06:14:12 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$
[2011/03/14 06:13:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Application Data\Windows Desktop Search
[2011/03/14 06:12:43 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2011/03/14 06:11:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2011/03/14 05:40:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2011/03/14 04:59:48 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2011/03/14 04:59:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Start Menu\Programs\Revo Uninstaller
[2011/03/14 02:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\prac6
[2011/03/07 23:53:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\Desktop\prac5
[2011/03/07 13:28:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Waka\.android
[1 C:\Documents and Settings\Waka\Desktop\*.tmp files -> C:\Documents and Settings\Waka\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/05 13:28:10 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2011/04/05 13:28:07 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/05 13:27:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/05 10:42:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\OTL.exe
[2011/04/05 09:51:23 | 111,693,519 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/04/05 08:13:26 | 000,000,543 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2011/04/05 07:49:05 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/05 07:36:40 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2011/04/04 17:50:41 | 000,140,248 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/04/04 17:50:36 | 000,266,400 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr
[2011/04/04 13:12:45 | 000,000,848 | ---- | M] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2011/04/04 13:12:45 | 000,000,830 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/04 11:27:17 | 000,431,524 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/04 11:06:40 | 000,003,954 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2011/04/04 11:06:37 | 000,431,398 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110404-112717.backup
[2011/04/03 15:15:31 | 000,236,661 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\RelativeResourceManager.pdf
[2011/04/03 06:02:14 | 000,266,400 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.ex0
[2011/04/02 16:47:44 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\7327fcpt.exe
[2011/04/02 16:42:45 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\w4bjdjhx.exe
[2011/04/02 16:42:35 | 000,625,664 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\dds.scr
[2011/04/02 14:45:23 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/04/02 14:28:55 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Waka\Desktop\TFC.exe
[2011/04/02 14:24:36 | 014,336,632 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\SAS_7751.COM
[2011/04/02 05:23:22 | 000,266,328 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\gifts-year-old-girl-800X800.jpg
[2011/04/01 20:17:42 | 001,885,088 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\SmitfraudFix.exe
[2011/04/01 19:20:31 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FileASSASSIN.lnk
[2011/04/01 17:38:04 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/04/01 17:38:04 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\Spybot - Search & Destroy.lnk
[2011/03/30 23:21:03 | 000,921,654 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\untitled.bmp
[2011/03/30 23:04:59 | 000,050,198 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\practical7.rar
[2011/03/30 15:53:31 | 000,587,158 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/30 15:53:31 | 000,123,580 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/30 04:58:40 | 000,022,683 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\practical8.rar
[2011/03/30 03:49:28 | 000,009,006 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\binarypic1.PNG
[2011/03/29 18:50:38 | 000,083,484 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\wakkaaa11.jpg
[2011/03/28 23:27:30 | 000,241,440 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/03/28 23:27:30 | 000,241,440 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/03/28 23:27:30 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/03/27 01:57:37 | 000,001,546 | ---- | M] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/27 01:57:36 | 000,001,528 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/03/25 06:50:22 | 002,574,294 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94707__x_2ch-games-with-nice-oppai-oshiri-part-2-033.gif
[2011/03/25 06:50:18 | 003,151,846 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94706__x_2ch-games-with-nice-oppai-oshiri-part-2-032.gif
[2011/03/25 06:50:10 | 002,328,932 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94702__x_2ch-games-with-nice-oppai-oshiri-part-2-030.gif
[2011/03/25 06:50:07 | 003,350,884 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\94700__x_2ch-games-with-nice-oppai-oshiri-part-2-029.gif
[2011/03/25 03:34:02 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/03/19 04:35:52 | 000,083,869 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\hoes.htm
[2011/03/18 22:54:15 | 000,137,515 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\259760527.jpg
[2011/03/18 06:31:40 | 000,000,239 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\2.java
[2011/03/18 03:54:17 | 000,052,936 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\wakaela1.jpg
[2011/03/15 06:10:49 | 000,137,856 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\MathsCW1.pdf
[2011/03/14 23:40:22 | 000,004,823 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\maths1111.PNG
[2011/03/14 16:26:25 | 000,000,656 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mumble.lnk
[2011/03/14 06:30:18 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/03/14 06:12:47 | 000,001,787 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/03/14 05:44:01 | 000,232,776 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/14 04:59:48 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\Revo Uninstaller.lnk
[2011/03/14 02:20:05 | 000,017,018 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\prac6.zip
[2011/03/09 01:25:23 | 000,015,889 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\prac5.rar
[2011/03/08 05:45:26 | 000,735,866 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\lonely-risa-wanko-to-kurasou.png
