This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Redirecting when going on websites!

79 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

when i go on certain websites i get redirected, usually through google searches, but i have also found that on certain sites, li the microsoft homepage, i am unable to download because i get a webpage not found.

i am running windows xp

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:28 PM, on 2/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Sonic\Product\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Documents and Settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\ooVoo\ooVoo.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\WebcamMax\wcmmon.exe
C:\Program Files\Mozilla Firefox 2 Beta 2\firefox.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 98.116.47.144.:80
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Sonic\Product\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [oovoo.exe] C:\Program Files\ooVoo\ooVoo.exe /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB
O16 - DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter25 Class) - http://download.netmarble.com/web/nmstarter/NMStarter25.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {92E82FBB-DA00-41E0-ABFE-95482E21A4F6} (NMTransX Module) - http://download.netmarble.net/NMChatX/NMTransX.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/activex/dmcc2.c…ersion=1,0,0,10
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - http://download.netmarble.net/kdefence/kdfense8237.cab
O16 - DPF: {AF60D574-F249-4243-8040-5521AAA5BB5E} (PandoraTVSet Class) - http://imgcdn.pandora.tv/pan_img/p3player/…ge/pdrtvset.cab
O16 - DPF: {C0B2F53E-5E61-4856-B314-FE9AE262A796} (MOPlayerWnd2 Class) - http://www.melon.com/cab/P3MelWebInstall.cab
O16 - DPF: {CBB45291-871B-4ADA-81D0-40D0C89ABD20} (NetmarbleDownloaderExCtrl Class) - http://download.netmarble.com/web/NMGameCh…ownloaderEx.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {EE4D2623-4584-42A1-9A2D-BD5FACAA9541} (Melon Sing Player) - http://sing.melon.com/melon/player/ocx/MelonSingPlayer.cab
O16 - DPF: {F4A1D5E2-AF49-47A7-A945-23038106F3A4} (Pandora_SetUp Control) - http://imgcdn.pandora.tv/pan_img/launcher/…ora_SetUpAX.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Unknown owner - C:\Program Files\Digidesign\Drivers\MMERefresh.exe (file missing)
O23 - Service: digiSPTIService - Unknown owner - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe (file missing)
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe

–
End of file - 11739 bytes
Hello Phil Kim and welcome to the forums here at WTT!

:welcome:

Is this only happening in Firefox? Or IE too?

Please download GooredFix and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.
Hey! thanks for the reply to my topic, and yes this problem persists with Firefox, IE, and Chrome. this is my log file from the Goored GooredFix v1.91 by jpshortstuff Log created at 20:02 on 22/02/2009 running Option #1 (Phillip) Firefox version 3.0.6 (en-US) =====Suspect Goored Entries===== =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions] "Plugins"="C:\Program Files\Mozilla Firefox 2 Beta 2\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions] "Components"="C:\Program Files\Mozilla Firefox 2 Beta 2\components" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"
Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program. Make sure you close all other programs and don't use the PC while the scan runs.
    • In the Rootkit Search section select the Yes radio button.
    • Under Additional Scans check the boxes beside Reg - ColumnHandlers, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, Reg - NetSvcs, Reg - Protocol Filters, Reg - Protocol Handlers, Reg - SafeBoot Minimal, Reg - SafeBoot Network, Reg - Session Manager Settings, Reg - Winsock2 Catalogs, File - Lop Check, File - Purity Scan, Files - Signature Check, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
OTScanIt2 logfile created on: 2/23/2009 4:59:55 PM - Run 2
OTScanIt2 by OldTimer - Version 1.0.8.0	 Folder = C:\Documents and Settings\Phillip\Desktop\OTScanIt2
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
1022.09 Mb Total Physical Memory | 422.93 Mb Available Physical Memory | 41.38% Memory free
2.45 Gb Paging File | 1.93 Gb Available in Paging File | 78.67% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.16 Gb Total Space | 4.80 Gb Free Space | 2.11% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: HOME
Current User Name: Phillip
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
 