[2011/03/08 05:36:22 | 000,057,901 | ---- | M] () -- C:\Documents and Settings\Waka\Desktop\34071.jpg
[1 C:\Documents and Settings\Waka\Desktop\*.tmp files -> C:\Documents and Settings\Waka\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/04 13:12:45 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2011/04/04 13:12:45 | 000,000,830 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/02 16:47:44 | 000,301,568 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\7327fcpt.exe
[2011/04/02 16:42:44 | 000,301,568 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\w4bjdjhx.exe
[2011/04/02 16:42:34 | 000,625,664 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\dds.scr
[2011/04/02 16:13:09 | 001,885,088 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\SmitfraudFix.exe
[2011/04/02 14:23:32 | 014,336,632 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\SAS_7751.COM
[2011/04/02 05:23:20 | 000,266,328 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\gifts-year-old-girl-800X800.jpg
[2011/04/01 20:22:37 | 000,003,954 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2011/04/01 20:19:15 | 000,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe
[2011/04/01 20:19:13 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe
[2011/04/01 20:19:12 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe
[2011/04/01 19:20:31 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\FileASSASSIN.lnk
[2011/04/01 17:38:04 | 000,000,951 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/04/01 17:38:04 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\Spybot - Search & Destroy.lnk
[2011/03/30 23:20:49 | 000,921,654 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\untitled.bmp
[2011/03/30 04:22:16 | 000,022,683 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\practical8.rar
[2011/03/30 03:49:28 | 000,009,006 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\binarypic1.PNG
[2011/03/29 18:50:37 | 000,083,484 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\wakkaaa11.jpg
[2011/03/27 05:09:48 | 001,839,104 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\mt420.iso
[2011/03/27 01:57:37 | 000,001,546 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/27 01:57:36 | 000,001,528 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/03/25 06:50:22 | 002,574,294 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94707__x_2ch-games-with-nice-oppai-oshiri-part-2-033.gif
[2011/03/25 06:50:17 | 003,151,846 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94706__x_2ch-games-with-nice-oppai-oshiri-part-2-032.gif
[2011/03/25 06:50:10 | 002,328,932 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94702__x_2ch-games-with-nice-oppai-oshiri-part-2-030.gif
[2011/03/25 06:50:06 | 003,350,884 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\94700__x_2ch-games-with-nice-oppai-oshiri-part-2-029.gif
[2011/03/23 08:16:41 | 018,604,442 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\Fire In The Booth _Charlie Sloth_ Radio.mp3
[2011/03/23 08:16:37 | 002,865,849 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\22 - Subzero & Pyper - Audio Music Star - Bassline Mix CD.mp3
[2011/03/23 02:12:16 | 000,050,198 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\practical7.rar
[2011/03/19 04:35:50 | 000,083,869 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\hoes.htm
[2011/03/18 22:54:15 | 000,137,515 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\259760527.jpg
[2011/03/18 06:31:40 | 000,000,239 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\2.java
[2011/03/18 03:54:16 | 000,052,936 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\wakaela1.jpg
[2011/03/14 23:40:22 | 000,004,823 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\maths1111.PNG
[2011/03/14 23:38:24 | 000,137,856 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\MathsCW1.pdf
[2011/03/14 06:15:35 | 000,001,077 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live ID.lnk
[2011/03/14 06:12:47 | 000,001,803 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Search.lnk
[2011/03/14 06:12:47 | 000,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/03/14 04:59:48 | 000,000,917 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\Revo Uninstaller.lnk
[2011/03/14 02:20:04 | 000,017,018 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\prac6.zip
[2011/03/10 03:32:48 | 000,236,661 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\RelativeResourceManager.pdf
[2011/03/09 01:25:23 | 000,015,889 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\prac5.rar
[2011/03/08 05:45:25 | 000,735,866 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\lonely-risa-wanko-to-kurasou.png
[2011/03/08 05:36:21 | 000,057,901 | ---- | C] () -- C:\Documents and Settings\Waka\Desktop\34071.jpg
[2011/03/06 04:50:31 | 000,000,075 | ---- | C] () -- C:\WINDOWS\System32\nvUnsupRes.dat
[2011/02/18 23:17:07 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Waka\Local Settings\Application Data\PUTTY.RND
[2010/10/29 01:10:14 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/10/29 01:10:14 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/10/14 02:36:44 | 000,179,263 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2010/10/13 22:06:27 | 000,241,440 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/10/13 22:06:01 | 000,241,440 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/10/13 22:06:01 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/10/13 22:05:33 | 002,293,194 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/09/18 14:03:52 | 000,669,184 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2010/08/03 14:30:33 | 000,002,278 | ---- | C] () -- C:\WINDOWS\System32\Cam122.ini
[2010/07/17 21:02:51 | 000,000,004 | -H-- | C] () -- C:\WINDOWS\ujspa.sys
[2010/06/02 00:49:58 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/05/14 23:29:15 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/04/17 20:19:26 | 000,047,204 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/04/02 16:14:15 | 000,140,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/04/02 16:13:45 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Waka\Application Data\PnkBstrK.sys
[2010/04/02 16:12:56 | 000,266,400 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2010/04/02 16:12:26 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
[2010/04/02 16:12:26 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2010/03/02 07:51:08 | 000,000,080 | RHS- | C] () -- C:\WINDOWS\System32\60F61203DC.dll