[Processes - Safe List]
aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware\AAWService.exe -> [2009/02/02 21:22:14 | 00,950,096 | —- | M] (Lavasoft)
aim6.exe -> %ProgramFiles%\AIM6\aim6.exe -> [2008/06/12 15:47:13 | 00,050,528 | —- | M] (AOL LLC)
aolsoftware.exe -> %ProgramFiles%\AIM6\aolsoftware.exe -> [2007/10/08 16:50:56 | 00,041,824 | —- | M] (AOL LLC)
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/09/10 15:50:26 | 00,116,040 | —- | M] (Apple Inc.)
dmxlauncher.exe -> %ProgramFiles%\Sonic\Product\Media Experience\DMXLauncher.exe -> [2007/04/02 04:24:10 | 00,113,400 | —- | M] ()
ehrecvr.exe -> %SystemRoot%\eHome\ehRecvr.exe -> [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation)
ehsched.exe -> %SystemRoot%\eHome\ehSched.exe -> [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation)
elservice.exe -> %ProgramFiles%\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe -> [2005/12/12 16:52:32 | 00,180,224 | —- | M] (Intel Corporation)
explorer.exe -> %SystemRoot%\explorer.exe -> [2008/04/13 19:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
firefox.exe -> %ProgramFiles%\Mozilla Firefox 2 Beta 2\firefox.exe -> [2009/02/20 01:32:55 | 00,307,704 | —- | M] (Mozilla Corporation)
googleupdate.exe -> %UserProfile%\Local Settings\Application Data\Google\Update\GoogleUpdate.exe -> [2008/12/20 23:46:23 | 00,133,104 | —- | M] (Google Inc.)
hpwuschd2.exe -> %ProgramFiles%\HP\HP Software Update\HPWuSchd2.exe -> [2005/05/11 22:12:54 | 00,049,152 | —- | M] (Hewlett-Packard Co.)
hpzipm12.exe -> %SystemRoot%\system32\HPZipm12.exe -> [2006/03/02 20:49:14 | 00,069,632 | —- | M] (HP)
iaanotif.exe -> %ProgramFiles%\Intel\Intel Matrix Storage Manager\iaanotif.exe -> [2005/06/17 07:56:14 | 00,139,264 | —- | M] (Intel Corporation)
iaantmon.exe -> %ProgramFiles%\Intel\Intel Matrix Storage Manager\iaantmon.exe -> [2005/06/17 07:55:58 | 00,086,140 | —- | M] (Intel Corporation)
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/09/10 16:39:48 | 00,536,872 | —- | M] (Apple Inc.)
issch.exe -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> [2005/08/12 05:30:30 | 00,081,920 | —- | M] (Macrovision Corporation)
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008/09/10 16:40:06 | 00,289,576 | —- | M] (Apple Inc.)
jqs.exe -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/02/20 11:42:50 | 00,152,984 | —- | M] (Sun Microsystems, Inc.)
jusched.exe -> %ProgramFiles%\Java\jre6\bin\jusched.exe -> [2009/02/20 11:42:50 | 00,148,888 | —- | M] (Sun Microsystems, Inc.)
mcrdsvc.exe -> %SystemRoot%\ehome\mcrdsvc.exe -> [2005/08/05 13:27:08 | 00,099,328 | —- | M] (Microsoft Corporation)
msascui.exe -> %ProgramFiles%\Windows Defender\MSASCui.exe -> [2006/11/03 18:20:12 | 00,866,584 | —- | M] (Microsoft Corporation)
mscams32.exe -> %ProgramFiles%\Microsoft LifeCam\MSCamS32.exe -> [2008/08/04 16:22:18 | 00,164,896 | —- | M] (Microsoft Corporation)
msmpeng.exe -> %ProgramFiles%\Windows Defender\MsMpEng.exe -> [2006/11/03 18:19:58 | 00,013,592 | —- | M] (Microsoft Corporation)
npkcmsvc.exe -> %SystemDrive%\Nexon\Mabinogi\npkcmsvc.exe -> [2007/08/02 11:33:50 | 00,080,528 | —- | M] (INCA Internet Co., Ltd.)
nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2007/12/05 00:41:00 | 00,155,716 | —- | M] (NVIDIA Corporation)
oovoo.exe -> %ProgramFiles%\ooVoo\ooVoo.exe -> [2009/02/01 23:51:08 | 14,612,272 | —- | M] (ooVoo)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/02/19 11:15:40 | 00,489,984 | —- | M] (OldTimer Tools)
pnkbstra.exe -> %SystemRoot%\system32\PnkBstrA.exe -> [2008/10/16 18:31:26 | 00,066,872 | —- | M] ()
realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> [2008/04/19 21:37:33 | 00,185,896 | —- | M] (RealNetworks, Inc.)
sndvol32.exe -> %SystemRoot%\system32\SNDVOL32.EXE -> [2004/08/10 05:00:00 | 00,138,752 | —- | M] (Microsoft Corporation)
sqlwriter.exe -> %ProgramFiles%\Microsoft SQL Server\90\Shared\sqlwriter.exe -> [2007/02/10 05:29:56 | 00,089,968 | —- | M] (Microsoft Corporation)
stsystra.exe -> %SystemRoot%\stsystra.exe -> [2005/03/22 23:20:44 | 00,339,968 | —- | M] (SigmaTel, Inc.)
tfswctrl.exe -> %SystemRoot%\system32\dla\tfswctrl.exe -> [2004/03/10 00:04:00 | 00,118,837 | —- | M] (Sonic Solutions)
wmiprvse.exe -> %SystemRoot%\system32\wbem\wmiprvse.exe -> [2008/04/13 19:12:40 | 00,218,112 | —- | M] (Microsoft Corporation)
wmpnetwk.exe -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
wmpnscfg.exe -> %ProgramFiles%\Windows Media Player\WMPNSCFG.exe -> [2006/10/18 20:05:26 | 00,204,288 | —- | M] (Microsoft Corporation)
wscntfy.exe -> %SystemRoot%\system32\wscntfy.exe -> [2008/04/13 19:12:41 | 00,013,824 | —- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/09/10 15:50:26 | 00,116,040 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2008/07/25 10:16:40 | 00,034,312 | —- | M] (Microsoft Corporation)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/25 10:17:02 | 00,069,632 | —- | M] (Microsoft Corporation)
(DigiRefresh) Digidesign MME Refresh Service [Win32_Shared | Auto | Stopped] ->  -> File not found
(digiSPTIService) digiSPTIService [Win32_Own | On_Demand | Stopped] ->  -> File not found
(ehRecvr) Media Center Receiver Service [Win32_Own | Auto | Running] -> %SystemRoot%\eHome\ehRecvr.exe -> [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation)
(ehSched) Media Center Scheduler Service [Win32_Own | Auto | Running] -> %SystemRoot%\eHome\ehSched.exe -> [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation)
(ELService) Intel® Quick Resume Technology Drivers [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe -> [2005/12/12 16:52:32 | 00,180,224 | —- | M] (Intel Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2008/07/29 20:10:04 | 00,046,104 | —- | M] (Microsoft Corporation)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/13 19:12:02 | 00,038,400 | —- | M] (Microsoft Corporation)
(IAANTMon) Intel(R) Matrix Storage Event Monitor [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Intel Matrix Storage Manager\iaantmon.exe -> [2005/06/17 07:55:58 | 00,086,140 | —- | M] (Intel Corporation)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> [2005/04/03 23:41:10 | 00,069,632 | —- | M] (Macrovision Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2008/07/29 18:24:50 | 00,881,664 | —- | M] (Microsoft Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/09/10 16:39:48 | 00,536,872 | —- | M] (Apple Inc.)
(JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/02/20 11:42:50 | 00,152,984 | —- | M] (Sun Microsystems, Inc.)
(Lavasoft Ad-Aware Service) Lavasoft Ad-Aware Service [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Lavasoft\Ad-Aware\AAWService.exe -> [2009/02/02 21:22:14 | 00,950,096 | —- | M] (Lavasoft)
(McrdSvc) Media Center Extender Service [Win32_Own | Auto | Running] -> %SystemRoot%\ehome\mcrdsvc.exe -> [2005/08/05 13:27:08 | 00,099,328 | —- | M] (Microsoft Corporation)
(McShield) McAfee Real-time Scanner [Win32_Own | Unknown | Stopped] ->  -> File not found
(McSysmon) McAfee SystemGuards [Win32_Own | Auto | Stopped] ->  -> File not found
(MHN) MHN [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\mhn.dll -> [2004/08/10 04:11:50 | 00,085,504 | —- | M] (Microsoft Corporation)
(MSCamSvc) MSCamSvc [Win32_Own | Auto | Running] -> %ProgramFiles%\Microsoft LifeCam\MSCamS32.exe -> [2008/08/04 16:22:18 | 00,164,896 | —- | M] (Microsoft Corporation)
(MSSQL$SONY_MEDIAMGR2) SQL Server (SONY_MEDIAMGR2) [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -> [2008/12/18 04:25:12 | 29,181,272 | —- | M] (Microsoft Corporation)
(MSSQLServerADHelper) SQL Server Active Directory Helper [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\Microsoft SQL Server\90\Shared\sqladhlp90.exe -> [2005/10/14 02:50:20 | 00,045,272 | —- | M] (Microsoft Corporation)
(NBService) NBService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Nero\Nero 7\Nero BackItUp\NBService.exe -> [2006/06/08 20:29:08 | 00,208,896 | —- | M] (Nero AG)
(NetSvc) Intel NCS NetService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Intel\PROSetWired\NCS\Sync\NetSvc.exe -> [2004/11/19 11:26:40 | 00,147,456 | —- | M] (Intel(R) Corporation)
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008/07/29 18:16:38 | 00,132,096 | —- | M] (Microsoft Corporation)
(npkcmsvc) npkcmsvc [Win32_Own | Auto | Running] -> %SystemDrive%\Nexon\Mabinogi\npkcmsvc.exe -> [2007/08/02 11:33:50 | 00,080,528 | —- | M] (INCA Internet Co., Ltd.)
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2007/12/05 00:41:00 | 00,155,716 | —- | M] (NVIDIA Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 12:28:22 | 00,089,136 | —- | M] (Microsoft Corporation)
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Unknown | Running] -> %SystemRoot%\system32\HPZipm12.exe -> [2006/03/02 20:49:14 | 00,069,632 | —- | M] (HP)
(PnkBstrA) PnkBstrA [Win32_Own | Auto | Running] -> %SystemRoot%\system32\PnkBstrA.exe -> [2008/10/16 18:31:26 | 00,066,872 | —- | M] ()
(Roxio UPnP Renderer 9) Roxio UPnP Renderer 9 [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Sonic Shared\RoxioUPnPRenderer9.exe -> [2006/12/11 21:16:32 | 00,064,248 | —- | M] (Sonic Solutions)
(Roxio Upnp Server 9) Roxio Upnp Server 9 [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Sonic Shared\RoxioUpnpService9.exe -> [2006/12/11 21:16:28 | 00,301,816 | —- | M] (Sonic Solutions)
(SQLBrowser) SQL Server Browser [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\Microsoft SQL Server\90\Shared\sqlbrowser.exe -> [2007/02/10 05:29:48 | 00,242,544 | —- | M] (Microsoft Corporation)
(SQLWriter) SQL Server VSS Writer [Win32_Own | Auto | Running] -> %ProgramFiles%\Microsoft SQL Server\90\Shared\sqlwriter.exe -> [2007/02/10 05:29:56 | 00,089,968 | —- | M] (Microsoft Corporation)
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\MSN Messenger\usnsvc.exe -> [2007/01/19 11:54:14 | 00,097,136 | —- | M] (Microsoft Corporation)
(WinDefend) Windows Defender [Win32_Own | Auto | Running] -> %ProgramFiles%\Windows Defender\MsMpEng.exe -> [2006/11/03 18:19:58 | 00,013,592 | —- | M] (Microsoft Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(AliIde) AliIde [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\aliide.sys -> [2001/08/17 13:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\amdagp.sys -> [2008/04/13 13:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.)
(asc) asc [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\asc.sys -> [2001/08/17 13:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\asc3550.sys -> [2001/08/17 13:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.)
(Aspi32) Aspi32 [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\aspi32.sys -> [2005/11/21 00:48:21 | 00,016,512 | —- | M] (Adaptec)
(CamDrL) Logitech QuickCam Pro 3000(CamDrl) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\Camdrl.sys -> [2007/02/03 09:25:56 | 01,075,360 | —- | M] (Logitech Inc.)
(CAMTHWDM) WebcamMax, WDM Video Capture [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\CAMTHWDM.sys -> [2008/03/11 08:14:54 | 00,941,784 | —- | M] ()
(CmdIde) CmdIde [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\cmdide.sys -> [2001/08/17 13:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.)
(dac2w2k) dac2w2k [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\dac2w2k.sys -> [2001/08/17 13:52:16 | 00,179,584 | —- | M] (Mylex Corporation)
(drvmcdb) drvmcdb [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\drvmcdb.sys -> [2005/01/27 02:22:00 | 00,088,016 | —- | M] (Sonic Solutions)
(drvnddm) drvnddm [File_System | Auto | Running] -> %SystemRoot%\system32\drivers\drvnddm.sys -> [2003/11/13 01:56:00 | 00,040,448 | —- | M] (Sonic Solutions)
(E1000) Intel(R) PRO/1000 Network Connection Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\e1000325.sys -> [2005/06/29 15:49:04 | 00,163,840 | —- | M] (Intel Corporation)
(E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\e100b325.sys -> [2001/08/17 12:12:10 | 00,117,760 | —- | M] (Intel Corporation)
(e1express) Intel(R) PRO/1000 PCI Express Network Connection Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\e1e5132.sys -> [2005/08/25 19:05:24 | 00,176,128 | —- | M] (Intel Corporation)
(ELacpi) ELacpi [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ELacpi.sys -> [2005/12/12 16:52:32 | 00,007,808 | —- | M] (Intel Corporation)
(ELhid) ELhid [Kernel | System | Running] -> %SystemRoot%\System32\DRIVERS\ELhid.sys -> [2005/12/12 16:52:34 | 00,010,112 | —- | M] (Intel Corporation)
(ELkbd) ELkbd [Kernel | System | Running] -> %SystemRoot%\System32\DRIVERS\ELkbd.sys -> [2005/12/12 16:52:34 | 00,006,912 | —- | M] (Intel Corporation)
(ELmon) ELmon [Kernel | System | Running] -> %SystemRoot%\System32\DRIVERS\ELmon.sys -> [2005/12/12 16:52:34 | 00,007,040 | —- | M] (Intel Corporation)
(ELmou) ELmou [Kernel | System | Running] -> %SystemRoot%\System32\DRIVERS\ELmou.sys -> [2005/12/12 16:52:34 | 00,006,400 | —- | M] (Intel Corporation)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\GEARAspiWDM.sys -> [2008/04/17 12:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.)
(giveio) giveio [Kernel | Boot | Running] -> %SystemRoot%\system32\giveio.sys -> [1996/04/03 14:33:26 | 00,005,248 | —- | M] ()
(hamachi) Hamachi Network Interface [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\hamachi.sys -> [2008/10/16 19:17:36 | 00,025,280 | —- | M] (LogMeIn, Inc.)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HDAudBus.sys -> [2008/04/13 11:36:05 | 00,144,384 | —- | M] (Windows (R) Server 2003 DDK provider)
(HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HPZid412.sys -> [2005/03/08 13:52:26 | 00,051,120 | —- | M] (HP)
(HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HPZipr12.sys -> [2005/03/08 13:52:28 | 00,016,496 | —- | M] (HP)
(HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HPZius12.sys -> [2005/03/08 13:52:28 | 00,021,744 | —- | M] (HP)
(HSFHWBS2) HSFHWBS2 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSFHWBS2.sys -> [2003/11/17 21:59:20 | 00,212,224 | —- | M] (Conexant Systems, Inc.)
(HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSF_DP.sys -> [2003/11/17 21:56:26 | 01,042,432 | —- | M] (Conexant Systems, Inc.)
(iastor) Intel AHCI Controller [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\iastor.sys -> [2006/07/24 20:28:10 | 00,872,064 | —- | M] (Intel Corporation)
(Lbd) Lbd [File_System | Boot | Running] -> %SystemRoot%\system32\DRIVERS\Lbd.sys -> [2009/01/21 21:22:42 | 00,064,160 | —- | M] (Lavasoft AB)
(MCSTRM) MCSTRM [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\mcstrm.sys -> [2007/08/21 22:30:36 | 00,008,413 | —- | M] (RealNetworks, Inc.)
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\mdmxsdk.sys -> [2003/04/09 18:48:08 | 00,011,043 | —- | M] (Conexant)
(MODEMCSA) Unimodem Streaming Filter Device [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\MODEMCSA.sys -> [2001/08/17 13:57:38 | 00,016,128 | —- | M] (Microsoft Corporation)
(mraid35x) mraid35x [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\mraid35x.sys -> [2001/08/17 13:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.)
(MSHUSBVideo) NX6000/NX3000/VX5000/VX5500/VX7000 Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\nx6000.sys -> [2008/08/04 16:22:18 | 00,033,808 | —- | M] (Microsoft Corporation)
(nocashio) nocashio [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nocashio.sys -> [2008/09/09 19:41:12 | 00,004,096 | —- | M] ()
(npkcrypt) npkcrypt [Kernel | Auto | Running] -> %ProgramFiles%\Wizet\MapleStory\npkcrypt.sys -> [2006/11/19 14:04:30 | 00,034,978 | —- | M] (INCA Internet Co., Ltd.)
(nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\nv4_mini.sys -> [2007/12/05 00:41:00 | 07,435,392 | —- | M] (NVIDIA Corporation)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> [2004/08/10 05:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\PxHelp20.sys -> [2007/03/23 02:00:00 | 00,043,528 | —- | M] (Sonic Solutions)
(ql1080) ql1080 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ql1080.sys -> [2001/08/17 13:52:20 | 00,040,320 | —- | M] (QLogic Corporation)
(ql12160) ql12160 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ql12160.sys -> [2001/08/17 13:52:20 | 00,045,312 | —- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ql1280.sys -> [2001/08/17 13:52:18 | 00,049,024 | —- | M] (QLogic Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> [2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sisagp) SIS AGP Bus Filter [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sisagp.sys -> [2008/04/13 13:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation)
(Sparrow) Sparrow [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sparrow.sys -> [2001/08/17 14:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.)
(speedfan) speedfan [Kernel | Boot | Running] -> %SystemRoot%\system32\speedfan.sys -> [2006/09/24 08:28:46 | 00,005,248 | —- | M] (Windows (R) 2000 DDK provider)
(sptd) sptd [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\sptd.sys -> [2006/11/21 17:18:16 | 00,639,224 | —- | M] ()
(sscdbhk5) sscdbhk5 [File_System | System | Running] -> %SystemRoot%\system32\drivers\sscdbhk5.sys -> [2003/11/13 10:47:40 | 00,005,621 | —- | M] (Sonic Solutions)
(sscdbus) SAMSUNG USB Composite Device driver (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\sscdbus.sys -> [2003/10/15 16:47:32 | 00,051,040 | —- | M] (MCCI)
(sscdmdfl) SAMSUNG CDMA Modem Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\sscdmdfl.sys -> [2003/10/15 16:48:28 | 00,006,000 | —- | M] (MCCI)
(sscdmdm) SAMSUNG CDMA Modem Drivers [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\sscdmdm.sys -> [2003/10/15 16:48:32 | 00,082,576 | —- | M] (MCCI)
(ssrtln) ssrtln [File_System | System | Running] -> %SystemRoot%\system32\drivers\ssrtln.sys -> [2003/11/13 10:47:28 | 00,023,219 | —- | M] (Sonic Solutions)
(STHDA) SigmaTel High Definition Audio CODEC [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\sthda.sys -> [2005/11/16 21:36:00 | 01,047,816 | —- | M] (SigmaTel, Inc.)
(StillCam) Still Serial Digital Camera Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\serscan.sys -> [2001/08/17 13:53:32 | 00,006,784 | —- | M] (Microsoft Corporation)
(SVKP) SVKP [Kernel | Auto | Running] -> %SystemRoot%\system32\SVKP.sys -> [2006/08/05 20:04:23 | 00,002,368 | —- | M] (AntiCracking)
(symc810) symc810 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\symc810.sys -> [2001/08/17 14:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\symc8xx.sys -> [2001/08/17 14:07:36 | 00,032,640 | —- | M] (LSI Logic)
(sym_hi) sym_hi [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sym_hi.sys -> [2001/08/17 14:07:40 | 00,028,384 | —- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sym_u3.sys -> [2001/08/17 14:07:42 | 00,030,688 | —- | M] (LSI Logic)
(tfsnboio) tfsnboio [File_System | Auto | Running] -> %SystemRoot%\system32\dla\tfsnboio.sys -> [2004/03/10 00:04:00 | 00,025,685 | —- | M] (Sonic Solutions)
(tfsncofs) tfsncofs [File_System | Auto | Running] -> %SystemRoot%\system32\dla\tfsncofs.sys -> [2004/03/10 00:04:00 | 00,034,837 | —- | M] (Sonic Solutions)
(tfsndrct) tfsndrct [File_System | Auto | Running] -> %SystemRoot%\system32\dla\tfsndrct.sys -> [2004/03/10 00:04:00 | 00,004,117 | —- | M] (Sonic Solutions)
(tfsndres) tfsndres [File_System | Auto | Running] -> %SystemRoot%\system32\dla\tfsndres.sys -> [2004/03/10 00:04:00 | 00,002,233 | —- | M] (Sonic Solutions)
(tfsnifs) tfsnifs [File_System | Auto | Running] -> %SystemRoot%\system32\dla\tfsnifs.sys -> [2004/03/10 00:04:00 | 00,085,204 | —- | M] (Sonic Solutions)
(tfsnopio) tfsnopio [File_System | Auto | Running] -> %SystemRoot%\system32\dla\tfsnopio.sys -> [2004/03/10 00:04:00 | 00,014,229 | —- | M] (Sonic Solutions)
(tfsnpool) tfsnpool [File_System | Auto | Running] -> %SystemRoot%\system32\dla\tfsnpool.sys -> [2004/03/10 00:04:00 | 00,006,357 | —- | M] (Sonic Solutions)
(tfsnudf) tfsnudf [File_System | Auto | Running] -> %SystemRoot%\system32\dla\tfsnudf.sys -> [2004/03/10 00:04:00 | 00,098,580 | —- | M] (Sonic Solutions)
(tfsnudfa) tfsnudfa [File_System | Auto | Running] -> %SystemRoot%\system32\dla\tfsnudfa.sys -> [2004/03/10 00:04:00 | 00,100,597 | —- | M] (Sonic Solutions)
(ultra) ultra [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ultra.sys -> [2001/08/17 13:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\usbaapl.sys -> [2008/09/10 15:45:18 | 00,032,000 | —- | M] (Apple, Inc.)
(usbaudio) USB Audio Driver (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\usbaudio.sys -> [2008/04/13 13:45:12 | 00,060,032 | —- | M] (Microsoft Corporation)
(winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSF_CNXT.sys -> [2003/11/17 21:58:02 | 00,680,704 | —- | M] (Conexant Systems, Inc.)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://www.google.com -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type. -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Secondary Start Pages" -> Reg Error: Invalid data type. -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.google.com -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"Default_Page_URL" -> www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://www.google.com/ie -> 
HKEY_LOCAL_MACHINE\: Search\\"Start Page" -> www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.google.com -> 
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.google.com -> 
HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key error. [Yahoo! Toolbar] -> File not found
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> 
< FireFox Settings [Default Profile] > -> C:\Documents and Settings\Phillip\Application Data\Mozilla\FireFox\Profiles\wb4on7zn.default\prefs.js -> 
browser.search.selectedEngine -> "Google" ->
browser.startup.homepage -> "http://www.weather.com/weather/local/11803?lswe=11803&lwsa;=WeatherLocalUndeclared&from;=whatwhere" ->
browser.startup.homepage_override.mstone -> "rv:1.9.0.6" ->
extensions.enabledItems -> {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10 ->
extensions.enabledItems -> [removed]:1.0 ->
extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.0 ->
extensions.enabledItems -> {5601B994-0E9B-4ce2-8AB9-AD1155F2ABBD}:1.0.0.8 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6 ->
< HOSTS File > (736 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
127.0.0.1	   localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/12/18 03:16:42 | 00,059,032 | —- | M] (Adobe Systems Incorporated)
{31FF080D-12A3-439A-A2EF-4BA95A3148E8} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{5CA3D70E-1895-11CF-8E15-001234567890} [HKLM] -> %SystemRoot%\system32\dla\tfswshx.dll [DriveLetterAccess] -> [2004/03/10 00:04:00 | 00,110,644 | —- | M] (Sonic Solutions)
{7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\google\googletoolbar1.dll [Google Toolbar Helper] -> [2009/02/21 11:58:56 | 02,133,056 | R— | M] (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> %ProgramFiles%\Java\jre6\bin\jp2ssv.dll [Java™ Plug-In 2 SSV Helper] -> [2009/02/20 11:42:50 | 00,035,840 | —- | M] (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2009/02/20 11:42:51 | 00,073,728 | —- | M] (Sun Microsystems, Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{0BF43445-2F28-4351-9252-17FE6E806AA0}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\google\googletoolbar1.dll [&Google;] -> [2009/02/21 11:58:56 | 02,133,056 | R— | M] (Google Inc.)
"{D0943516-5076-4020-A3B5-AEFAF26AB263}" [HKLM] -> %ProgramFiles%\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [Veoh Browser Plug-in] -> [2008/04/01 17:23:42 | 00,352,256 | —- | M] (Veoh Networks Inc)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\google\googletoolbar1.dll [&Google;] -> [2009/02/21 11:58:56 | 02,133,056 | R— | M] (Google Inc.)
WebBrowser\\"{A057A204-BACC-4D26-8087-36EE87E26986}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"" ->  [] -> File not found
"Ad-Watch" -> %ProgramFiles%\Lavasoft\Ad-Aware\AAWTray.exe [C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe] -> [2009/02/02 21:22:15 | 00,509,784 | —- | M] (Lavasoft)
"ClubBox" ->  [] -> File not found
"dla" -> %SystemRoot%\system32\dla\tfswctrl.exe [C:\WINDOWS\system32\dla\tfswctrl.exe] -> [2004/03/10 00:04:00 | 00,118,837 | —- | M] (Sonic Solutions)
"DMXLauncher" -> %ProgramFiles%\Sonic\Product\Media Experience\DMXLauncher.exe ["C:\Program Files\Sonic\Product\Media Experience\DMXLauncher.exe"] -> [2007/04/02 04:24:10 | 00,113,400 | —- | M] ()
"HP Software Update" -> %ProgramFiles%\HP\HP Software Update\HPWuSchd2.exe [C:\Program Files\HP\HP Software Update\HPWuSchd2.exe] -> [2005/05/11 22:12:54 | 00,049,152 | —- | M] (Hewlett-Packard Co.)
"IAAnotif" -> %ProgramFiles%\Intel\Intel Matrix Storage Manager\iaanotif.exe [C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe] -> [2005/06/17 07:56:14 | 00,139,264 | —- | M] (Intel Corporation)
"ISUSPM Startup" -> %CommonProgramFiles%\InstallShield\UpdateService\isuspm.exe ["C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup] -> [2005/08/12 05:30:30 | 00,249,856 | —- | M] (Macrovision Corporation)
"ISUSScheduler" -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe ["C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start] -> [2005/08/12 05:30:30 | 00,081,920 | —- | M] (Macrovision Corporation)
"iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/09/10 16:40:06 | 00,289,576 | —- | M] (Apple Inc.)
"LifeCam" -> %ProgramFiles%\Microsoft LifeCam\LifeExp.exe ["C:\Program Files\Microsoft LifeCam\LifeExp.exe"] -> [2008/08/04 16:22:18 | 00,160,800 | —- | M] (Microsoft Corporation)
"NvCplDaemon" -> %SystemRoot%\system32\NvCpl.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2007/12/05 00:41:00 | 08,523,776 | —- | M] (NVIDIA Corporation)
"NvMediaCenter" -> %SystemRoot%\system32\NvMcTray.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2007/12/05 00:41:00 | 00,081,920 | —- | M] (NVIDIA Corporation)
"nwiz" -> %SystemRoot%\system32\nwiz.exe [nwiz.exe /install] -> [2007/12/05 00:41:00 | 01,626,112 | —- | M] ()
"QuickTime Task" -> %ProgramFiles%\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2008/09/06 14:09:14 | 00,413,696 | —- | M] (Apple Inc.)
"SigmatelSysTrayApp" -> %SystemRoot%\stsystra.exe [stsystra.exe] -> [2005/03/22 23:20:44 | 00,339,968 | —- | M] (SigmaTel, Inc.)
"SunJavaUpdateSched" -> %ProgramFiles%\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009/02/20 11:42:50 | 00,148,888 | —- | M] (Sun Microsystems, Inc.)
"TkBellExe" -> %CommonProgramFiles%\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot] -> [2008/04/19 21:37:33 | 00,185,896 | —- | M] (RealNetworks, Inc.)
"Windows Defender" -> %ProgramFiles%\Windows Defender\MSASCui.exe ["C:\Program Files\Windows Defender\MSASCui.exe" -hide] -> [2006/11/03 18:20:12 | 00,866,584 | —- | M] (Microsoft Corporation)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"" ->  [] -> File not found
"Aim6" -> %ProgramFiles%\AIM6\aim6.exe ["C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp] -> [2008/06/12 15:47:13 | 00,050,528 | —- | M] (AOL LLC)
"Google Update" -> %UserProfile%\Local Settings\Application Data\Google\Update\GoogleUpdate.exe ["C:\Documents and Settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c] -> [2008/12/20 23:46:23 | 00,133,104 | —- | M] (Google Inc.)
"oovoo.exe" -> %ProgramFiles%\ooVoo\ooVoo.exe [C:\Program Files\ooVoo\ooVoo.exe /minimized] -> [2009/02/01 23:51:08 | 14,612,272 | —- | M] (ooVoo)
"updateMgr" -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0] -> [2006/03/30 15:45:08 | 00,313,472 | R— | M] (Adobe Systems Incorporated)
"WMPNSCFG" -> %ProgramFiles%\Windows Media Player\WMPNSCFG.exe [C:\Program Files\Windows Media Player\WMPNSCFG.exe] -> [2006/10/18 20:05:26 | 00,204,288 | —- | M] (Microsoft Corporation)
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> [2008/04/23 02:38:16 | 00,029,696 | —- | M] (Adobe Systems Incorporated)
< Phillip Startup Folder > -> C:\Documents and Settings\Phillip\Start Menu\Programs\Startup -> 
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer -> 
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoCDBurning" ->  [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"InstallVisualStyle" -> %SystemRoot%\Resources\Themes\Royale\Royale.mss [C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles] -> File not found
\\"InstallTheme" -> %SystemRoot%\Resources\Themes\Royale.the [C:\WINDOWS\Resources\Themes\Royale.theme] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [36] -> File not found
\\"NoDriveAutoRun" ->  [FF FF FF FF  [binary data]] -> File not found
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
Download with GetRight -> %ProgramFiles%\GetRight\GRdownload.htm [C:\Program Files\GetRight\GRdownload.htm] -> File not found
E&xport; to Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000] -> [2008/10/13 11:29:28 | 10,351,944 | —- | M] (Microsoft Corporation)
Open with GetRight Browser -> %ProgramFiles%\GetRight\GRbrowse.htm [C:\Program Files\GetRight\GRbrowse.htm] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Menu: Sun Java Console] -> [2008/06/10 03:27:02 | 00,132,496 | —- | M] (Sun Microsystems, Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2007/04/19 14:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}:Exec [HKLM] -> %ProgramFiles%\AIM\aim.exe [Button: AIM] -> [2006/08/01 14:35:36 | 00,067,112 | —- | M] (America Online, Inc.)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 03:27:02 | 00,132,496 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 14:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}" [HKLM] -> %ProgramFiles%\AIM\aim.exe [AIM] -> [2006/08/01 14:35:36 | 00,067,112 | —- | M] (America Online, Inc.)
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime;=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 2 domain(s) found. -> 
online_musicmatch.com [https] -> Trusted sites -> 
2 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4169 domain(s) found. -> 
32 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{00001025-A15C-11D4-97A4-0050BF0FBE67} [HKLM] -> http://download.netmarble.com/web/nmstarter/NMStarter25.cab [NetmarbleStarter25 Class] -> 
{0CCA191D-13A6-4E29-B746-314DEE697D83} [HKLM] -> http://upload.facebook.com/controls/FacebookPhotoUploader5.cab [Facebook Photo Uploader 5] -> 
{1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} [HKLM] -> http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB [Tpwin Control] -> 
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} [HKLM] -> http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab [Reg Error: Key error.] -> 
{5F5F9FB8-878E-4455-95E0-F64B2314288A} [HKLM] -> http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab [ijjiPlugin2 Class] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab [Java Plug-in 1.6.0_12] -> 
{92E82FBB-DA00-41E0-ABFE-95482E21A4F6} [HKLM] -> http://download.netmarble.net/NMChatX/NMTransX.cab [NMTransX Module] -> 
{938527D1-CDB7-4147-998A-B20FCA5CC976} [HKLM] -> http://cafeimg.hanmail.net/activex/dmcc2.cab?Version=1,0,0,10 [Cdmcco Class] -> 
{A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} [HKLM] -> http://download.netmarble.net/kdefence/kdfense8237.cab [Reg Error: Key error.] -> 
{AF60D574-F249-4243-8040-5521AAA5BB5E} [HKLM] -> http://imgcdn.pandora.tv/pan_img/p3player/package/pdrtvset.cab [PandoraTVSet Class] -> 
{C0B2F53E-5E61-4856-B314-FE9AE262A796} [HKLM] -> http://www.melon.com/cab/P3MelWebInstall.cab [MOPlayerWnd2 Class] -> 
{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab [Reg Error: Key error.] -> 
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab [Reg Error: Key error.] -> 
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab [Reg Error: Key error.] -> 
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab [Reg Error: Key error.] -> 
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> 
{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab [Java Plug-in 1.6.0_12] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab [Java Plug-in 1.6.0_12] -> 
{CBB45291-871B-4ADA-81D0-40D0C89ABD20} [HKLM] -> http://download.netmarble.com/web/NMGameCheck/NetmarbleDownloaderEx.cab [NetmarbleDownloaderExCtrl Class] -> 
{CD995117-98E5-4169-9920-6C12D4C0B548} [HKLM] -> http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab [Reg Error: Key error.] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab [Shockwave Flash Object] -> 
{EE4D2623-4584-42A1-9A2D-BD5FACAA9541} [HKLM] -> http://sing.melon.com/melon/player/ocx/MelonSingPlayer.cab [Melon Sing Player] -> 
{F4A1D5E2-AF49-47A7-A945-23038106F3A4} [HKLM] -> http://imgcdn.pandora.tv/pan_img/launcher/codebase/Pandora_SetUpAX.cab [Pandora_SetUp Control] -> 
vzTCPConfig [HKLM] -> http://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB [Reg Error: Key error.] -> 
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{7789D749-544C-4382-90DD-2C3AA7C3E3BA} ->	(Intel(R) PRO/1000 PL Network Connection) -> 
{EB5AE332-E1A2-45FB-9D4D-D9DE494E6920} ->	() -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
Explorer.exe -> %SystemRoot%\Explorer.exe -> [2008/04/13 19:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> 
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" [HKLM] -> %ProgramFiles%\Windows Defender\MpShHook.dll [Microsoft AntiMalware ShellExecuteHook] -> [2006/11/03 18:20:00 | 00,083,224 | —- | M] (Microsoft Corporation)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 19:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Program Files\AIM\aim.exe" -> C:\Program Files\AIM\aim.exe [C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger] -> [2006/08/01 14:35:36 | 00,067,112 | —- | M] (America Online, Inc.)
"C:\Program Files\America Online 9.0\waol.exe" -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 15:10:02 | 00,297,752 | —- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msncall.exe" -> C:\Program Files\MSN Messenger\msncall.exe [C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)] -> File not found
"C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 11:54:56 | 05,674,352 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 19:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme" -> C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme [C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme:*:Enabled:GunBound] -> File not found
"C:\ijji\ENGLISH\u_gbound.exe" -> C:\ijji\ENGLISH\u_gbound.exe [C:\ijji\ENGLISH\u_gbound.exe:*:Enabled:] -> [2008/05/19 21:06:05 | 00,868,352 | —- | M] (NHN USA inc.)
"C:\ijji\ENGLISH\u_gunz.exe" -> C:\ijji\ENGLISH\u_gunz.exe [C:\ijji\ENGLISH\u_gunz.exe:*:Enabled:] -> [2008/05/27 17:31:30 | 00,868,352 | —- | M] (NHN USA inc.)
"C:\ijji\ENGLISH\u_sf\soldierfront.exe" -> C:\ijji\ENGLISH\u_sf\soldierfront.exe [C:\ijji\ENGLISH\u_sf\soldierfront.exe:*:Enabled:soldierfront] -> File not found
"C:\Netmarble\NetmarbleDownLoaderEx\NetmarbleDownLoader_EngineEx.exe" -> C:\Netmarble\NetmarbleDownLoaderEx\NetmarbleDownLoader_EngineEx.exe [C:\Netmarble\NetmarbleDownLoaderEx\NetmarbleDownLoader_EngineEx.exe:*:Enabled:NetmarbleDownLoader_EngineEx.exe] -> [2008/09/10 12:21:28 | 00,643,072 | —- | M] ()
"C:\Nexon\MapleStory\MapleStory.exe" -> C:\Nexon\MapleStory\MapleStory.exe [C:\Nexon\MapleStory\MapleStory.exe:*:Enabled:MapleStory] -> File not found
"C:\Nexon\MapleStory\Patcher.exe" -> C:\Nexon\MapleStory\Patcher.exe [C:\Nexon\MapleStory\Patcher.exe:*:Enabled:Patcher MFC 응용 프로그램] -> File not found
"C:\Program Files\AIM\aim.exe" -> C:\Program Files\AIM\aim.exe [C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger] -> [2006/08/01 14:35:36 | 00,067,112 | —- | M] (America Online, Inc.)
"C:\Program Files\AIM6\aim6.exe" -> C:\Program Files\AIM6\aim6.exe [C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM] -> [2008/06/12 15:47:13 | 00,050,528 | —- | M] (AOL LLC)
"C:\Program Files\America Online 9.0\waol.exe" -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\America's Army\System\ArmyOps.exe" -> C:\Program Files\America's Army\System\ArmyOps.exe [C:\Program Files\America's Army\System\ArmyOps.exe:*:Enabled:ArmyOps] -> [2008/10/16 16:40:20 | 00,131,072 | —- | M] ()
"C:\Program Files\America's Army\System\Server.exe" -> C:\Program Files\America's Army\System\Server.exe [C:\Program Files\America's Army\System\Server.exe:*:Enabled:Server] -> [2008/10/16 16:40:32 | 00,061,440 | —- | M] ()
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe" -> C:\Program Files\BearShare Applications\BearShare\BearShare.exe [C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare] -> File not found
"C:\Program Files\BitTorrent\bittorrent.exe" -> C:\Program Files\BitTorrent\bittorrent.exe [C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent] -> [2008/12/08 20:08:04 | 00,637,232 | —- | M] (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 02:17:27 | 00,010,800 | —- | M] (AOL LLC)
"C:\Program Files\DNA\btdna.exe" -> C:\Program Files\DNA\btdna.exe [C:\Program Files\DNA\btdna.exe:*:Enabled:DNA] -> File not found
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/09/10 16:39:54 | 14,228,264 | —- | M] (Apple Inc.)
"C:\Program Files\JCePORTS\FreeStyle\FreeStyle.exe" -> C:\Program Files\JCePORTS\FreeStyle\FreeStyle.exe [C:\Program Files\JCePORTS\FreeStyle\FreeStyle.exe:*:Enabled:FreeStyle] -> File not found
"C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> [2006/08/16 14:16:24 | 00,159,744 | —- | M] ()
"C:\Program Files\Ma9Ma9\AceClient.exe" -> C:\Program Files\Ma9Ma9\AceClient.exe [C:\Program Files\Ma9Ma9\AceClient.exe:*:Enabled:AceClient] -> File not found
"C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" -> C:\Program Files\Microsoft LifeCam\LifeCam.exe [C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe] -> [2008/08/04 16:22:18 | 00,140,320 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe" -> C:\Program Files\Microsoft LifeCam\LifeEnC2.exe [C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe] -> [2008/08/04 16:22:18 | 00,230,432 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" -> C:\Program Files\Microsoft LifeCam\LifeExp.exe [C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe] -> [2008/08/04 16:22:18 | 00,160,800 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeTray.exe" -> C:\Program Files\Microsoft LifeCam\LifeTray.exe [C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe] -> [2008/08/04 16:22:18 | 00,107,552 | —- | M] (Microsoft Corporation)
"C:\Program Files\mIRC\mirc.exe" -> C:\Program Files\mIRC\mirc.exe [C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC] -> File not found
"C:\Program Files\Mozilla Firefox 2 Beta 2\firefox.exe" -> C:\Program Files\Mozilla Firefox 2 Beta 2\firefox.exe [C:\Program Files\Mozilla Firefox 2 Beta 2\firefox.exe:*:Enabled:Firefox] -> [2009/02/20 01:32:55 | 00,307,704 | —- | M] (Mozilla Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" -> C:\Program Files\Mozilla Firefox\firefox.exe [C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox] -> File not found
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 15:10:02 | 00,297,752 | —- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msncall.exe" -> C:\Program Files\MSN Messenger\msncall.exe [C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)] -> File not found
"C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 11:54:56 | 05,674,352 | —- | M] (Microsoft Corporation)
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe" -> C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe [C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home] -> [2006/06/01 13:32:50 | 00,147,456 | —- | M] (Nero AG)
"C:\Program Files\Netmarble\NetmarbleTetrisPlus\TetrisPlus.exe" -> C:\Program Files\Netmarble\NetmarbleTetrisPlus\TetrisPlus.exe [C:\Program Files\Netmarble\NetmarbleTetrisPlus\TetrisPlus.exe:*:Enabled:넷마블 테트리스 플러스] -> File not found
"C:\Program Files\ooVoo\ooVoo.exe" -> C:\Program Files\ooVoo\ooVoo.exe [C:\Program Files\ooVoo\ooVoo.exe:*:Enabled:ooVoo] -> [2009/02/01 23:51:08 | 14,612,272 | —- | M] (ooVoo)
"C:\Program Files\Real\RealPlayer\realplay.exe" -> C:\Program Files\Real\RealPlayer\realplay.exe [C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer] -> [2008/04/19 21:37:55 | 00,214,560 | —- | M] (RealNetworks, Inc.)
"C:\Program Files\Sierra Online\FreeStyle Street Basketball(TM)\FreeStyle.exe" -> C:\Program Files\Sierra Online\FreeStyle Street Basketball(TM)\FreeStyle.exe [C:\Program Files\Sierra Online\FreeStyle Street Basketball(TM)\FreeStyle.exe:*:Enabled:FreeStyle] -> File not found
"C:\Program Files\Skype\Phone\Skype.exe" -> C:\Program Files\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] -> File not found
"C:\Program Files\Starcraft\StarCraft.exe" -> C:\Program Files\Starcraft\StarCraft.exe [C:\Program Files\Starcraft\StarCraft.exe:*:Enabled:Starcraft] -> [2008/01/10 15:23:42 | 01,220,608 | —- | M] (Blizzard Entertainment)
"C:\Program Files\Steam\Steam.exe" -> C:\Program Files\Steam\Steam.exe [C:\Program Files\Steam\Steam.exe:*:Enabled:Steam] -> [2008/10/25 20:46:08 | 01,410,296 | —- | M] (Valve Corporation)
"C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForever.exe" -> C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForever.exe [C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForever.exe:*:Enabled:TmForever] -> File not found
"C:\Program Files\Steam\steamapps\lilkrnboi323\counter-strike\hl.exe" -> C:\Program Files\Steam\steamapps\lilkrnboi323\counter-strike\hl.exe [C:\Program Files\Steam\steamapps\lilkrnboi323\counter-strike\hl.exe:*:Enabled:Half-Life Launcher] -> File not found
"C:\Program Files\Steam\steamapps\nv_snipe\counter-strike\hl.exe" -> C:\Program Files\Steam\steamapps\nv_snipe\counter-strike\hl.exe [C:\Program Files\Steam\steamapps\nv_snipe\counter-strike\hl.exe:*:Enabled:Half-Life Launcher] -> [2006/07/28 00:57:42 | 00,081,920 | —- | M] (Valve)
"C:\Program Files\Steam\steamapps\nv_snipe\day of defeat source\hl2.exe" -> C:\Program Files\Steam\steamapps\nv_snipe\day of defeat source\hl2.exe [C:\Program Files\Steam\steamapps\nv_snipe\day of defeat source\hl2.exe:*:Enabled:hl2] -> [2006/07/26 12:05:11 | 00,106,496 | —- | M] ()
"C:\Program Files\Steam\steamapps\xxredkidxx\condition zero deleted scenes\hl.exe" -> C:\Program Files\Steam\steamapps\xxredkidxx\condition zero deleted scenes\hl.exe [C:\Program Files\Steam\steamapps\xxredkidxx\condition zero deleted scenes\hl.exe:*:Enabled:Half-Life Launcher] -> File not found
"C:\Program Files\Steam\steamapps\xxredkidxx\condition zero\hl.exe" -> C:\Program Files\Steam\steamapps\xxredkidxx\condition zero\hl.exe [C:\Program Files\Steam\steamapps\xxredkidxx\condition zero\hl.exe:*:Enabled:Half-Life Launcher] -> File not found
"C:\Program Files\Steam\steamapps\xxredkidxx\counter-strike source beta\hl2.exe" -> C:\Program Files\Steam\steamapps\xxredkidxx\counter-strike source beta\hl2.exe [C:\Program Files\Steam\steamapps\xxredkidxx\counter-strike source beta\hl2.exe:*:Enabled:hl2] -> [2006/10/28 19:06:08 | 00,106,496 | —- | M] ()
"C:\Program Files\Steam\steamapps\xxredkidxx\counter-strike source\hl2.exe" -> C:\Program Files\Steam\steamapps\xxredkidxx\counter-strike source\hl2.exe [C:\Program Files\Steam\steamapps\xxredkidxx\counter-strike source\hl2.exe:*:Enabled:hl2] -> [2008/06/25 11:07:30 | 00,106,496 | —- | M] ()
"C:\Program Files\Steam\steamapps\xxredkidxx\counter-strike\hl.exe" -> C:\Program Files\Steam\steamapps\xxredkidxx\counter-strike\hl.exe [C:\Program Files\Steam\steamapps\xxredkidxx\counter-strike\hl.exe:*:Enabled:Half-Life Launcher] -> [2009/02/14 16:19:07 | 00,086,077 | —- | M] (Valve)
"C:\Program Files\Steam\steamapps\xxredkidxx\day of defeat source\hl2.exe" -> C:\Program Files\Steam\steamapps\xxredkidxx\day of defeat source\hl2.exe [C:\Program Files\Steam\steamapps\xxredkidxx\day of defeat source\hl2.exe:*:Enabled:hl2] -> [2008/06/25 14:15:05 | 00,106,496 | —- | M] ()
"C:\Program Files\Steam\steamapps\xxredkidxx\dedicated server\hlds.exe" -> C:\Program Files\Steam\steamapps\xxredkidxx\dedicated server\hlds.exe [C:\Program Files\Steam\steamapps\xxredkidxx\dedicated server\hlds.exe:*:Enabled:HLDS Launcher] -> File not found
"C:\Program Files\Steam\steamapps\xxredkidxx\dedicated server\hltv.exe" -> C:\Program Files\Steam\steamapps\xxredkidxx\dedicated server\hltv.exe [C:\Program Files\Steam\steamapps\xxredkidxx\dedicated server\hltv.exe:*:Enabled:HLTV Launcher] -> [2006/12/24 00:30:58 | 00,221,184 | —- | M] (Valve)
"C:\Program Files\Steam\steamapps\xxredkidxx\half-life\hl.exe" -> C:\Program Files\Steam\steamapps\xxredkidxx\half-life\hl.exe [C:\Program Files\Steam\steamapps\xxredkidxx\half-life\hl.exe:*:Enabled:Half-Life Launcher] -> File not found
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" -> C:\Program Files\Veoh Networks\Veoh\VeohClient.exe [C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client] -> [2008/04/01 17:35:26 | 03,587,120 | —- | M] (Veoh Networks)
"C:\Program Files\Warcraft III\Warcraft III.exe" -> C:\Program Files\Warcraft III\Warcraft III.exe [C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III] -> [2007/11/17 00:17:48 | 00,274,432 | —- | M] (Blizzard Entertainment)
"C:\Program Files\Wizet\MapleStory\Patcher.exe" -> C:\Program Files\Wizet\MapleStory\Patcher.exe [C:\Program Files\Wizet\MapleStory\Patcher.exe:*:Enabled:Patcher MFC 응용 프로그램] -> File not found
"C:\Program Files\Xfire\Xfire.exe" -> C:\Program Files\Xfire\Xfire.exe [C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire] -> File not found
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -> C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger] -> File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" -> C:\Program Files\Yahoo!\Messenger\YServer.exe [C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server] -> File not found
"C:\StubInstaller.exe" -> C:\StubInstaller.exe [C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer] -> [2005/10/31 10:56:00 | 00,700,416 | —- | M] (LimeWire)
"C:\WINDOWS\system32\BugsSvr.exe" -> C:\WINDOWS\system32\BugsSvr.exe [C:\WINDOWS\system32\BugsSvr.exe:*:Enabled:Bugs Music Player Control] -> File not found
"C:\WINDOWS\system32\ClubBox.exe" -> C:\WINDOWS\system32\ClubBox.exe [C:\WINDOWS\system32\ClubBox.exe:*:Enabled:嬷´¹ú½º æäàïàü¼û °ü¸®àú] -> File not found
"C:\WINDOWS\system32\dpvsetup.exe" -> C:\WINDOWS\system32\dpvsetup.exe [C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test] -> [2008/04/13 19:12:18 | 00,083,456 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\FSCAgent.exe" -> C:\WINDOWS\system32\FSCAgent.exe [C:\WINDOWS\system32\FSCAgent.exe:*:Enabled:클럽박스 파일전송 데몬] -> File not found
"C:\WINDOWS\system32\grdmgr.exe" -> C:\WINDOWS\system32\grdmgr.exe [C:\WINDOWS\system32\grdmgr.exe:*:Enabled:CDN 파일전송 데몬] -> [2007/03/20 07:50:46 | 00,102,400 | R— | M] (나우콤)
"C:\WINDOWS\system32\pdrtvsvr.exe" -> C:\WINDOWS\system32\pdrtvsvr.exe [C:\WINDOWS\system32\pdrtvsvr.exe:*:Enabled:PandoraTV VoD Control] -> [2007/03/11 12:02:07 | 00,204,800 | —- | M] (PandoraTV)
"C:\WINDOWS\system32\rundll32.exe" -> C:\WINDOWS\system32\rundll32.exe [C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App] -> [2008/04/13 19:12:33 | 00,033,280 | —- | M] (Microsoft Corporation)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 13:40:46 | 00,062,976 | —- | M] (Microsoft Corporation)
< Drives with AutoRun files > ->  -> 
C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2005/08/16 04:43:04 | 00,000,000 | —- | M] ()
C:\autorun.inf [] -> %SystemDrive%\autorun.inf [ NTFS ] -> [2009/02/21 15:11:20 | 00,000,000 | RHSD | M]
C:\autorun.PNF [ | ] -> %SystemDrive%\autorun.PNF [ NTFS ] -> [2009/02/20 14:11:11 | 00,002,524 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
\{361ac05d-0e0d-11da-9aa9-806d6172696f}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell
\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\\"" ->  [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun
\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\\"" ->  [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command
\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command\\"" -> E:\setup.exe [E:\setup.exe] -> File not found
 
[Registry - Additional Scans - Safe List]
< ColumnHandlers - Folder [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\ -> 
{F9DB5320-233E-11D1-9F84-707F02C10627} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll [PDF Shell Extension] -> [2004/12/14 01:20:02 | 00,110,592 | —- | M] (Adobe Systems, Inc.)
< Desktop Components > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\ -> 
0 -> [Key] -> 
0 -> FriendlyName = My Current Home Page -> 
0 -> Source = About:Home -> 
0 -> SubscribedURL = About:Home -> 
< Disabled MSConfig Folder Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\ -> 
C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> [2005/05/11 22:23:26 | 00,282,624 | —- | M] (Hewlett-Packard Co.)
< Disabled MSConfig State [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state -> 
"bootini" -> 0 -> 
"services" -> 0 -> 
"startup" -> 2 -> 
"system.ini" -> 0 -> 
"win.ini" -> 0 -> 
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> 
.bat [@ = batfile] -> "%1" %* -> 
.cmd [@ = cmdfile] -> "%1" %* -> 
.com [@ = comfile] -> "%1" %* -> 
.exe [@ = exefile] -> "%1" %* -> 
.html [@ = FirefoxHTML] -> %ProgramFiles%\Mozilla Firefox 2 Beta 2\firefox.exe -> [2009/02/20 01:32:55 | 00,307,704 | —- | M] (Mozilla Corporation)
.pif [@ = piffile] -> "%1" %* -> 
.scr [@ = scrfile] -> "%1" /S -> 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > -> ->
*netsvcs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ->
6to4 ->  [] -> 
Ias ->  [] -> 
Iprip ->  [] -> 
Irmon ->  [] -> 
NWCWorkstation ->  [] -> 
Nwsapagent ->  [] -> 
WmdmPmSp ->  [] -> 
MHN -> C:\WINDOWS\System32\mhn.dll [C:\WINDOWS\System32\mhn.dll] -> [2004/08/10 04:11:50 | 00,085,504 | —- | M] (Microsoft Corporation)
helpsvc -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll] -> [2008/04/13 19:12:02 | 00,038,400 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Protocol Filters [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\ -> 
text/xml:{807553E5-5146-11D5-A672-00B0D022E945} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\OFFICE11\MSOXMLMF.DLL[Reg Error: Value error.] -> [2007/04/19 13:57:40 | 00,046,432 | —- | M] (Microsoft Corporation)
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 
ipp: [HKLM] -> No CLSID value
ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> %CommonProgramFiles%\SYSTEM\OLE DB\msdaipp.dll[MSDAMON.BINDER] -> [2005/09/20 12:33:58 | 00,843,984 | —- | M] (Microsoft Corporation)
livecall:{828030A1-22C1-4009-854F-8E305202313F} [HKLM] -> %ProgramFiles%\MSN Messenger\msgrapp.8.1.0178.00.dll[Reg Error: Value error.] -> [2007/01/19 11:53:24 | 00,063,344 | —- | M] (Microsoft Corporation)
msdaipp: [HKLM] -> No CLSID value
msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> %CommonProgramFiles%\SYSTEM\OLE DB\msdaipp.dll[MSDAMON.BINDER] -> [2005/09/20 12:33:58 | 00,843,984 | —- | M] (Microsoft Corporation)
msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> %CommonProgramFiles%\SYSTEM\OLE DB\msdaipp.dll[MSDAIPP.BINDER] -> [2005/09/20 12:33:58 | 00,843,984 | —- | M] (Microsoft Corporation)
msnim:{828030A1-22C1-4009-854F-8E305202313F} [HKLM] -> %ProgramFiles%\MSN Messenger\msgrapp.8.1.0178.00.dll[Reg Error: Value error.] -> [2007/01/19 11:53:24 | 00,063,344 | —- | M] (Microsoft Corporation)
mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Web Components\10\OWC10.DLL[Data Page Pluggable Protocol mso-offdap Handler] -> [2007/03/14 13:10:22 | 07,255,384 | —- | M] (Microsoft Corporation)
mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Web Components\11\OWC11.DLL[Data Page Plugable Protocal mso-offdap11 Handler] -> [2007/05/10 13:45:34 | 08,069,464 | —- | M] (Microsoft Corporation)
< SafeBoot-Minimal Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ -> 
{36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse
{4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} -> System
{4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive
{533C5B84-EC70-11D2-9505-00C04F79DEAF} -> Volume shadow copy
{71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices
Base -> Driver Group
Boot Bus Extender -> Driver Group
Boot file system -> Driver Group
File system -> Driver Group
Filter -> Driver Group
HelpSvc -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/13 19:12:02 | 00,038,400 | —- | M] (Microsoft Corporation)
Lavasoft Ad-Aware Service -> %ProgramFiles%\Lavasoft\Ad-Aware\AAWService.exe -> [2009/02/02 21:22:14 | 00,950,096 | —- | M] (Lavasoft)
PCI Configuration -> Driver Group
PNP Filter -> Driver Group
Primary disk -> Driver Group
SCSI Class -> Driver Group
sermouse.sys -> Driver
System Bus Extender -> Driver Group
vds -> Service
vga.sys -> Driver
WinDefend -> %ProgramFiles%\Windows Defender\MsMpEng.exe -> [2006/11/03 18:19:58 | 00,013,592 | —- | M] (Microsoft Corporation)
< SafeBoot-Network Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ -> 
{36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse
{4D36E972-E325-11CE-BFC1-08002BE10318} -> Net
{4D36E973-E325-11CE-BFC1-08002BE10318} -> NetClient
{4D36E974-E325-11CE-BFC1-08002BE10318} -> NetService
{4D36E975-E325-11CE-BFC1-08002BE10318} -> NetTrans
{4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} -> System
{4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices
Base -> Driver Group
Boot Bus Extender -> Driver Group
Boot file system -> Driver Group
File system -> Driver Group
Filter -> Driver Group
HelpSvc -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/13 19:12:02 | 00,038,400 | —- | M] (Microsoft Corporation)
Lavasoft Ad-Aware Service -> %ProgramFiles%\Lavasoft\Ad-Aware\AAWService.exe -> [2009/02/02 21:22:14 | 00,950,096 | —- | M] (Lavasoft)
NDIS Wrapper -> Driver Group
NetBIOSGroup -> Driver Group
NetDDEGroup -> Driver Group
Network -> Driver Group
NetworkProvider -> Driver Group
PCI Configuration -> Driver Group
PNP Filter -> Driver Group
PNP_TDI -> Driver Group
Primary disk -> Driver Group
rdpdd.sys -> %SystemRoot%\System32\rdpdd.dll -> [2008/04/13 19:13:22 | 00,092,424 | —- | M] (Microsoft Corporation)
SCSI Class -> Driver Group
sermouse.sys -> Driver
Streams Drivers -> Driver Group
System Bus Extender -> Driver Group
TDI -> Driver Group
vga.sys -> Driver
WinDefend -> %ProgramFiles%\Windows Defender\MsMpEng.exe -> [2006/11/03 18:19:58 | 00,013,592 | —- | M] (Microsoft Corporation)
< Session Manager Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager -> 
"BootExecute" -> autocheck autochk *;lsdelete; -> 
"ExcludeFromKnownDlls" ->  -> 
*ObjectDirectories* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\ObjectDirectories -> 
\Windows ->  -> File not found
\RPC Control ->  -> File not found
*MultiFile Done* -> -> 
*PendingFileRenameOperations* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\PendingFileRenameOperations -> 
\??\c:\docume~1\phillip\locals~1\temp\wjeeoeqj.dll [\??\c:\docume~1\phillip\locals~1\temp\wjeeoeqj.dll]  -> %SystemDrive%\docume~1\phillip\locals~1\temp\wjeeoeqj.dll [%SystemDrive%\docume~1\phillip\locals~1\temp\wjeeoeqj.dll] -> File not found
*MultiFile Done* -> -> 
< Session Manager Environment Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment -> 
"ComSpec" -> C:\WINDOWS\system32\cmd.exe -> [2008/04/13 19:12:14 | 00,389,120 | —- | M] (Microsoft Corporation)
"TEMP" -> %SystemRoot%\TEMP -> 
"TMP" -> %SystemRoot%\TEMP -> 
"windir" -> %SystemRoot% -> 
*Path* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\Path -> 
%SystemRoot%\system32 -> %SystemRoot%\system32 -> [2009/02/22 23:05:25 | 00,000,000 | —D | M]
%SystemRoot% -> %SystemRoot% -> [2009/02/23 16:44:59 | 00,000,000 | —D | M]
%SystemRoot%\System32\Wbem -> %SystemRoot%\System32\Wbem -> [2009/02/22 22:09:31 | 00,000,000 | —D | M]
C:\Program Files\Common Files\Roxio Shared\DLLShared\ -> %CommonProgramFiles%\Roxio Shared\DLLShared -> [2007/07/22 08:48:51 | 00,000,000 | —D | M]
C:\Program Files\Samsung\Samsung PC Studio 3\ ->  -> File not found
C:\Program Files\ATI Technologies\ATI.ACE\ -> %ProgramFiles%\ATI Technologies\ATI.ACE\ -> File not found
C:\Program Files\QuickTime\QTSystem\ -> %ProgramFiles%\QuickTime\QTSystem -> [2008/09/21 18:41:36 | 00,000,000 | —D | M]
c:\Program Files\Microsoft SQL Server\90\Tools\binn\ -> %ProgramFiles%\Microsoft SQL Server\90\Tools\binn -> [2008/12/04 21:30:23 | 00,000,000 | —D | M]
*MultiFile Done* -> -> 
*PATHEXT* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\PATHEXT -> 
.COM ->  -> File not found
.EXE ->  -> File not found
.BAT ->  -> File not found
.CMD ->  -> File not found
.VBS ->  -> File not found
.VBE ->  -> File not found
.JS ->  -> File not found
.JSE ->  -> File not found
.WSF ->  -> File not found
.WSH ->  -> File not found
*MultiFile Done* -> -> 
< Session Manager FileRenameOperations Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations -> 
< Session Manager KnownDlls Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDlls -> 
"advapi32" -> C:\WINDOWS\system32\advapi32.dll -> [2008/04/13 19:11:48 | 00,617,472 | —- | M] (Microsoft Corporation)
"comdlg32" -> C:\WINDOWS\system32\comdlg32.dll -> [2008/04/13 19:11:51 | 00,276,992 | —- | M] (Microsoft Corporation)
"DllDirectory" -> C:\WINDOWS\system32 -> [2009/02/22 23:05:25 | 00,000,000 | —D | M]
"gdi32" -> C:\WINDOWS\system32\gdi32.dll -> [2008/10/23 07:36:14 | 00,286,720 | —- | M] (Microsoft Corporation)
"imagehlp" -> C:\WINDOWS\system32\imagehlp.dll -> [2008/04/13 19:11:54 | 00,144,384 | —- | M] (Microsoft Corporation)
"kernel32" -> C:\WINDOWS\system32\kernel32.dll -> [2008/04/13 19:11:56 | 00,989,696 | —- | M] (Microsoft Corporation)
"lz32" -> C:\WINDOWS\system32\lz32.dll -> [2004/08/10 05:00:00 | 00,002,560 | —- | M] (Microsoft Corporation)
"ole32" -> C:\WINDOWS\system32\ole32.dll -> [2008/04/13 19:12:02 | 01,287,168 | —- | M] (Microsoft Corporation)
"oleaut32" -> C:\WINDOWS\system32\oleaut32.dll -> [2008/04/13 19:12:02 | 00,551,936 | —- | M] (Microsoft Corporation)
"olecli32" -> C:\WINDOWS\system32\olecli32.dll -> [2008/04/13 19:12:02 | 00,074,752 | —- | M] (Microsoft Corporation)
"olecnv32" -> C:\WINDOWS\system32\olecnv32.dll -> [2008/04/13 19:12:02 | 00,037,376 | —- | M] (Microsoft Corporation)
"olesvr32" -> C:\WINDOWS\system32\olesvr32.dll -> [2004/08/10 05:00:00 | 00,022,016 | —- | M] (Microsoft Corporation)
"olethk32" -> C:\WINDOWS\system32\olethk32.dll -> [2004/08/10 05:00:00 | 00,069,120 | —- | M] (Microsoft Corporation)
"rpcrt4" -> C:\WINDOWS\system32\rpcrt4.dll -> [2008/04/13 19:12:04 | 00,584,704 | —- | M] (Microsoft Corporation)
"shell32" -> C:\WINDOWS\system32\shell32.dll -> [2008/04/13 19:12:05 | 08,461,312 | —- | M] (Microsoft Corporation)
"url" -> C:\WINDOWS\system32\url.dll -> [2008/12/20 18:15:39 | 00,105,984 | —- | M] (Microsoft Corporation)
"urlmon" -> C:\WINDOWS\system32\urlmon.dll -> [2008/12/20 18:15:40 | 01,160,192 | —- | M] (Microsoft Corporation)
"user32" -> C:\WINDOWS\system32\user32.dll -> [2008/04/13 19:12:08 | 00,578,560 | —- | M] (Microsoft Corporation)
"version" -> C:\WINDOWS\system32\version.dll -> [2008/04/13 19:12:08 | 00,018,944 | —- | M] (Microsoft Corporation)
"wininet" -> C:\WINDOWS\system32\wininet.dll -> [2008/12/20 18:15:41 | 00,826,368 | —- | M] (Microsoft Corporation)
"wldap32" -> C:\WINDOWS\system32\wldap32.dll -> [2008/04/13 19:12:09 | 00,172,032 | —- | M] (Microsoft Corporation)
< Session Manager SFC Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SFC -> 
"CommonFilesDir" -> C:\Program Files\Common Files -> [2009/02/12 19:15:20 | 00,000,000 | —D | M]
"ProgramFilesDir" -> C:\Program Files -> [2009/02/22 23:08:32 | 00,000,000 | —D | M]
< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> 
NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] -> %SystemRoot%\System32\nwprovau.dll -> [2008/04/13 19:12:02 | 00,142,336 | —- | M] (Microsoft Corporation)
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 2/22/2009 12:36:11 AM Computer Name = HOME | Source = nview_info | ID = 11141121 -> Description = 
Application [ Error ] 2/22/2009 12:36:11 AM Computer Name = HOME | Source = nview_info | ID = 11141121 -> Description = 
Application [ Error ] 2/22/2009 12:36:11 AM Computer Name = HOME | Source = nview_info | ID = 11141121 -> Description = 
Application [ Error ] 2/22/2009 12:36:11 AM Computer Name = HOME | Source = nview_info | ID = 11141121 -> Description = 
Application [ Error ] 2/22/2009 12:36:11 AM Computer Name = HOME | Source = nview_info | ID = 11141121 -> Description = 
Application [ Error ] 2/22/2009 8:53:19 PM Computer Name = HOME | Source = nview_info | ID = 11141121 -> Description = 
Application [ Error ] 2/22/2009 9:02:53 PM Computer Name = HOME | Source = nview_info | ID = 11141121 -> Description = 
Application [ Error ] 2/22/2009 9:02:56 PM Computer Name = HOME | Source = nview_info | ID = 11141121 -> Description = 
Application [ Error ] 2/22/2009 9:38:39 PM Computer Name = HOME | Source = nview_info | ID = 11141121 -> Description = 
Application [ Error ] 2/23/2009 5:44:37 PM Computer Name = HOME | Source = Media Center Receiver | ID = 4 -> Description = TV tuner malfunction. (0xc0040597) WebcamMax, WDM Video Capture
System [ Error ] 2/22/2009 11:17:09 PM Computer Name = HOME | Source = Service Control Manager | ID = 7000 -> Description = The Digidesign MME Refresh Service service failed to start due to the following error:   %%2
System [ Error ] 2/22/2009 11:17:09 PM Computer Name = HOME | Source = Service Control Manager | ID = 7000 -> Description = The McAfee Real-time Scanner service failed to start due to the following error:   %%3
System [ Error ] 2/22/2009 11:17:09 PM Computer Name = HOME | Source = Service Control Manager | ID = 7000 -> Description = The McAfee SystemGuards service failed to start due to the following error:   %%3
System [ Error ] 2/22/2009 11:17:09 PM Computer Name = HOME | Source = Service Control Manager | ID = 7009 -> Description = Timeout (30000 milliseconds) waiting for the Roxio Upnp Server 9 service to connect.
System [ Error ] 2/22/2009 11:17:35 PM Computer Name = HOME | Source = Service Control Manager | ID = 7026 -> Description = The following boot-start or system-start driver(s) failed to load:   DigiFilter
System [ Error ] 2/23/2009 5:44:46 PM Computer Name = HOME | Source = Service Control Manager | ID = 7000 -> Description = The Digidesign MME Refresh Service service failed to start due to the following error:   %%2
System [ Error ] 2/23/2009 5:44:46 PM Computer Name = HOME | Source = Service Control Manager | ID = 7000 -> Description = The McAfee Real-time Scanner service failed to start due to the following error:   %%3
System [ Error ] 2/23/2009 5:44:46 PM Computer Name = HOME | Source = Service Control Manager | ID = 7000 -> Description = The McAfee SystemGuards service failed to start due to the following error:   %%3
System [ Error ] 2/23/2009 5:44:46 PM Computer Name = HOME | Source = Service Control Manager | ID = 7009 -> Description = Timeout (30000 milliseconds) waiting for the Roxio Upnp Server 9 service to connect.
System [ Error ] 2/23/2009 5:44:57 PM Computer Name = HOME | Source = Service Control Manager | ID = 7026 -> Description = The following boot-start or system-start driver(s) failed to load:   DigiFilter
 