[2009/11/03 16:07:30 | 000,000,219 | ---- | C] () -- C:\WINDOWS\ACTIVEJP.INI
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/11 19:20:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/07/07 02:23:10 | 000,018,944 | ---- | C] () -- C:\Documents and Settings\Waka\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/04 02:18:13 | 000,781,312 | ---- | C] () -- C:\WINDOWS\System32\RGSS102J.dll
[2009/07/04 02:18:13 | 000,778,752 | ---- | C] () -- C:\WINDOWS\System32\RGSS102E.dll
[2009/07/04 02:18:13 | 000,771,584 | ---- | C] () -- C:\WINDOWS\System32\RGSS100J.dll
[2009/07/04 02:18:13 | 000,685,056 | ---- | C] () -- C:\WINDOWS\System32\RGSS103J.dll
[2009/07/01 03:40:03 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/06/29 20:57:47 | 000,133,632 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2009/06/18 16:24:43 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/06/18 13:03:52 | 000,032,914 | ---- | C] () -- C:\WINDOWS\System32\t3.ini
[2009/06/18 13:03:52 | 000,000,049 | R--- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2009/06/18 13:03:11 | 000,145,920 | ---- | C] () -- C:\WINDOWS\System32\OemSpi.dll
[2009/06/18 13:03:11 | 000,118,850 | ---- | C] () -- C:\WINDOWS\System32\CTPcie.dll
[2009/06/18 13:03:11 | 000,008,535 | ---- | C] () -- C:\WINDOWS\sfsyn.ini
[2009/06/18 03:44:31 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/18 03:26:11 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2009/06/18 03:26:11 | 000,012,400 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2009/06/18 03:26:10 | 000,011,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2009/06/18 03:26:10 | 000,010,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2009/06/18 03:25:50 | 000,005,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/06/18 03:11:30 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2009/06/18 00:58:10 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/06/18 00:58:08 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2009/06/18 00:25:57 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/06/18 00:22:50 | 000,232,776 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/18 00:22:00 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2009/06/17 23:39:23 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/06/17 23:35:34 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/05/26 22:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 22:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 05:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007/09/27 11:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/12/31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/18 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/18 12:00:00 | 000,587,158 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/18 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/18 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/18 12:00:00 | 000,123,580 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/18 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/18 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/18 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2009/10/18 03:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2DBoy
[2011/04/02 14:45:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/19 12:14:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/19 12:19:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2009/11/03 15:57:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/04/02 14:41:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/02/03 16:15:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nHancer
[2011/01/19 07:43:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/04/05 11:30:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/18 01:52:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
[2011/01/30 00:36:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\.minecraft
[2011/04/04 14:16:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\AVG
[2010/10/19 12:21:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\AVG10
[2009/11/03 16:06:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\DAEMON Tools Lite
[2010/03/02 07:54:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\DJJava
[2011/02/27 15:48:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\gtk-2.0
[2010/07/10 03:35:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\HLSW
[2011/03/27 02:03:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\ImgBurn
[2011/01/21 02:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\LolClient
[2011/04/05 13:25:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Mumble
[2010/02/03 16:15:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\nHancer
[2010/02/23 23:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Notepad++
[2009/12/17 01:24:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\OpenOffice.org
[2009/11/18 18:45:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Processing
[2009/08/25 03:23:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Scendix Software
[2010/12/08 16:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\SmartDraw
[2011/03/05 04:44:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Spotify
[2010/10/13 21:35:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\SystemRequirementsLab
[2010/07/14 00:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\TS3Client
[2010/12/11 20:46:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Uniblue
[2011/03/19 07:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\uTorrent
[2011/03/14 06:13:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Windows Desktop Search
[2011/03/14 06:18:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Waka\Application Data\Windows Search
[2011/04/05 13:28:10 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========

========== Files - Unicode (All) ==========
[2011/02/22 22:37:50 | 000,411,905 | ---- | M] ()(C:\Documents and Settings\Waka\Desktop\QQ?????.png) -- C:\Documents and Settings\Waka\Desktop\QQ截图未命名.png
[2011/02/22 22:37:42 | 000,411,905 | ---- | C] ()(C:\Documents and Settings\Waka\Desktop\QQ?????.png) -- C:\Documents and Settings\Waka\Desktop\QQ截图未命名.png

========== Alternate Data Streams ==========

@Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:4E17D6D2B619558D
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

I ran it before I came to seek help on this forum~

This question has already been answered. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.