[Files/Folders - Created Within 30 Days]
3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
1 C:\Documents and Settings\Phillip\My Documents\*.tmp files -> C:\Documents and Settings\Phillip\My Documents\*.tmp -> 
aaw7boot.cmd -> %SystemDrive%\aaw7boot.cmd -> [2009/02/23 16:59:20 | 00,000,098 | -H– | C] ()
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/02/23 16:51:52 | 00,000,000 | —D | C]
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/02/23 16:51:12 | 00,661,370 | —- | C] ()
Microsoft LifeCam.lnk -> %AllUsersProfile%\Desktop\Microsoft LifeCam.lnk -> [2009/02/22 23:09:20 | 00,001,788 | —- | C] ()
Microsoft LifeCam -> %ProgramFiles%\Microsoft LifeCam -> [2009/02/22 23:08:32 | 00,000,000 | —D | C]
Prefetch -> %SystemRoot%\Prefetch -> [2009/02/22 22:16:17 | 00,000,000 | —D | C]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/02/22 22:15:37 | 10,718,12608 | -HS- | C] ()
cc_20090222_220447.reg -> %UserProfile%\Desktop\cc_20090222_220447.reg -> [2009/02/22 22:04:51 | 01,932,472 | —- | C] ()
CCleaner -> %ProgramFiles%\CCleaner -> [2009/02/22 22:02:48 | 00,000,000 | —D | C]
MISC STUFF -> %UserProfile%\Desktop\MISC STUFF -> [2009/02/22 21:41:52 | 00,000,000 | —D | C]
ServicePackFiles -> %SystemRoot%\ServicePackFiles -> [2009/02/22 20:25:32 | 00,000,000 | —D | C]
$NtServicePackUninstall$ -> %SystemRoot%\$NtServicePackUninstall$ -> [2009/02/22 20:12:51 | 00,000,000 | -H-D | C]
GooredFix.exe -> %UserProfile%\Desktop\GooredFix.exe -> [2009/02/22 20:01:05 | 00,094,208 | —- | C] ()
SQL9_KB960089_ENU -> %SystemRoot%\SQL9_KB960089_ENU -> [2009/02/22 02:48:09 | 00,000,000 | —D | C]
win32k.sys -> %SystemRoot%\System32\dllcache\win32k.sys -> [2009/02/22 00:10:30 | 01,846,400 | —- | C] (Microsoft Corporation)
ntkrnlmp.exe -> %SystemRoot%\System32\dllcache\ntkrnlmp.exe -> [2009/02/22 00:10:26 | 02,145,280 | —- | C] (Microsoft Corporation)
ntoskrnl.exe -> %SystemRoot%\System32\dllcache\ntoskrnl.exe -> [2009/02/22 00:10:25 | 02,189,184 | —- | C] (Microsoft Corporation)
ntkrpamp.exe -> %SystemRoot%\System32\dllcache\ntkrpamp.exe -> [2009/02/22 00:10:24 | 02,023,936 | —- | C] (Microsoft Corporation)
ntkrnlpa.exe -> %SystemRoot%\System32\dllcache\ntkrnlpa.exe -> [2009/02/22 00:10:23 | 02,066,048 | —- | C] (Microsoft Corporation)
mrxsmb.sys -> %SystemRoot%\System32\dllcache\mrxsmb.sys -> [2009/02/22 00:10:20 | 00,455,296 | —- | C] (Microsoft Corporation)
srv.sys -> %SystemRoot%\System32\dllcache\srv.sys -> [2009/02/22 00:10:18 | 00,333,952 | —- | C] (Microsoft Corporation)
netapi32.dll -> %SystemRoot%\System32\dllcache\netapi32.dll -> [2009/02/22 00:09:45 | 00,337,408 | —- | C] (Microsoft Corporation)
wlanapi.dll -> %SystemRoot%\System32\wlanapi.dll -> [2009/02/21 22:41:30 | 00,069,120 | —- | C] (Microsoft Corporation)
wacompen.sys -> %SystemRoot%\System32\drivers\wacompen.sys -> [2009/02/21 22:41:24 | 00,014,208 | —- | C] (Microsoft Corporation)
usb8023x.sys -> %SystemRoot%\System32\drivers\usb8023x.sys -> [2009/02/21 22:41:19 | 00,012,800 | —- | C] (Microsoft Corporation)
tspkg.dll -> %SystemRoot%\System32\tspkg.dll -> [2009/02/21 22:41:15 | 00,050,688 | —- | C] (Microsoft Corporation)
uagp35.sys -> %SystemRoot%\System32\drivers\uagp35.sys -> [2009/02/21 22:41:15 | 00,044,672 | —- | C] (Microsoft Corporation)
tsgqec.dll -> %SystemRoot%\System32\tsgqec.dll -> [2009/02/21 22:41:14 | 00,053,248 | —- | C] (Microsoft Corporation)
spupdwxp.exe -> %SystemRoot%\System32\spupdwxp.exe -> [2009/02/21 22:41:03 | 00,020,992 | —- | C] (Microsoft Corporation)
smbali.sys -> %SystemRoot%\System32\drivers\smbali.sys -> [2009/02/21 22:41:00 | 00,005,888 | —- | C] (Microsoft Corporation)
setupn.exe -> %SystemRoot%\System32\setupn.exe -> [2009/02/21 22:40:55 | 00,032,768 | —- | C] (Microsoft Corporation)
sffp_mmc.sys -> %SystemRoot%\System32\drivers\sffp_mmc.sys -> [2009/02/21 22:40:55 | 00,010,240 | —- | C] (Microsoft Corporation)
rndismpx.sys -> %SystemRoot%\System32\drivers\rndismpx.sys -> [2009/02/21 22:40:51 | 00,030,592 | —- | C] (Microsoft Corporation)
rhttpaa.dll -> %SystemRoot%\System32\rhttpaa.dll -> [2009/02/21 22:40:50 | 00,290,304 | —- | C] (Microsoft Corporation)
rfcomm.sys -> %SystemRoot%\System32\drivers\rfcomm.sys -> [2009/02/21 22:40:50 | 00,059,136 | —- | C] (Microsoft Corporation)
rasqec.dll -> %SystemRoot%\System32\rasqec.dll -> [2009/02/21 22:40:49 | 00,061,952 | —- | C] (Microsoft Corporation)
qutil.dll -> %SystemRoot%\System32\qutil.dll -> [2009/02/21 22:40:47 | 00,076,800 | —- | C] (Microsoft Corporation)
qagentrt.dll -> %SystemRoot%\System32\qagentrt.dll -> [2009/02/21 22:40:46 | 00,291,328 | —- | C] (Microsoft Corporation)
qagent.dll -> %SystemRoot%\System32\qagent.dll -> [2009/02/21 22:40:46 | 00,150,528 | —- | C] (Microsoft Corporation)
qcliprov.dll -> %SystemRoot%\System32\qcliprov.dll -> [2009/02/21 22:40:46 | 00,062,464 | —- | C] (Microsoft Corporation)
onex.dll -> %SystemRoot%\System32\onex.dll -> [2009/02/21 22:40:40 | 00,144,384 | —- | C] (Microsoft Corporation)
netwlan5.img -> %SystemRoot%\System32\drivers\netwlan5.img -> [2009/02/21 22:40:30 | 00,067,866 | —- | C] ()
napmontr.dll -> %SystemRoot%\System32\napmontr.dll -> [2009/02/21 22:40:27 | 00,193,024 | —- | C] (Microsoft Corporation)
napstat.exe -> %SystemRoot%\System32\napstat.exe -> [2009/02/21 22:40:27 | 00,176,640 | —- | C] (Microsoft Corporation)
napipsec.dll -> %SystemRoot%\System32\napipsec.dll -> [2009/02/21 22:40:27 | 00,030,208 | —- | C] (Microsoft Corporation)
mutohpen.sys -> %SystemRoot%\System32\drivers\mutohpen.sys -> [2009/02/21 22:40:27 | 00,012,672 | —- | C] (Microsoft Corporation)
msxml6.dll -> %SystemRoot%\System32\dllcache\msxml6.dll -> [2009/02/21 22:40:25 | 01,307,648 | —- | C] (Microsoft Corporation)
msxml6r.dll -> %SystemRoot%\System32\dllcache\msxml6r.dll -> [2009/02/21 22:40:25 | 00,079,872 | —- | C] (Microsoft Corporation)
mssha.dll -> %SystemRoot%\System32\mssha.dll -> [2009/02/21 22:40:23 | 00,155,136 | —- | C] (Microsoft Corporation)
msshavmsg.dll -> %SystemRoot%\System32\msshavmsg.dll -> [2009/02/21 22:40:23 | 00,076,800 | —- | C] (Microsoft Corporation)
mmcex.dll -> %SystemRoot%\System32\mmcex.dll -> [2009/02/21 22:40:05 | 00,397,312 | —- | C] (Microsoft Corporation)
microsoft.managementconsole.dll -> %SystemRoot%\System32\microsoft.managementconsole.dll -> [2009/02/21 22:40:05 | 00,184,320 | —- | C] (Microsoft Corporation)
mmcfxcommon.dll -> %SystemRoot%\System32\mmcfxcommon.dll -> [2009/02/21 22:40:05 | 00,106,496 | —- | C] (Microsoft Corporation)
mmcperf.exe -> %SystemRoot%\System32\mmcperf.exe -> [2009/02/21 22:40:05 | 00,033,792 | —- | C] (Microsoft Corporation)
kmsvc.dll -> %SystemRoot%\System32\kmsvc.dll -> [2009/02/21 22:39:48 | 00,061,440 | —- | C] (Microsoft Corporation)
l2gpstore.dll -> %SystemRoot%\System32\l2gpstore.dll -> [2009/02/21 22:39:48 | 00,037,376 | —- | C] (Microsoft Corporation)
kbdpash.dll -> %SystemRoot%\System32\kbdpash.dll -> [2009/02/21 22:39:47 | 00,006,144 | —- | C] (Microsoft Corporation)
kbdnepr.dll -> %SystemRoot%\System32\kbdnepr.dll -> [2009/02/21 22:39:47 | 00,006,144 | —- | C] (Microsoft Corporation)
kbdiultn.dll -> %SystemRoot%\System32\kbdiultn.dll -> [2009/02/21 22:39:47 | 00,006,144 | —- | C] (Microsoft Corporation)
kbdbhc.dll -> %SystemRoot%\System32\kbdbhc.dll -> [2009/02/21 22:39:47 | 00,006,144 | —- | C] (Microsoft Corporation)
smtpapi.dll -> %SystemRoot%\System32\smtpapi.dll -> [2009/02/21 22:39:37 | 00,010,752 | —- | C] (Microsoft Corporation)
rwnh.dll -> %SystemRoot%\System32\rwnh.dll -> [2009/02/21 22:39:37 | 00,009,728 | —- | C] (Microsoft Corporation)
pid.inf -> %SystemRoot%\System32\pid.inf -> [2009/02/21 22:39:37 | 00,000,974 | —- | C] ()
comsdupd.exe -> %SystemRoot%\System32\comsdupd.exe -> [2009/02/21 22:39:32 | 00,009,728 | —- | C] (Microsoft Corporation)
hidbth.sys -> %SystemRoot%\System32\drivers\hidbth.sys -> [2009/02/21 22:39:30 | 00,025,600 | —- | C] (Microsoft Corporation)
gagp30kx.sys -> %SystemRoot%\System32\drivers\gagp30kx.sys -> [2009/02/21 22:39:28 | 00,046,464 | —- | C] (Microsoft Corporation)
eapp3hst.dll -> %SystemRoot%\System32\eapp3hst.dll -> [2009/02/21 22:39:25 | 00,184,832 | —- | C] (Microsoft Corporation)
eapphost.dll -> %SystemRoot%\System32\eapphost.dll -> [2009/02/21 22:39:25 | 00,180,224 | —- | C] (Microsoft Corporation)
eappcfg.dll -> %SystemRoot%\System32\eappcfg.dll -> [2009/02/21 22:39:25 | 00,126,976 | —- | C] (Microsoft Corporation)
eappgnui.dll -> %SystemRoot%\System32\eappgnui.dll -> [2009/02/21 22:39:25 | 00,094,208 | —- | C] (Microsoft Corporation)
eapqec.dll -> %SystemRoot%\System32\eapqec.dll -> [2009/02/21 22:39:25 | 00,059,392 | —- | C] (Microsoft Corporation)
eappprxy.dll -> %SystemRoot%\System32\eappprxy.dll -> [2009/02/21 22:39:25 | 00,040,960 | —- | C] (Microsoft Corporation)
eapsvc.dll -> %SystemRoot%\System32\eapsvc.dll -> [2009/02/21 22:39:25 | 00,033,792 | —- | C] (Microsoft Corporation)
eapolqec.dll -> %SystemRoot%\System32\eapolqec.dll -> [2009/02/21 22:39:25 | 00,030,720 | —- | C] (Microsoft Corporation)
faxpatch.exe -> %SystemRoot%\System32\faxpatch.exe -> [2009/02/21 22:39:25 | 00,020,992 | —- | C] (Microsoft Corporation)
dot3ui.dll -> %SystemRoot%\System32\dot3ui.dll -> [2009/02/21 22:39:22 | 00,650,752 | —- | C] (Microsoft Corporation)
dot3svc.dll -> %SystemRoot%\System32\dot3svc.dll -> [2009/02/21 22:39:22 | 00,132,096 | —- | C] (Microsoft Corporation)
dot3cfg.dll -> %SystemRoot%\System32\dot3cfg.dll -> [2009/02/21 22:39:22 | 00,057,856 | —- | C] (Microsoft Corporation)
dot3msm.dll -> %SystemRoot%\System32\dot3msm.dll -> [2009/02/21 22:39:22 | 00,056,320 | —- | C] (Microsoft Corporation)
dot3gpclnt.dll -> %SystemRoot%\System32\dot3gpclnt.dll -> [2009/02/21 22:39:22 | 00,039,936 | —- | C] (Microsoft Corporation)
dimsroam.dll -> %SystemRoot%\System32\dimsroam.dll -> [2009/02/21 22:39:22 | 00,039,936 | —- | C] (Microsoft Corporation)
dot3api.dll -> %SystemRoot%\System32\dot3api.dll -> [2009/02/21 22:39:22 | 00,026,112 | —- | C] (Microsoft Corporation)
dimsntfy.dll -> %SystemRoot%\System32\dimsntfy.dll -> [2009/02/21 22:39:22 | 00,019,456 | —- | C] (Microsoft Corporation)
dot3dlg.dll -> %SystemRoot%\System32\dot3dlg.dll -> [2009/02/21 22:39:22 | 00,009,216 | —- | C] (Microsoft Corporation)
dhcpqec.dll -> %SystemRoot%\System32\dhcpqec.dll -> [2009/02/21 22:39:20 | 00,048,640 | —- | C] (Microsoft Corporation)
cxthsfs2.cty -> %SystemRoot%\System32\drivers\cxthsfs2.cty -> [2009/02/21 22:39:19 | 00,129,045 | —- | C] ()
credssp.dll -> %SystemRoot%\System32\credssp.dll -> [2009/02/21 22:39:17 | 00,012,800 | —- | C] (Microsoft Corporation)
bthpan.sys -> %SystemRoot%\System32\drivers\bthpan.sys -> [2009/02/21 22:39:14 | 00,101,120 | —- | C] (Microsoft Corporation)
bthmodem.sys -> %SystemRoot%\System32\drivers\bthmodem.sys -> [2009/02/21 22:39:14 | 00,037,888 | —- | C] (Microsoft Corporation)
bthprint.sys -> %SystemRoot%\System32\drivers\bthprint.sys -> [2009/02/21 22:39:14 | 00,036,480 | —- | C] (Microsoft Corporation)
bthusb.sys -> %SystemRoot%\System32\drivers\bthusb.sys -> [2009/02/21 22:39:14 | 00,018,944 | —- | C] (Microsoft Corporation)
bthenum.sys -> %SystemRoot%\System32\drivers\bthenum.sys -> [2009/02/21 22:39:14 | 00,017,024 | —- | C] (Microsoft Corporation)
bitsprx4.dll -> %SystemRoot%\System32\bitsprx4.dll -> [2009/02/21 22:39:12 | 00,007,168 | —- | C] (Microsoft Corporation)
azroles.dll -> %SystemRoot%\System32\azroles.dll -> [2009/02/21 22:39:11 | 00,233,472 | —- | C] (Microsoft Corporation)
ativmc20.cod -> %SystemRoot%\System32\drivers\ativmc20.cod -> [2009/02/21 22:39:11 | 00,064,352 | —- | C] ()
aaclient.dll -> %SystemRoot%\System32\aaclient.dll -> [2009/02/21 22:39:06 | 00,136,192 | —- | C] (Microsoft Corporation)
Webcammax -> %AllUsersProfile%\Application Data\Webcammax -> [2009/02/21 22:19:42 | 00,000,000 | —D | C]
WebcamMax -> %ProgramFiles%\WebcamMax -> [2009/02/21 22:18:24 | 00,000,000 | —D | C]
ERDNT -> %SystemRoot%\ERDNT -> [2009/02/21 22:04:08 | 00,000,000 | —D | C]
ERUNT -> %ProgramFiles%\ERUNT -> [2009/02/21 22:03:42 | 00,000,000 | —D | C]
Trend Micro -> %ProgramFiles%\Trend Micro -> [2009/02/21 21:53:49 | 00,000,000 | —D | C]
Malwarebytes -> %AppData%\Malwarebytes -> [2009/02/21 21:46:52 | 00,000,000 | —D | C]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/02/21 21:46:46 | 00,015,504 | —- | C] (Malwarebytes Corporation)
mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/02/21 21:46:43 | 00,038,496 | —- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2009/02/21 21:46:42 | 00,000,000 | —D | C]
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2009/02/21 21:46:42 | 00,000,000 | —D | C]
autorun.inf -> %SystemDrive%\autorun.inf -> [2009/02/21 15:11:20 | 00,000,000 | RHSD | C]
Eric Suh.wmv -> %UserProfile%\Desktop\Eric Suh.wmv -> [2009/02/21 12:38:03 | 04,670,095 | —- | C] ()
Google -> %AllUsersProfile%\Application Data\Google -> [2009/02/21 11:59:01 | 00,000,000 | —D | C]
ie7 -> %SystemRoot%\ie7 -> [2009/02/21 11:57:09 | 00,000,000 | -H-D | C]
IE7Setup_G.exe -> %UserProfile%\My Documents\IE7Setup_G.exe -> [2009/02/21 11:52:54 | 17,464,248 | —- | C] (Microsoft Corporation)
usbvideo.sys -> %SystemRoot%\System32\drivers\usbvideo.sys -> [2009/02/20 23:02:48 | 00,121,984 | —- | C] (Microsoft Corporation)
autorun.PNF -> %SystemDrive%\autorun.PNF -> [2009/02/20 14:11:11 | 00,002,524 | —- | C] ()
Harry Park (feat. Eric Lee) - One Shot .mp3 -> %UserProfile%\Desktop\Harry Park (feat. Eric Lee) - One Shot .mp3 -> [2009/02/17 21:17:44 | 02,274,114 | —- | C] ()
david guitar.mpg -> %UserProfile%\Desktop\david guitar.mpg -> [2009/02/15 02:43:52 | 12,030,3620 | —- | C] ()
feb 13 2009 -> %UserProfile%\My Documents\feb 13 2009 -> [2009/02/13 22:43:12 | 00,000,000 | —D | C]
Entourage - Season 1 -> %UserProfile%\Desktop\Entourage - Season 1 -> [2009/02/12 23:21:17 | 00,000,000 | —D | C]
Alwil Software -> %ProgramFiles%\Alwil Software -> [2009/02/12 22:40:45 | 00,000,000 | —D | C]
acidrainessay.doc -> %UserProfile%\My Documents\acidrainessay.doc -> [2009/02/12 22:03:23 | 00,026,624 | —- | C] ()
ooVoo.lnk -> %AllUsersProfile%\Desktop\ooVoo.lnk -> [2009/02/12 19:35:13 | 00,000,638 | —- | C] ()
ooVoo -> %ProgramFiles%\ooVoo -> [2009/02/12 19:35:13 | 00,000,000 | —D | C]
gaopdxcounter -> %SystemRoot%\System32\gaopdxcounter -> [2009/02/09 23:18:40 | 00,000,004 | —- | C] ()
PACE Anti-Piracy -> %UserProfile%\Local Settings\Application Data\PACE Anti-Piracy -> [2009/02/09 20:38:52 | 00,000,000 | —D | C]
PACE Anti-Piracy -> %CommonProgramFiles%\PACE Anti-Piracy -> [2009/02/09 20:38:52 | 00,000,000 | —D | C]
PACE Anti-Piracy -> %AppData%\PACE Anti-Piracy -> [2009/02/09 20:38:52 | 00,000,000 | —D | C]
PACE Anti-Piracy -> %AllUsersProfile%\Application Data\PACE Anti-Piracy -> [2009/02/09 20:38:52 | 00,000,000 | —D | C]
mfc71.dll -> %SystemRoot%\System32\mfc71.dll -> [2009/02/09 18:19:05 | 01,060,864 | —- | C] (Microsoft Corporation)
qtmlClient.dll -> %SystemRoot%\System32\qtmlClient.dll -> [2009/02/09 18:19:05 | 00,217,088 | —- | C] ()
ilinet.dll -> %SystemRoot%\System32\ilinet.dll -> [2009/02/09 18:19:03 | 00,630,784 | —- | C] (PACE Anti-Piracy)
REX Shared Library.dll -> %SystemRoot%\System32\REX Shared Library.dll -> [2009/02/09 18:19:03 | 00,233,472 | —- | C] (Propellerhead Software AB)
Digidesign -> %ProgramFiles%\Digidesign -> [2009/02/09 18:18:22 | 00,000,000 | —D | C]
InstallShield -> %AppData%\InstallShield -> [2009/02/09 18:17:32 | 00,000,000 | —D | C]
Forever Acoustic Chris Brown Kollaboration 9- David Choi, Kina Grannis, Jane Lui, Jazmin -2_21_09 (HQ).avi -> %UserProfile%\Desktop\Forever Acoustic Chris Brown Kollaboration 9- David Choi, Kina Grannis, Jane Lui, Jazmin -2_21_09 (HQ).avi -> [2009/02/08 20:06:03 | 23,670,704 | —- | C] ()
January 31 2009 -> %UserProfile%\Desktop\January 31 2009 -> [2009/01/31 15:49:57 | 00,000,000 | —D | C]
Collision -> %ProgramFiles%\Collision -> [2009/01/29 12:42:01 | 00,000,000 | —D | C]
Track 4 Recording 1.wav -> %UserProfile%\My Documents\Track 4 Recording 1.wav -> [2009/01/25 21:30:49 | 08,882,406 | —- | C] ()
Track 3 Recording 1.wav -> %UserProfile%\My Documents\Track 3 Recording 1.wav -> [2009/01/25 21:29:21 | 14,285,642 | —- | C] ()
Track 2 Recording 1.sfk -> %UserProfile%\My Documents\Track 2 Recording 1.sfk -> [2009/01/25 21:28:51 | 00,030,864 | —- | C] ()
Track 2 Recording 1.wav -> %UserProfile%\My Documents\Track 2 Recording 1.wav -> [2009/01/25 21:27:51 | 03,942,574 | —- | C] ()
Track 1 Recording 1.sfk -> %UserProfile%\My Documents\Track 1 Recording 1.sfk -> [2009/01/25 21:25:33 | 00,029,096 | —- | C] ()
Track 1 Recording 1.wav -> %UserProfile%\My Documents\Track 1 Recording 1.wav -> [2009/01/25 21:24:52 | 03,715,962 | —- | C] ()
PhilGood-Lady.avi.MP3 -> %UserProfile%\Desktop\PhilGood-Lady.avi.MP3 -> [2009/01/25 01:34:00 | 04,431,247 | —- | C] ()
 
[Files/Folders - Modified Within 30 Days]
31 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
1 C:\Documents and Settings\Phillip\My Documents\*.tmp files -> C:\Documents and Settings\Phillip\My Documents\*.tmp -> 
35 C:\Documents and Settings\Phillip\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Phillip\Local Settings\Temp\*.tmp -> 
35 C:\Documents and Settings\Phillip\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Phillip\Local Settings\Temp\*.tmp -> 
175 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> 
175 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> 
175 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> 
aaw7boot.cmd -> %SystemDrive%\aaw7boot.cmd -> [2009/02/23 16:59:20 | 00,000,098 | -H– | M] ()
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/02/23 16:51:17 | 00,661,370 | —- | M] ()
MP Scheduled Scan.job -> %SystemRoot%\tasks\MP Scheduled Scan.job -> [2009/02/23 16:47:27 | 00,000,330 | -H– | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009/02/23 16:45:43 | 00,002,206 | —- | M] ()
Perflib_Perfdata_384.dat -> %SystemRoot%\Temp\Perflib_Perfdata_384.dat -> [2009/02/23 16:44:35 | 00,000,000 | —- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/02/23 16:44:18 | 00,000,006 | -H– | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/02/23 16:44:14 | 00,002,048 | –S- | M] ()
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/02/23 16:44:07 | 10,718,12608 | -HS- | M] ()
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2009/02/23 16:44:07 | 00,312,376 | —- | M] ()
NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009/02/23 00:03:03 | 13,631,488 | —- | M] ()
ntuser.ini -> %UserProfile%\ntuser.ini -> [2009/02/23 00:02:33 | 00,000,278 | -HS- | M] ()
Microsoft LifeCam.lnk -> %AllUsersProfile%\Desktop\Microsoft LifeCam.lnk -> [2009/02/22 23:09:20 | 00,001,788 | —- | M] ()
GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2009/02/22 22:43:18 | 00,083,208 | —- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/02/22 22:33:59 | 00,156,672 | —- | M] ()
Thumbs.db -> %UserProfile%\My Documents\Thumbs.db -> [2009/02/22 22:27:26 | 00,249,856 | -HS- | M] ()
perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [2009/02/22 22:21:06 | 00,492,386 | —- | M] ()
perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [2009/02/22 22:21:06 | 00,090,574 | —- | M] ()
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2009/02/22 22:21:03 | 00,594,512 | —- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2009/02/22 22:07:56 | 00,001,374 | —- | M] ()
cc_20090222_220447.reg -> %UserProfile%\Desktop\cc_20090222_220447.reg -> [2009/02/22 22:05:04 | 01,932,472 | —- | M] ()
qmgr1.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/02/22 21:23:54 | 00,004,232 | —- | M] ()
qmgr0.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/02/22 21:23:53 | 00,004,646 | —- | M] ()
GoogleUpdateTaskUserS-1-5-21-1518184048-3988524191-3343478579-1005.job -> %SystemRoot%\tasks\GoogleUpdateTaskUserS-1-5-21-1518184048-3988524191-3343478579-1005.job -> [2009/02/22 20:47:57 | 00,000,934 | —- | M] ()
ntldr -> %SystemDrive%\ntldr -> [2009/02/22 20:21:35 | 00,250,048 | RHS- | M] ()
GooredFix.exe -> %UserProfile%\Desktop\GooredFix.exe -> [2009/02/22 20:01:28 | 00,094,208 | —- | M] ()
sqmdata16.sqm -> %SystemDrive%\sqmdata16.sqm -> [2009/02/22 18:25:39 | 00,000,268 | -H– | M] ()
sqmnoopt17.sqm -> %SystemDrive%\sqmnoopt17.sqm -> [2009/02/22 18:25:39 | 00,000,244 | -H– | M] ()
1C.exe -> %UserProfile%\Local Settings\Temp\1C.exe -> [2009/02/21 22:18:12 | 09,000,720 | —- | M] ()
ooVoo.lnk -> %AllUsersProfile%\Desktop\ooVoo.lnk -> [2009/02/21 22:15:14 | 00,000,638 | —- | M] ()
gaopdxcounter -> %SystemRoot%\System32\gaopdxcounter -> [2009/02/21 15:38:16 | 00,000,004 | —- | M] ()
Perflib_Perfdata_274.dat -> %SystemRoot%\Temp\Perflib_Perfdata_274.dat -> [2009/02/21 15:35:36 | 00,016,384 | —- | M] ()
hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [2009/02/21 15:35:25 | 00,000,736 | —- | M] ()
ehshell.exe -> %SystemRoot%\Temp\ZAP29.tmp\ehshell.exe -> [2009/02/21 12:06:03 | 06,336,512 | —- | M] ()
nscompat.tlb -> %SystemRoot%\System32\nscompat.tlb -> [2009/02/21 12:03:17 | 00,023,392 | —- | M] ()
amcompat.tlb -> %SystemRoot%\System32\amcompat.tlb -> [2009/02/21 12:03:17 | 00,016,832 | —- | M] ()
desktop.ini -> %UserProfile%\My Documents\desktop.ini -> [2009/02/21 12:03:06 | 00,000,078 | -HS- | M] ()
Perflib_Perfdata_790.dat -> %SystemRoot%\Temp\Perflib_Perfdata_790.dat -> [2009/02/21 12:03:04 | 00,016,384 | —- | M] ()
IE7Setup_G.exe -> %UserProfile%\My Documents\IE7Setup_G.exe -> [2009/02/21 11:53:16 | 17,464,248 | —- | M] (Microsoft Corporation)
ErrorSmart Scheduled Scan.job -> %SystemRoot%\tasks\ErrorSmart Scheduled Scan.job -> [2009/02/21 03:30:00 | 00,000,406 | —- | M] ()
autorun.PNF -> %SystemDrive%\autorun.PNF -> [2009/02/20 14:11:11 | 00,002,524 | —- | M] ()
Perflib_Perfdata_7b4.dat -> %SystemRoot%\Temp\Perflib_Perfdata_7b4.dat -> [2009/02/20 14:00:30 | 00,016,384 | —- | M] ()
CONFIG.NT -> %SystemRoot%\System32\CONFIG.NT -> [2009/02/20 13:08:28 | 00,002,577 | —- | M] ()
Eric Suh.wmv -> %UserProfile%\Desktop\Eric Suh.wmv -> [2009/02/19 23:37:36 | 04,670,095 | —- | M] ()
Ad-Aware Update (Weekly).job -> %SystemRoot%\tasks\Ad-Aware Update (Weekly).job -> [2009/02/18 21:22:04 | 00,000,472 | —- | M] ()
Perflib_Perfdata_c08.dat -> %UserProfile%\Local Settings\Temp\Perflib_Perfdata_c08.dat -> [2009/02/18 00:39:28 | 00,016,384 | —- | M] ()
Perflib_Perfdata_20c.dat -> %SystemRoot%\Temp\Perflib_Perfdata_20c.dat -> [2009/02/17 21:05:03 | 00,016,384 | —- | M] ()
sqmdata15.sqm -> %SystemDrive%\sqmdata15.sqm -> [2009/02/17 19:07:27 | 00,000,268 | -H– | M] ()
sqmnoopt16.sqm -> %SystemDrive%\sqmnoopt16.sqm -> [2009/02/17 19:07:27 | 00,000,244 | -H– | M] ()
Harry Park (feat. Eric Lee) - One Shot .mp3 -> %UserProfile%\Desktop\Harry Park (feat. Eric Lee) - One Shot .mp3 -> [2009/02/16 18:48:51 | 02,274,114 | —- | M] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2009/02/15 09:09:39 | 02,640,720 | -H– | M] ()
david guitar.mpg -> %UserProfile%\Desktop\david guitar.mpg -> [2009/02/15 02:52:49 | 12,030,3620 | —- | M] ()
Perflib_Perfdata_8d8.dat -> %SystemRoot%\Temp\Perflib_Perfdata_8d8.dat -> [2009/02/14 11:57:41 | 00,016,384 | —- | M] ()
Perflib_Perfdata_6d0.dat -> %SystemRoot%\Temp\Perflib_Perfdata_6d0.dat -> [2009/02/14 11:57:16 | 00,016,384 | —- | M] ()
Microsoft Office Word 2003 (3).lnk -> %UserProfile%\Desktop\Microsoft Office Word 2003 (3).lnk -> [2009/02/12 22:03:58 | 00,002,497 | —- | M] ()
acidrainessay.doc -> %UserProfile%\My Documents\acidrainessay.doc -> [2009/02/12 22:03:24 | 00,026,624 | —- | M] ()
MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2009/02/11 23:56:17 | 21,244,872 | —- | M] (Microsoft Corporation)
sqmdata14.sqm -> %SystemDrive%\sqmdata14.sqm -> [2009/02/11 12:57:08 | 00,000,268 | -H– | M] ()
sqmnoopt15.sqm -> %SystemDrive%\sqmnoopt15.sqm -> [2009/02/11 12:57:08 | 00,000,244 | -H– | M] ()
mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation)
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation)
Perflib_Perfdata_224.dat -> %SystemRoot%\Temp\Perflib_Perfdata_224.dat -> [2009/02/09 20:37:43 | 00,016,384 | —- | M] ()
Forever Acoustic Chris Brown Kollaboration 9- David Choi, Kina Grannis, Jane Lui, Jazmin -2_21_09 (HQ).avi -> %UserProfile%\Desktop\Forever Acoustic Chris Brown Kollaboration 9- David Choi, Kina Grannis, Jane Lui, Jazmin -2_21_09 (HQ).avi -> [2009/02/08 20:06:05 | 23,670,704 | —- | M] ()
Google Chrome.lnk -> %UserProfile%\Desktop\Google Chrome.lnk -> [2009/02/07 09:13:13 | 00,002,260 | —- | M] ()
sqmdata17.sqm -> %SystemDrive%\sqmdata17.sqm -> [2009/02/04 09:17:58 | 00,000,268 | -H– | M] ()
sqmnoopt18.sqm -> %SystemDrive%\sqmnoopt18.sqm -> [2009/02/04 09:17:58 | 00,000,244 | -H– | M] ()
mcs.rma -> %SystemRoot%\System32\mcs.rma -> [2009/02/04 09:13:27 | 00,870,128 | —- | M] ()
11AFDF -> %SystemRoot%\System32\11AFDF -> [2009/02/04 09:13:27 | 00,000,004 | —- | M] ()
sqmdata13.sqm -> %SystemDrive%\sqmdata13.sqm -> [2009/02/03 07:09:58 | 00,000,268 | -H– | M] ()
sqmnoopt14.sqm -> %SystemDrive%\sqmnoopt14.sqm -> [2009/02/03 07:09:58 | 00,000,244 | -H– | M] ()
sqmdata12.sqm -> %SystemDrive%\sqmdata12.sqm -> [2009/02/02 22:16:43 | 00,000,268 | -H– | M] ()
sqmnoopt13.sqm -> %SystemDrive%\sqmnoopt13.sqm -> [2009/02/02 22:16:43 | 00,000,244 | -H– | M] ()
lsdelete.exe -> %SystemRoot%\System32\lsdelete.exe -> [2009/02/02 21:22:42 | 00,015,688 | —- | M] ()
d3d9caps.dat -> %SystemRoot%\System32\d3d9caps.dat -> [2009/02/01 20:26:47 | 00,001,324 | —- | M] ()
sqmdata11.sqm -> %SystemDrive%\sqmdata11.sqm -> [2009/02/01 18:04:25 | 00,000,268 | -H– | M] ()
sqmnoopt12.sqm -> %SystemDrive%\sqmnoopt12.sqm -> [2009/02/01 18:04:25 | 00,000,244 | -H– | M] ()
Track 2 Recording 1.sfk -> %UserProfile%\My Documents\Track 2 Recording 1.sfk -> [2009/01/25 21:31:55 | 00,030,864 | —- | M] ()
Track 1 Recording 1.sfk -> %UserProfile%\My Documents\Track 1 Recording 1.sfk -> [2009/01/25 21:31:55 | 00,029,096 | —- | M] ()
Track 4 Recording 1.wav -> %UserProfile%\My Documents\Track 4 Recording 1.wav -> [2009/01/25 21:31:44 | 08,882,406 | —- | M] ()
Track 3 Recording 1.wav -> %UserProfile%\My Documents\Track 3 Recording 1.wav -> [2009/01/25 21:30:45 | 14,285,642 | —- | M] ()
Track 2 Recording 1.wav -> %UserProfile%\My Documents\Track 2 Recording 1.wav -> [2009/01/25 21:28:51 | 03,942,574 | —- | M] ()
Track 1 Recording 1.wav -> %UserProfile%\My Documents\Track 1 Recording 1.wav -> [2009/01/25 21:25:33 | 03,715,962 | —- | M] ()
PhilGood-Lady.avi.MP3 -> %UserProfile%\Desktop\PhilGood-Lady.avi.MP3 -> [2009/01/25 01:47:29 | 04,431,247 | —- | M] ()
Perflib_Perfdata_764.dat -> %SystemRoot%\Temp\Perflib_Perfdata_764.dat -> [2008/12/25 12:33:33 | 00,016,384 | —- | M] ()
VCExpress000223.dat -> %AllUsersProfile%\Application Data\Microsoft\VCExpress\9.0\VCExpress000223.dat -> [2008/10/16 20:59:46 | 00,677,178 | -H– | M] ()
VCSExpress000223.dat -> %AllUsersProfile%\Application Data\Microsoft\VCSExpress\9.0\VCSExpress000223.dat -> [2008/10/16 20:02:59 | 00,677,178 | -H– | M] ()
index.dat -> %SystemRoot%\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008/09/11 19:57:08 | 00,049,152 | —- | M] ()
index.dat -> %SystemRoot%\Temp\History\History.IE5\index.dat -> [2008/09/11 19:57:08 | 00,032,768 | —- | M] ()
index.dat -> %SystemRoot%\Temp\Cookies\index.dat -> [2008/09/11 19:57:08 | 00,032,768 | —- | M] ()
index.dat -> %UserProfile%\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008/06/21 17:33:17 | 00,016,384 | -HS- | M] ()
index.dat -> %UserProfile%\Local Settings\Temp\History\History.IE5\index.dat -> [2008/06/21 17:33:17 | 00,016,384 | -HS- | M] ()
index.dat -> %UserProfile%\Local Settings\Temp\Cookies\index.dat -> [2008/06/21 17:33:17 | 00,016,384 | -HS- | M] ()
opa11.dat -> %AllUsersProfile%\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [2008/03/30 19:53:27 | 00,011,092 | —- | M] ()
IEViewBar.dll -> %SystemRoot%\Temp\0\Private\Runtime\ProgFiles\IEViewBar.dll -> [2007/11/28 18:58:26 | 00,327,759 | —- | M] (Viewpoint Corporation)
ViewBar.dll -> %SystemRoot%\Temp\0\Private\Runtime\ProgFiles\ViewBar.dll -> [2007/11/28 18:58:19 | 01,298,509 | —- | M] (Viewpoint Corporation)
ViewBarSystemInfo.dll -> %SystemRoot%\Temp\0\Private\Vendor\ProgFiles\ViewBarSystemInfo.dll -> [2007/11/28 18:55:13 | 00,032,855 | —- | M] (Viewpoint Corporation)
PhotoSharing.dll -> %SystemRoot%\Temp\0\Private\Runtime\AllUsersData\SkinEngine\features\photoview\PhotoSharing.dll -> [2007/11/28 18:55:08 | 00,966,738 | —- | M] (Viewpoint Corporation)
FotomatShellExt.dll -> %SystemRoot%\Temp\0\Private\Runtime\ProgFiles\FotomatShellExt.dll -> [2007/11/28 18:52:37 | 00,077,954 | —- | M] (Viewpoint Corporation)
FileModifiedDate.dll -> %SystemRoot%\Temp\0\Private\Runtime\AllUsersData\SkinEngine\features\photoview\FileModifiedDate.dll -> [2007/11/28 18:52:28 | 00,082,006 | —- | M] (Viewpoint Corporation)
ViewBarBHO.dll -> %SystemRoot%\Temp\0\Private\Vendor\ProgFiles\ViewBarBHO.dll -> [2007/11/28 18:51:55 | 00,032,867 | —- | M] (Viewpoint Corporation)
Uninstaller.exe -> %SystemRoot%\Temp\0\Private\Vendor\ProgFiles\Uninstaller.exe -> [2007/11/28 18:51:53 | 00,184,406 | —- | M] (Viewpoint Corporation)
Installer.exe -> %SystemRoot%\Temp\0\Installer.exe -> [2007/11/28 18:51:53 | 00,184,406 | —- | M] (Viewpoint Corporation)
FotomatDeviceConnect.exe -> %SystemRoot%\Temp\0\Private\Runtime\ProgFiles\FotomatDeviceConnect.exe -> [2007/11/28 18:51:13 | 00,139,354 | —- | M] (Viewpoint Corporation)
PcEQnElc1jOAP.dat -> %AllUsersProfile%\Application Data\Microsoft\Gnk9KENiFapO\PcEQnElc1jOAP.dat -> [2007/10/18 03:24:52 | 00,001,134 | -H– | M] ()
Perflib_Perfdata_16dc.dat -> %SystemRoot%\Temp\Perflib_Perfdata_16dc.dat -> [2007/07/30 23:15:28 | 00,016,384 | —- | M] ()
Perflib_Perfdata_138.dat -> %SystemRoot%\Temp\Perflib_Perfdata_138.dat -> [2007/06/29 03:02:30 | 00,016,384 | —- | M] ()
Perflib_Perfdata_124.dat -> %SystemRoot%\Temp\Perflib_Perfdata_124.dat -> [2007/04/13 03:02:52 | 00,016,384 | —- | M] ()
Perflib_Perfdata_67c.dat -> %SystemRoot%\Temp\Perflib_Perfdata_67c.dat -> [2007/03/09 12:59:08 | 00,016,384 | —- | M] ()
Perflib_Perfdata_474.dat -> %SystemRoot%\Temp\Perflib_Perfdata_474.dat -> [2007/03/09 12:28:46 | 00,016,384 | —- | M] ()
0313591172795573mcinst.exe -> %SystemRoot%\Temp\0313591172795573mcinst.exe -> [2007/01/09 11:04:20 | 00,291,944 | —- | M] (McAfee, Inc.)
0252391181664074mcinst.exe -> %SystemRoot%\Temp\0252391181664074mcinst.exe -> [2007/01/09 10:04:20 | 00,291,944 | —- | M] (McAfee, Inc.)
0001331176267934mcinst.exe -> %SystemRoot%\Temp\0001331176267934mcinst.exe -> [2007/01/09 10:04:20 | 00,291,944 | —- | M] (McAfee, Inc.)
Perflib_Perfdata_590.dat -> %SystemRoot%\Temp\Perflib_Perfdata_590.dat -> [2006/12/16 23:31:28 | 00,016,384 | —- | M] ()
Perflib_Perfdata_360.dat -> %SystemRoot%\Temp\Perflib_Perfdata_360.dat -> [2006/11/23 01:06:16 | 00,016,384 | —- | M] ()
PersonalizationWrapper.dll -> %SystemRoot%\Temp\0\Private\Vendor\AllUsersData\ThemesV3\Windows\features\Amazon\core\PersonalizationWrapper.dll -> [2006/11/14 17:01:38 | 00,118,784 | —- | M] ()
wiaaut.dll -> %SystemRoot%\Temp\0\Private\Runtime\AllUsersData\SkinEngine\features\photoview\wiaaut.dll -> [2006/11/07 15:15:40 | 00,323,624 | —- | M] (Microsoft Corporation)
PersonalizationWrapper.dll -> %SystemRoot%\Temp\0\Private\Vendor\AllUsersData\ThemesV3\Default\features\Amazon\core\PersonalizationWrapper.dll -> [2006/11/07 15:11:45 | 00,118,784 | —- | M] ()
shredder.exe -> %SystemRoot%\Temp\mcu8CA.tmp\mps\en-us\us\shredder.exe -> [2006/07/30 03:52:03 | 01,107,525 | —- | M] ()
shredder.exe -> %SystemRoot%\Temp\mcu2E.tmp\mps\en-us\us\shredder.exe -> [2006/07/28 06:10:20 | 01,107,525 | —- | M] ()
VETScriptInterpreter.dll -> %SystemRoot%\Temp\0\Private\Runtime\ProgFiles\VETScriptInterpreter.dll -> [2006/06/01 12:42:30 | 00,726,704 | —- | M] (Viewpoint Corporation)
SWFView.dll -> %SystemRoot%\Temp\0\Private\Runtime\ProgFiles\SWFView.dll -> [2006/06/01 12:42:20 | 00,718,496 | —- | M] (Viewpoint Corporation)
MpEngine.dll -> %SystemRoot%\Temp\MpEngine.dll -> [2006/03/20 18:45:24 | 02,625,296 | —- | M] (Microsoft Corporation)
McAppIns.exe -> %SystemRoot%\Temp\mcuF.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcuB.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu9A.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu98.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu8CA.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu867.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu782.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu66B.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu510.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu4C.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu48E.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu43.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu42.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu408.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu3E2.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu3A8.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu39.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu37.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu333.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu33.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu2F.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu2E.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu2D.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu291.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu27.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu22.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu21D.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu1E.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu1B.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu18.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
McAppIns.exe -> %SystemRoot%\Temp\mcu10.tmp\McAppIns.exe -> [2006/01/23 17:55:06 | 00,131,072 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcuF.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcuB.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu9A.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu98.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu8CA.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu867.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu782.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu66B.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu510.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu4C.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu48E.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu43.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu42.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu408.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu3E2.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu3A8.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu39.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu37.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu333.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu33.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu2F.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu2E.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu2D.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu291.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu27.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu22.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu21D.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu1E.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu1B.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu18.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\mcu10.tmp\mcinsres.dll -> [2006/01/23 17:54:54 | 00,033,280 | —- | M] (McAfee, Inc)
MCINSCTL.DLL -> %SystemRoot%\Temp\SHR_6_0_ENUS.tmp\shared\MCINSCTL.DLL -> [2005/07/17 23:33:00 | 00,349,760 | —- | M] (McAfee, Inc)
setup.exe -> %SystemRoot%\Temp\SHR_6_0_ENUS.tmp\setup.exe -> [2005/07/11 12:55:00 | 00,131,072 | —- | M] (McAfee)
mcappins.exe -> %SystemRoot%\Temp\SHR_6_0_ENUS.tmp\mcappins.exe -> [2005/06/25 01:57:00 | 00,131,072 | —- | M] (McAfee, Inc)
mcinsres.dll -> %SystemRoot%\Temp\SHR_6_0_ENUS.tmp\mcinsres.dll -> [2005/06/25 01:57:00 | 00,033,280 | —- | M] (McAfee, Inc)
Eula.exe -> %SystemRoot%\Temp\SHR_6_0_ENUS.tmp\Eula.exe -> [2005/06/21 04:47:00 | 00,114,688 | —- | M] (McAfee)
EulaRes.dll -> %SystemRoot%\Temp\SHR_6_0_ENUS.tmp\EulaRes.dll -> [2005/06/21 04:45:00 | 00,860,160 | —- | M] (McAfee)
SetupRes.dll -> %SystemRoot%\Temp\SHR_6_0_ENUS.tmp\SetupRes.dll -> [2005/06/16 11:31:00 | 00,061,440 | —- | M] (McAfee)
mcuninst.dll -> %SystemRoot%\Temp\mcu8CA.tmp\mcuninst.dll -> [2005/04/21 20:02:40 | 00,114,688 | —- | M] (McAfee com)
mcuninst.dll -> %SystemRoot%\Temp\mcu2E.tmp\mcuninst.dll -> [2005/04/21 20:02:40 | 00,114,688 | —- | M] (McAfee com)
 
[Files/Folders - Unicode - All]
??? ?? ??.txt -> C:\Documents and Settings\Phillip\My Documents\꽃피는 봄이 오면.txt -> [2008/04/07 18:59:46 | 00,001,488 | —- | M] ()
????.txt -> C:\Documents and Settings\Phillip\My Documents\버릇처럼.txt -> [2008/06/16 19:33:07 | 00,001,864 | —- | M] ()
??? ???.txt -> C:\Documents and Settings\Phillip\My Documents\사랑은 맛있다.txt -> [2007/09/15 19:25:35 | 00,001,866 | —- | M] ()
???????.txt -> C:\Documents and Settings\Phillip\My Documents\사랑해도됄까요.txt -> [2008/04/09 20:08:19 | 00,000,934 | —- | M] ()
??? ???.txt -> C:\Documents and Settings\Phillip\My Documents\사진을 보다가.txt -> [2008/04/07 18:12:43 | 00,001,722 | —- | M] ()
???.txt -> C:\Documents and Settings\Phillip\My Documents\여우비.txt -> [2007/12/09 20:00:03 | 00,000,756 | —- | M] ()
??.txt -> C:\Documents and Settings\Phillip\My Documents\파도.txt -> [2007/07/04 21:45:02 | 00,001,360 | —- | M] ()
 
[Alternate Data Streams]
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\ehthumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\redanride.flv:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\redonce.flv:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 106 bytes -> %AllUsersProfile%\Application Data\TEMP:9FA5EC55
@Alternate Data Stream - 110 bytes -> %AllUsersProfile%\Application Data\TEMP:888AFB86
@Alternate Data Stream - 1103 bytes -> %AllUsersProfile%\Application Data\Microsoft:5HJMFDvIwDjq4wgk1BFi
@Alternate Data Stream - 1139 bytes -> %ProgramFiles%\Outlook Express:onoA3UOB0v8nCabdpxG
@Alternate Data Stream - 1168 bytes -> %AllUsersProfile%\Application Data\Microsoft:aMSwzs4cvX8WQ72WcP
@Alternate Data Stream - 1251 bytes -> %AllUsersProfile%\Application Data\Microsoft\KU0SKdt0:IC5dMns7nWk7gdrWjVinboii6B
 
[File - Lop Check]
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2009/02/21 22:19:42 | 00,000,000 | RH-D | M]
{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/09/21 18:44:07 | 00,000,000 | —D | M]
{83C91755-2546-441D-AC40-9A6B4B860800} -> C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800} -> [2009/01/21 21:21:52 | 00,000,000 | -H-D | M]
acccore -> C:\Documents and Settings\All Users\Application Data\acccore -> [2008/06/19 10:16:35 | 00,000,000 | —D | M]
America's Army Deploy Client -> C:\Documents and Settings\All Users\Application Data\America's Army Deploy Client -> [2008/11/06 20:41:12 | 00,000,000 | —D | M]
IJJIGame -> C:\Documents and Settings\All Users\Application Data\IJJIGame -> [2007/10/07 21:10:05 | 00,000,000 | —D | M]
Logishrd -> C:\Documents and Settings\All Users\Application Data\Logishrd -> [2009/01/10 23:00:40 | 00,000,000 | —D | M]
Otto -> C:\Documents and Settings\All Users\Application Data\Otto -> [2006/08/04 21:10:48 | 00,000,000 | —D | M]
PACE Anti-Piracy -> C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy -> [2009/02/09 20:38:58 | 00,000,000 | —D | M]
SecTaskMan -> C:\Documents and Settings\All Users\Application Data\SecTaskMan -> [2006/08/27 20:59:08 | 00,000,000 | —D | M]
Sony -> C:\Documents and Settings\All Users\Application Data\Sony -> [2008/12/04 21:53:02 | 00,000,000 | —D | M]
TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [2009/02/15 09:09:57 | 00,000,000 | —D | M]
TrackMania -> C:\Documents and Settings\All Users\Application Data\TrackMania -> [2008/05/19 20:30:41 | 00,000,000 | —D | M]
Ulead Systems -> C:\Documents and Settings\All Users\Application Data\Ulead Systems -> [2008/04/29 19:47:24 | 00,000,000 | —D | M]
Viewpoint -> C:\Documents and Settings\All Users\Application Data\Viewpoint -> [2008/09/11 18:49:46 | 00,000,000 | —D | M]
Webcammax -> C:\Documents and Settings\All Users\Application Data\Webcammax -> [2009/02/21 22:19:42 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Phillip\Application Data -> [2009/02/21 21:46:52 | 00,000,000 | RH-D | M]
acccore -> C:\Documents and Settings\Phillip\Application Data\acccore -> [2007/01/03 16:29:24 | 00,000,000 | —D | M]
Ahead -> C:\Documents and Settings\Phillip\Application Data\Ahead -> [2006/07/28 17:04:42 | 00,000,000 | —D | M]
Aim -> C:\Documents and Settings\Phillip\Application Data\Aim -> [2006/07/26 15:37:42 | 00,000,000 | —D | M]
ATI -> C:\Documents and Settings\Phillip\Application Data\ATI -> [2006/08/20 20:18:51 | 00,000,000 | —D | M]
Backup MyPC -> C:\Documents and Settings\Phillip\Application Data\Backup MyPC -> [2007/07/31 17:22:44 | 00,000,000 | —D | M]
Corel -> C:\Documents and Settings\Phillip\Application Data\Corel -> [2007/06/05 18:46:12 | 00,000,000 | —D | M]
Corel Photo Album -> C:\Documents and Settings\Phillip\Application Data\Corel Photo Album -> [2006/08/15 22:43:57 | 00,000,000 | —D | M]
Elaborate Bytes -> C:\Documents and Settings\Phillip\Application Data\Elaborate Bytes -> [2006/08/17 02:06:08 | 00,000,000 | —D | M]
ErrorSmart -> C:\Documents and Settings\Phillip\Application Data\ErrorSmart -> [2008/04/29 19:38:03 | 00,000,000 | —D | M]
GetRightToGo -> C:\Documents and Settings\Phillip\Application Data\GetRightToGo -> [2006/12/16 16:23:25 | 00,000,000 | —D | M]
Hamachi -> C:\Documents and Settings\Phillip\Application Data\Hamachi -> [2008/10/16 21:37:38 | 00,000,000 | —D | M]
ijjigame -> C:\Documents and Settings\Phillip\Application Data\ijjigame -> [2008/11/25 21:27:21 | 00,000,000 | -H-D | M]
Juce VST Host -> C:\Documents and Settings\Phillip\Application Data\Juce VST Host -> [2008/04/13 20:20:25 | 00,000,000 | —D | M]
Leadertech -> C:\Documents and Settings\Phillip\Application Data\Leadertech -> [2006/07/27 23:20:02 | 00,000,000 | —D | M]
mIRC -> C:\Documents and Settings\Phillip\Application Data\mIRC -> [2007/09/10 20:18:57 | 00,000,000 | —D | M]
netmarble -> C:\Documents and Settings\Phillip\Application Data\netmarble -> [2008/09/13 13:06:18 | 00,000,000 | -H-D | M]
Nexon -> C:\Documents and Settings\Phillip\Application Data\Nexon -> [2008/02/19 00:20:03 | 00,000,000 | —D | M]
ooVoo Details -> C:\Documents and Settings\Phillip\Application Data\ooVoo Details -> [2008/05/14 17:09:19 | 00,000,000 | —D | M]
Opera -> C:\Documents and Settings\Phillip\Application Data\Opera -> [2006/09/11 14:01:40 | 00,000,000 | —D | M]
Otto -> C:\Documents and Settings\Phillip\Application Data\Otto -> [2006/08/04 21:10:48 | 00,000,000 | —D | M]
PACE Anti-Piracy -> C:\Documents and Settings\Phillip\Application Data\PACE Anti-Piracy -> [2009/02/09 20:38:58 | 00,000,000 | —D | M]
Publish Providers -> C:\Documents and Settings\Phillip\Application Data\Publish Providers -> [2008/01/17 17:30:02 | 00,000,000 | —D | M]
Samsung -> C:\Documents and Settings\Phillip\Application Data\Samsung -> [2006/08/05 22:14:07 | 00,000,000 | —D | M]
Seven Zip -> C:\Documents and Settings\Phillip\Application Data\Seven Zip -> [2006/08/17 01:16:14 | 00,000,000 | —D | M]
Sony -> C:\Documents and Settings\Phillip\Application Data\Sony -> [2008/12/04 21:54:37 | 00,000,000 | —D | M]
Sony Setup -> C:\Documents and Settings\Phillip\Application Data\Sony Setup -> [2008/01/09 16:39:36 | 00,000,000 | —D | M]
Syntrillium -> C:\Documents and Settings\Phillip\Application Data\Syntrillium -> [2009/01/01 23:06:40 | 00,000,000 | —D | M]
teamspeak2 -> C:\Documents and Settings\Phillip\Application Data\teamspeak2 -> [2006/08/04 20:36:54 | 00,000,000 | —D | M]
U3 -> C:\Documents and Settings\Phillip\Application Data\U3 -> [2008/12/27 13:33:57 | 00,000,000 | —D | M]
Ulead Systems -> C:\Documents and Settings\Phillip\Application Data\Ulead Systems -> [2008/03/03 20:23:29 | 00,000,000 | —D | M]
Ventrilo -> C:\Documents and Settings\Phillip\Application Data\Ventrilo -> [2006/10/26 18:34:42 | 00,000,000 | —D | M]
Vso -> C:\Documents and Settings\Phillip\Application Data\Vso -> [2006/08/17 01:46:00 | 00,000,000 | —D | M]
Webcammax -> C:\Documents and Settings\Phillip\Application Data\Webcammax -> [2008/05/14 23:32:50 | 00,000,000 | —D | M]
C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2009/02/23 16:47:26 | 00,000,000 | –SD | M]
Ad-Aware Update (Weekly).job -> C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job -> [2009/02/18 21:22:04 | 00,000,472 | —- | M] ()
desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/10 05:00:00 | 00,000,065 | RH– | M] ()
ErrorSmart Scheduled Scan.job -> C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job -> [2009/02/21 03:30:00 | 00,000,406 | —- | M] ()
GoogleUpdateTaskUserS-1-5-21-1518184048-3988524191-3343478579-1005.job -> C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1518184048-3988524191-3343478579-1005.job -> [2009/02/22 20:47:57 | 00,000,934 | —- | M] ()
MP Scheduled Scan.job -> C:\WINDOWS\Tasks\MP Scheduled Scan.job -> [2009/02/23 16:47:27 | 00,000,330 | -H– | M] ()
SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2009/02/23 16:44:18 | 00,000,006 | -H– | M] ()
 
[File - Purity Scan]
 
[File - Signature Check]
< Cached Copy > -> < OS Copy > -> < MD5's >
C:\WINDOWS\servicepackfiles\i386\explorer.exe [2008/04/13 19:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\explorer.exe [2008/04/13 19:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) -> Cached Copy = 12896823FB95BFB3DC9B46BCAEDC9923 \ OS Copy = 12896823FB95BFB3DC9B46BCAEDC9923
C:\WINDOWS\servicepackfiles\i386\csrss.exe [2008/04/13 19:12:15 | 00,006,144 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\csrss.exe [2008/04/13 19:12:15 | 00,006,144 | —- | M] (Microsoft Corporation) -> Cached Copy = 44F275C64738EA2056E3D9580C23B60F \ OS Copy = 44F275C64738EA2056E3D9580C23B60F
C:\WINDOWS\servicepackfiles\i386\lsass.exe [2008/04/13 19:12:24 | 00,013,312 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\lsass.exe [2008/04/13 19:12:24 | 00,013,312 | —- | M] (Microsoft Corporation) -> Cached Copy = BF2466B3E18E970D8A976FB95FC1CA85 \ OS Copy = BF2466B3E18E970D8A976FB95FC1CA85
C:\WINDOWS\servicepackfiles\i386\rundll32.exe [2008/04/13 19:12:33 | 00,033,280 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\rundll32.exe [2008/04/13 19:12:33 | 00,033,280 | —- | M] (Microsoft Corporation) -> Cached Copy = 037B1E7798960E0420003D05BB577EE6 \ OS Copy = 037B1E7798960E0420003D05BB577EE6
C:\WINDOWS\servicepackfiles\i386\services.exe [2008/04/13 19:12:34 | 00,108,544 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\services.exe [2008/04/13 19:12:34 | 00,108,544 | —- | M] (Microsoft Corporation) -> Cached Copy = 0E776ED5F7CC9F94299E70461B7B8185 \ OS Copy = 0E776ED5F7CC9F94299E70461B7B8185
C:\WINDOWS\servicepackfiles\i386\smss.exe [2008/04/13 19:12:36 | 00,050,688 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\smss.exe [2008/04/13 19:12:36 | 00,050,688 | —- | M] (Microsoft Corporation) -> Cached Copy = 5F816C1F539266D2D4C78694239DA0B5 \ OS Copy = 5F816C1F539266D2D4C78694239DA0B5
C:\WINDOWS\servicepackfiles\i386\spoolsv.exe [2008/04/13 19:12:36 | 00,057,856 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\spoolsv.exe [2008/04/13 19:12:36 | 00,057,856 | —- | M] (Microsoft Corporation) -> Cached Copy = D8E14A61ACC1D4A6CD0D38AEBAC7FA3B \ OS Copy = D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
C:\WINDOWS\servicepackfiles\i386\svchost.exe [2008/04/13 19:12:36 | 00,014,336 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\svchost.exe [2008/04/13 19:12:36 | 00,014,336 | —- | M] (Microsoft Corporation) -> Cached Copy = 27C6D03BCDB8CFEB96B716F3D8BE3E18 \ OS Copy = 27C6D03BCDB8CFEB96B716F3D8BE3E18
C:\WINDOWS\servicepackfiles\i386\taskmgr.exe [2008/04/13 19:12:37 | 00,135,680 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\taskmgr.exe [2008/04/13 19:12:37 | 00,135,680 | —- | M] (Microsoft Corporation) -> Cached Copy = 2CD1C3506A85B38E2D17E61ADED175C4 \ OS Copy = 2CD1C3506A85B38E2D17E61ADED175C4
C:\WINDOWS\servicepackfiles\i386\userinit.exe [2008/04/13 19:12:38 | 00,026,112 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\userinit.exe [2008/04/13 19:12:38 | 00,026,112 | —- | M] (Microsoft Corporation) -> Cached Copy = A93AEE1928A9D7CE3E16D24EC7380F89 \ OS Copy = A93AEE1928A9D7CE3E16D24EC7380F89
C:\WINDOWS\servicepackfiles\i386\winlogon.exe [2008/04/13 19:12:39 | 00,507,904 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\winlogon.exe [2008/04/13 19:12:39 | 00,507,904 | —- | M] (Microsoft Corporation) -> Cached Copy = ED0EF0A136DEC83DF69F04118870003E \ OS Copy = ED0EF0A136DEC83DF69F04118870003E
 
[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden processes …
scanning hidden services & system hive …
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\gaopdxacwjcxef.sys"
"group"="file system"
"userdata"=dword:ffffffff
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules]
"gaopdxserv"="\\?\globalroot\systemroot\system32\drivers\gaopdxacwjcxef.sys"
"gaopdxl"="\\?\globalroot\systemroot\system32\gaopdxjkatnsxc.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:97856d1a
"s2"=dword:d12ad2bd
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:22,69,b6,3d,02,29,5d,fe,dd,ee,2e,2c,c8,29,cc,4f,84,2a,45,b0,9f,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,3a,79,ad,7a,23,91,a3,cb,ce,8f,c7,3c,8a,e5,dd,60,7c,..
"khjeh"=hex:a4,6b,5f,91,1f,b5,4c,5a,45,ca,4b,26,3c,0a,56,04,0b,08,48,5c,6f,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:fd,6f,3b,b9,58,67,d0,ff,17,8f,f5,fe,64,5c,10,3d,46,6b,9b,19,e4,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gaopdxserv.sys]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\gaopdxacwjcxef.sys"
"group"="file system"
"userdata"=dword:ffffffff
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gaopdxserv.sys\modules]
"gaopdxserv"="\\?\globalroot\systemroot\system32\drivers\gaopdxacwjcxef.sys"
"gaopdxl"="\\?\globalroot\systemroot\system32\gaopdxjkatnsxc.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:22,69,b6,3d,02,29,5d,fe,dd,ee,2e,2c,c8,29,cc,4f,84,2a,45,b0,9f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,3a,79,ad,7a,23,91,a3,cb,ce,8f,c7,3c,8a,e5,dd,60,7c,..
"khjeh"=hex:a4,6b,5f,91,1f,b5,4c,5a,45,ca,4b,26,3c,0a,56,04,0b,08,48,5c,6f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:fd,6f,3b,b9,58,67,d0,ff,17,8f,f5,fe,64,5c,10,3d,46,6b,9b,19,e4,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:22,69,b6,3d,02,29,5d,fe,dd,ee,2e,2c,c8,29,cc,4f,84,2a,45,b0,9f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,3a,79,ad,7a,23,91,a3,cb,ce,8f,c7,3c,8a,e5,dd,60,7c,..
"khjeh"=hex:a4,6b,5f,91,1f,b5,4c,5a,45,ca,4b,26,3c,0a,56,04,0b,08,48,5c,6f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:fd,6f,3b,b9,58,67,d0,ff,17,8f,f5,fe,64,5c,10,3d,46,6b,9b,19,e4,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\gaopdxserv.sys]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\gaopdxacwjcxef.sys"
"group"="file system"
"userdata"=dword:ffffffff
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\gaopdxserv.sys\modules]
"gaopdxserv"="\\?\globalroot\systemroot\system32\drivers\gaopdxacwjcxef.sys"
"gaopdxl"="\\?\globalroot\systemroot\system32\gaopdxjkatnsxc.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:22,69,b6,3d,02,29,5d,fe,dd,ee,2e,2c,c8,29,cc,4f,84,2a,45,b0,9f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,3a,79,ad,7a,23,91,a3,cb,ce,8f,c7,3c,8a,e5,dd,60,7c,..
"khjeh"=hex:a4,6b,5f,91,1f,b5,4c,5a,45,ca,4b,26,3c,0a,56,04,0b,08,48,5c,6f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:fd,6f,3b,b9,58,67,d0,ff,17,8f,f5,fe,64,5c,10,3d,46,6b,9b,19,e4,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\gaopdxserv.sys]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\gaopdxacwjcxef.sys"
"group"="file system"
"userdata"=dword:ffffffff
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\gaopdxserv.sys\modules]
"gaopdxserv"="\\?\globalroot\systemroot\system32\drivers\gaopdxacwjcxef.sys"
"gaopdxl"="\\?\globalroot\systemroot\system32\gaopdxjkatnsxc.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:22,69,b6,3d,02,29,5d,fe,dd,ee,2e,2c,c8,29,cc,4f,84,2a,45,b0,9f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,3a,79,ad,7a,23,91,a3,cb,ce,8f,c7,3c,8a,e5,dd,60,7c,..
"khjeh"=hex:a4,6b,5f,91,1f,b5,4c,5a,45,ca,4b,26,3c,0a,56,04,0b,08,48,5c,6f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:fd,6f,3b,b9,58,67,d0,ff,17,8f,f5,fe,64,5c,10,3d,46,6b,9b,19,e4,..
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
< Document and Settings folder & sub folders >
scanning hidden files …
C:\Documents and Settings\All Users\Application Data\Microsoft:5HJMFDvIwDjq4wgk1BFi 1103 bytes
C:\Documents and Settings\All Users\Application Data\Microsoft:aMSwzs4cvX8WQ72WcP 1168 bytes
C:\Documents and Settings\All Users\Application Data\Microsoft\KU0SKdt0:IC5dMns7nWk7gdrWjVinboii6B 1251 bytes
C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86 110 bytes
C:\Documents and Settings\All Users\Application Data\TEMP:9FA5EC55 106 bytes
C:\Documents and Settings\Jeannie\Favorites\Advanta - Small Business Credit Cards and Services.url:favicon 318 bytes
C:\Documents and Settings\Jeannie\Favorites\Chase Personal Banking Investments Credit Cards Home Auto Commercial Small Business Insurance.url:favicon 894 bytes
C:\Documents and Settings\Jeannie\Favorites\Classroom Forms - TeacherVision.com.url:favicon 894 bytes
C:\Documents and Settings\Jeannie\Favorites\Free 4th grade math worksheets. Randomly generated, printable from your browser!.url:favicon 318 bytes
C:\Documents and Settings\Jeannie\Favorites\Language Arts Standards - 4th grade student performance skills.url:favicon 1406 bytes
C:\Documents and Settings\Jeannie\Favorites\MSN.com.url:favicon 3638 bytes
C:\Documents and Settings\Jeannie\Favorites\WaMu  Transaction History.url:favicon 318 bytes
C:\Documents and Settings\Jeannie\Favorites\Washington Mutual  Log In.url:favicon 318 bytes
C:\Documents and Settings\Jeannie\Favorites\
C:\Documents and Settings\Phillip\Desktop\My Music\Drunken Tiger 6 1945 
C:\Documents and Settings\Phillip\Desktop\My Music\MC 
C:\Documents and Settings\Phillip\Desktop\My Music\
C:\Documents and Settings\Phillip\Desktop\My Music\
C:\Documents and Settings\Phillip\Favorites\TV Links.url:favicon 318 bytes
C:\Documents and Settings\Phillip\Favorites\
C:\Documents and Settings\Phillip\Favorites\
C:\Documents and Settings\Phillip\Local Settings\Temporary Internet Files:TLFmMLDYe5kfjbNx 1204 bytes
C:\Documents and Settings\Phillip\Local Settings\Temporary Internet Files\SUDPYPMSa0:KYiV1Ju7Z0iV0KXjL 1070 bytes
C:\Documents and Settings\Phillip\My Documents\redonce.flv:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} 0 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\1\1.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\2\2.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\3\3.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\4\4.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\5\5.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\6\6.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\7\7.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\burned\burned.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\loveletter\loveletter.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\Ohk Ju-Hyun Yoga\Ohk Ju-Hyun Yoga.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\project16\project16.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\TCPK 1 MONTH\TCPK 1 MONTH.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\My DVDs\we\we.dvd:Afp_AfpInfo 48 bytes
C:\Documents and Settings\Phillip\My Documents\redanride.flv:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} 0 bytes
scan completed successfully
hidden files: 408
 
< End of report >
EDIT: I had originally posted another scan to run, but combofix should deal with much of this, so let's go for it.

Hi Phil,

We're getting there, looks like a rootkit.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Please also post an updated HijackThis log and let me know how it's running.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
everything seems good so far!!
i'm not positive because this redirecting problem usually occurs only with some sites, but i think you might've done it!
thanks!














Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:51:34 PM, on 2/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Sonic\Product\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox 2 Beta 2\firefox.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\ooVoo\ooVoo.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 98.116.47.144.:80
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Sonic\Product\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [oovoo.exe] C:\Program Files\ooVoo\ooVoo.exe /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB
O16 - DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter25 Class) - http://download.netmarble.com/web/nmstarter/NMStarter25.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {92E82FBB-DA00-41E0-ABFE-95482E21A4F6} (NMTransX Module) - http://download.netmarble.net/NMChatX/NMTransX.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/activex/dmcc2.c…ersion=1,0,0,10
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - http://download.netmarble.net/kdefence/kdfense8237.cab
O16 - DPF: {AF60D574-F249-4243-8040-5521AAA5BB5E} (PandoraTVSet Class) - http://imgcdn.pandora.tv/pan_img/p3player/…ge/pdrtvset.cab
O16 - DPF: {C0B2F53E-5E61-4856-B314-FE9AE262A796} (MOPlayerWnd2 Class) - http://www.melon.com/cab/P3MelWebInstall.cab
O16 - DPF: {CBB45291-871B-4ADA-81D0-40D0C89ABD20} (NetmarbleDownloaderExCtrl Class) - http://download.netmarble.com/web/NMGameCh…ownloaderEx.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {EE4D2623-4584-42A1-9A2D-BD5FACAA9541} (Melon Sing Player) - http://sing.melon.com/melon/player/ocx/MelonSingPlayer.cab
O16 - DPF: {F4A1D5E2-AF49-47A7-A945-23038106F3A4} (Pandora_SetUp Control) - http://imgcdn.pandora.tv/pan_img/launcher/…ora_SetUpAX.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Unknown owner - C:\Program Files\Digidesign\Drivers\MMERefresh.exe (file missing)
O23 - Service: digiSPTIService - Unknown owner - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe (file missing)
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe

–
End of file - 11763 bytes

Attachments:

1. Open Notepad

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\windows\Tasks\ErrorSmart Scheduled Scan.job

Folder::
c:\program files\ErrorSmart


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Also,

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.
Please post back with
  • Rooter log
  • New HJt log
ComboFix 09-02-21.01 - Phillip 2009-02-23 20:15:40.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.561 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Phillip\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\windows\Tasks\ErrorSmart Scheduled Scan.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\ErrorSmart Scheduled Scan.job

.
((((((((((((((((((((((((( Files Created from 2009-01-24 to 2009-02-24 )))))))))))))))))))))))))))))))
.

2009-02-22 23:08 . 2009-02-22 23:09 d——– c:\program files\Microsoft LifeCam
2009-02-22 22:02 . 2009-02-22 22:02 d——– c:\program files\CCleaner
2009-02-22 20:25 . 2009-02-22 20:37 d——– c:\windows\ServicePackFiles
2009-02-22 02:48 . 2009-02-22 02:48 d——– c:\windows\SQL9_KB960089_ENU
2009-02-22 00:10 . 2008-08-14 05:11 2,189,184 ——— c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-22 00:10 . 2008-08-14 05:09 2,145,280 ——— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-22 00:10 . 2008-08-14 04:33 2,066,048 ——— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-22 00:10 . 2008-08-14 04:33 2,023,936 ——— c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-22 00:10 . 2008-09-15 07:12 1,846,400 ——— c:\windows\system32\dllcache\win32k.sys
2009-02-22 00:10 . 2008-10-24 06:21 455,296 ——— c:\windows\system32\dllcache\mrxsmb.sys
2009-02-22 00:10 . 2008-12-11 05:57 333,952 ——— c:\windows\system32\dllcache\srv.sys
2009-02-22 00:09 . 2008-10-15 11:34 337,408 ——— c:\windows\system32\dllcache\netapi32.dll
2009-02-21 22:40 . 2008-04-13 19:12 1,737,856 ——— c:\windows\system32\mtxparhd.dll
2009-02-21 22:39 . 2004-08-03 22:41 1,041,536 ——— c:\windows\system32\drivers\hsfdpsp2.sys
2009-02-21 22:19 . 2009-02-21 22:19 d——– c:\documents and settings\All Users\Application Data\Webcammax
2009-02-21 22:18 . 2009-02-21 22:26 d——– c:\program files\WebcamMax
2009-02-21 22:03 . 2009-02-21 22:03 d——– c:\program files\ERUNT
2009-02-21 21:53 . 2009-02-21 21:53 d——– c:\program files\Trend Micro
2009-02-21 21:46 . 2009-02-21 21:46 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-21 21:46 . 2009-02-21 21:46 d——– c:\documents and settings\Phillip\Application Data\Malwarebytes
2009-02-21 21:46 . 2009-02-21 21:46 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-21 21:46 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-21 21:46 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-20 23:02 . 2008-04-13 13:46 121,984 –a—— c:\windows\system32\drivers\usbvideo.sys
2009-02-20 14:11 . 2009-02-20 14:11 2,524 –a—— C:\autorun.PNF
2009-02-12 22:40 . 2009-02-12 22:40 d——– c:\program files\Alwil Software
2009-02-12 19:35 . 2009-02-21 22:15 d——– c:\program files\ooVoo
2009-02-09 20:38 . 2009-02-09 20:38 d——– c:\program files\Common Files\PACE Anti-Piracy
2009-02-09 20:38 . 2009-02-09 20:38 d——– c:\documents and settings\Phillip\Application Data\PACE Anti-Piracy
2009-02-09 20:38 . 2009-02-09 20:38 d——– c:\documents and settings\All Users\Application Data\PACE Anti-Piracy
2009-02-09 18:19 . 2003-03-18 22:20 1,060,864 –a—— c:\windows\system32\mfc71.dll
2009-02-09 18:19 . 2007-09-05 11:43 630,784 ——— c:\windows\system32\ilinet.dll
2009-02-09 18:19 . 2006-03-29 15:11 233,472 –a—— c:\windows\system32\REX Shared Library.dll
2009-02-09 18:19 . 2001-06-27 10:13 217,088 –a—— c:\windows\system32\qtmlClient.dll
2009-02-09 18:18 . 2009-02-10 00:15 d——– c:\program files\Digidesign
2009-02-09 18:17 . 2009-02-09 18:17 d——– c:\documents and settings\Phillip\Application Data\InstallShield
2009-01-29 12:42 . 2009-01-29 12:42 d——– c:\program files\Collision

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-24 00:49 ——— d—–w c:\program files\Mozilla Firefox 2 Beta 2
2009-02-23 02:02 ——— d—–w c:\program files\Best Buy Digital Music Store Powered by Rhapsody
2009-02-22 07:48 ——— d—–w c:\program files\Microsoft SQL Server
2009-02-21 20:38 ——— d—–w c:\program files\Microsoft Silverlight
2009-02-21 16:58 ——— d—–w c:\program files\Google
2009-02-20 16:42 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-02-20 16:42 ——— d—–w c:\program files\Java
2009-02-18 05:03 ——— d—–w c:\program files\Steam
2009-02-18 00:04 ——— d—–w c:\documents and settings\Jeannie\Application Data\AdobeUM
2009-02-15 14:09 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-14 05:36 ——— d—–w c:\program files\Warcraft III
2009-02-13 00:35 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-13 00:16 ——— d—–w c:\program files\DNA
2009-02-13 00:15 ——— d—–w c:\program files\Dell
2009-02-13 00:11 ——— d—–w c:\program files\Sony
2009-02-10 04:27 ——— d—–w c:\program files\Sony Setup
2009-02-03 20:11 ——— d—–w c:\program files\GameGuard
2009-02-03 02:22 15,688 —-a-w c:\windows\system32\lsdelete.exe
2009-01-29 17:41 ——— d—–w c:\program files\data
2009-01-22 02:22 64,160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-01-22 02:22 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-22 02:21 ——— dc-h–w c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-22 02:21 ——— d—–w c:\program files\Lavasoft
2009-01-22 02:19 ——— d—–w c:\documents and settings\Phillip\Application Data\Lavasoft
2009-01-20 04:37 ——— d—–w c:\program files\BitTorrent
2009-01-17 02:35 3,594,752 —-a-w c:\windows\system32\dllcache\mshtml.dll
2009-01-14 07:12 ——— d—–w c:\program files\res
2009-01-14 07:09 ——— d—–w c:\program files\bitmaps
2009-01-14 07:07 ——— d—–w c:\program files\world
2009-01-14 07:07 ——— d—–w c:\program files\sound
2009-01-14 07:07 ——— d—–w c:\program files\model
2009-01-13 21:01 ——— d—–w c:\program files\Neffy
2009-01-11 04:02 ——— d—–w c:\program files\Common Files\logishrd
2009-01-11 04:00 ——— d—–w c:\program files\Logitech
2009-01-11 04:00 ——— d—–w c:\documents and settings\All Users\Application Data\Logishrd
2009-01-02 04:06 ——— d—–w c:\documents and settings\Phillip\Application Data\Syntrillium
2008-12-27 18:33 ——— d—–w c:\documents and settings\Phillip\Application Data\U3
2008-12-19 09:10 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ——w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2006-08-17 06:26 81,920 -c–a-w c:\documents and settings\Phillip\Application Data\ezpinst.exe
2006-08-17 06:26 47,360 -c–a-w c:\documents and settings\Phillip\Application Data\pcouffin.sys
2005-05-13 21:12 217,073 –sha-r c:\windows\meta4.exe
2005-10-24 15:13 66,560 –sha-r c:\windows\MOTA113.exe
2008-10-01 19:15 88 –sh–r c:\windows\system32\603CD59FD3.sys
2005-07-14 16:31 27,648 –sha-r c:\windows\system32\AVSredirect.dll
2005-06-26 19:32 616,448 –sha-r c:\windows\system32\cygwin1.dll
2005-06-22 02:37 45,568 –sha-r c:\windows\system32\cygz.dll
2008-09-22 23:07 56 –sh–r c:\windows\system32\D39FD53C60.sys
2006-05-03 10:06 163,328 –sh–r c:\windows\system32\flvDX.dll
2004-01-25 04:00 70,656 –sha-r c:\windows\system32\i420vfw.dll
2008-10-01 19:15 5,018 –sha-w c:\windows\system32\KGyGaAvL.sys
2005-02-28 17:16 240,128 –sha-r c:\windows\system32\x.264.exe
2008-09-30 11:57 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008093020081001\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-02-23_18.47.08.48 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-06-12 50528]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Google Update"="c:\documents and settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-20 133104]
"oovoo.exe"="c:\program files\ooVoo\ooVoo.exe" [2009-02-01 14612272]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-12 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-12 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-10 118837]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"DMXLauncher"="c:\program files\Sonic\Product\Media Experience\DMXLauncher.exe" [2007-04-02 113400]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-19 185896]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-02 509784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-20 148888]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]
"nwiz"="nwiz.exe" [2007-12-05 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\steamapps\\xxredkidxx\\counter-strike\\hl.exe"=
"c:\\Program Files\\Steam\\steamapps\\nv_snipe\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\nv_snipe\\counter-strike\\hl.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Steam\\steamapps\\xxredkidxx\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Steam\\steamapps\\xxredkidxx\\day of defeat source\\hl2.exe"=
"c:\\WINDOWS\\system32\\grdmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Steam\\steamapps\\xxredkidxx\\counter-strike source beta\\hl2.exe"=
"c:\\Program Files\\America's Army\\System\\Server.exe"=
"c:\\Program Files\\Steam\\steamapps\\xxredkidxx\\dedicated server\\hltv.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Mozilla Firefox 2 Beta 2\\firefox.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\pdrtvsvr.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\ijji\\ENGLISH\\u_gbound.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\ooVoo\\ooVoo.exe"=
"c:\\ijji\\ENGLISH\\u_gunz.exe"=
"c:\\Netmarble\\NetmarbleDownLoaderEx\\NetmarbleDownLoader_EngineEx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:warcraft
"37674:TCP"= 37674:TCP:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:ooVoo UDP port 37675
"443:TCP"= 443:TCP:ooVoo TCP port 443
"443:UDP"= 443:UDP:ooVoo UDP port 443

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-01-21 64160]
R2 CAMTHWDM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\CAMTHWDM.sys [2008-05-14 941784]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2006-08-05 2368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [2009-01-10 33808]
S0 DigiFilter;DigiFilter;c:\windows\system32\drivers\DigiFilt.sys –> c:\windows\system32\drivers\DigiFilt.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S3 MSSQL$SONY_MEDIAMGR2;SQL Server (SONY_MEDIAMGR2);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-12-18 29181272]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-19 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-02 21:22]

2009-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1518184048-3988524191-3343478579-1005.job
- c:\documents and settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-20 23:46]

2009-02-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyServer = 98.116.47.144.:80
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
Trusted Zone: musicmatch.com\online
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} - hxxp://download.netmarble.com/web/nmstarter/NMStarter25.cab
DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} - hxxp://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
DPF: {92E82FBB-DA00-41E0-ABFE-95482E21A4F6} - hxxp://download.netmarble.net/NMChatX/NMTransX.cab
DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} - hxxp://cafeimg.hanmail.net/activex/dmcc2.cab?Version=1,0,0,10
DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - hxxp://download.netmarble.net/kdefence/kdfense8237.cab
DPF: {AF60D574-F249-4243-8040-5521AAA5BB5E} - hxxp://imgcdn.pandora.tv/pan_img/p3player/package/pdrtvset.cab
DPF: {C0B2F53E-5E61-4856-B314-FE9AE262A796} - hxxp://www.melon.com/cab/P3MelWebInstall.cab
DPF: {CBB45291-871B-4ADA-81D0-40D0C89ABD20} - hxxp://download.netmarble.com/web/NMGameCheck/NetmarbleDownloaderEx.cab
DPF: {EE4D2623-4584-42A1-9A2D-BD5FACAA9541} - hxxp://sing.melon.com/melon/player/ocx/MelonSingPlayer.cab
DPF: {F4A1D5E2-AF49-47A7-A945-23038106F3A4} - hxxp://imgcdn.pandora.tv/pan_img/launcher/codebase/Pandora_SetUpAX.cab
FF - ProfilePath - c:\documents and settings\Phillip\Application Data\Mozilla\Firefox\Profiles\wb4on7zn.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.weather.com/weather/local/11803?lswe=11803&lwsa;=WeatherLocalUndeclared&from;=whatwhere
FF - component: c:\program files\Mozilla Firefox 2 Beta 2\components\iamfamous.dll
FF - plugin: c:\documents and settings\Phillip\Application Data\Mozilla\Firefox\Profiles\wb4on7zn.default\extensions\{5601B994-0E9B-4ce2-8AB9-AD1155F2ABBD}\plugins\NPNeffyPlugin.dll
FF - plugin: c:\documents and settings\Phillip\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox 2 Beta 2\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox 2 Beta 2\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox 2 Beta 2\plugins\npunagi2.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-23 20:20:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
Completion time: 2009-02-23 20:24:22
ComboFix-quarantined-files.txt 2009-02-24 01:23:05
ComboFix2.txt 2009-02-23 23:49:24

Pre-Run: 7,445,229,568 bytes free
Post-Run: 7,427,444,736 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
268 — E O F — 2009-02-24 00:14:38








































new hijackthis




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:43:06 PM, on 2/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Sonic\Product\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ooVoo\ooVoo.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox 2 Beta 2\firefox.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 98.116.47.144.:80
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Sonic\Product\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [oovoo.exe] C:\Program Files\ooVoo\ooVoo.exe /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB
O16 - DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter25 Class) - http://download.netmarble.com/web/nmstarter/NMStarter25.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {92E82FBB-DA00-41E0-ABFE-95482E21A4F6} (NMTransX Module) - http://download.netmarble.net/NMChatX/NMTransX.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/activex/dmcc2.c…ersion=1,0,0,10
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - http://download.netmarble.net/kdefence/kdfense8237.cab
O16 - DPF: {AF60D574-F249-4243-8040-5521AAA5BB5E} (PandoraTVSet Class) - http://imgcdn.pandora.tv/pan_img/p3player/…ge/pdrtvset.cab
O16 - DPF: {C0B2F53E-5E61-4856-B314-FE9AE262A796} (MOPlayerWnd2 Class) - http://www.melon.com/cab/P3MelWebInstall.cab
O16 - DPF: {CBB45291-871B-4ADA-81D0-40D0C89ABD20} (NetmarbleDownloaderExCtrl Class) - http://download.netmarble.com/web/NMGameCh…ownloaderEx.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {EE4D2623-4584-42A1-9A2D-BD5FACAA9541} (Melon Sing Player) - http://sing.melon.com/melon/player/ocx/MelonSingPlayer.cab
O16 - DPF: {F4A1D5E2-AF49-47A7-A945-23038106F3A4} (Pandora_SetUp Control) - http://imgcdn.pandora.tv/pan_img/launcher/…ora_SetUpAX.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Unknown owner - C:\Program Files\Digidesign\Drivers\MMERefresh.exe (file missing)
O23 - Service: digiSPTIService - Unknown owner - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe (file missing)
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe

–
End of file - 11801 bytes




































rooter log

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Pentium® D CPU 2.80GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A05
USER : Phillip ( Administrator )
BOOT : Normal boot




C:\ (Local Disk) - NTFS - Total:228 Go (Free:6 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (CD or DVD)

Mon 02/23/2009|20:44

———————-\\ Search..

———————-\\ Cracks & Keygens..

C:\DOCUME~1\Phillip\My Documents\redcrack.rar
C:\DOCUME~1\Phillip\My Documents\My Pictures\SponceCrack.jpg


1 - "C:\Rooter$\Rooter_1.txt" - Mon 02/23/2009|20:44

———————-\\ Scan completed at 20:44












new HJTlog

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:46:15 PM, on 2/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Sonic\Product\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ooVoo\ooVoo.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox 2 Beta 2\firefox.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 98.116.47.144.:80
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Sonic\Product\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Phillip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [oovoo.exe] C:\Program Files\ooVoo\ooVoo.exe /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB
O16 - DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter25 Class) - http://download.netmarble.com/web/nmstarter/NMStarter25.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {92E82FBB-DA00-41E0-ABFE-95482E21A4F6} (NMTransX Module) - http://download.netmarble.net/NMChatX/NMTransX.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/activex/dmcc2.c…ersion=1,0,0,10
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - http://download.netmarble.net/kdefence/kdfense8237.cab
O16 - DPF: {AF60D574-F249-4243-8040-5521AAA5BB5E} (PandoraTVSet Class) - http://imgcdn.pandora.tv/pan_img/p3player/…ge/pdrtvset.cab
O16 - DPF: {C0B2F53E-5E61-4856-B314-FE9AE262A796} (MOPlayerWnd2 Class) - http://www.melon.com/cab/P3MelWebInstall.cab
O16 - DPF: {CBB45291-871B-4ADA-81D0-40D0C89ABD20} (NetmarbleDownloaderExCtrl Class) - http://download.netmarble.com/web/NMGameCh…ownloaderEx.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {EE4D2623-4584-42A1-9A2D-BD5FACAA9541} (Melon Sing Player) - http://sing.melon.com/melon/player/ocx/MelonSingPlayer.cab
O16 - DPF: {F4A1D5E2-AF49-47A7-A945-23038106F3A4} (Pandora_SetUp Control) - http://imgcdn.pandora.tv/pan_img/launcher/…ora_SetUpAX.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Unknown owner - C:\Program Files\Digidesign\Drivers\MMERefresh.exe (file missing)
O23 - Service: digiSPTIService - Unknown owner - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe (file missing)
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe

–
End of file - 11762 bytes
Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.


Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
    * Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    * Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    * Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in
your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

In your next reply post:
Kaspersky log
New HJT log taken after the above scan has run
hey i've tried running the kaspersky scan but it freezes within 10 minutes of the start of the scan, i thought that it was just stalling like you said. but i left it on overnight and in the morning it was still at 2:56. and i've tried this kaspersky scan numerous times. i turned off all my spyware/anti virus removal software.
Let's try something else….

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

it didnt seem to have detected anything. Scan —- Scanned: 1057299 Detected: 0 Untreated: 0 Start time: 2/27/2009 7:04:41 AM Duration: 07:14:09 Finish time: 2/27/2009 2:18:50 PM Detected ——– Status Object —— ——

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI