This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very strong virus/malware? HELP IS NEEDED!

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, while I was doing some research online, my computer pop-ed up an admin request of allowing an "update.exe" or something to be authorized. I accidentally clicked on "allow" before I know it due to reflex reaction.. so i'm pretty sure my laptop got virus/malware from it. so right now, the virus does not allow me to run .exe or IE or firefox. everytime I try to open them, this advertisement of "vista internet security 2011 unregistered" thing pops up. starts to show it's scannig my laptop and found many virus in it. it then asked to buy the full version to clean it. I opened task manager and figured this "hke.exe" should be related to this thing. Luckily, i found out i can run .exe and firefox by right clicking and run as admin to have them function normally.

here is my hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:38:32 AM, on 04/04/2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.19019)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\User\AppData\Local\hke.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
G:\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live μn?J?pA°?a - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.0"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerProducer" update "Software\CyberLink\PowerProducer\5.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SmileboxTray] "C:\Users\User\AppData\Roaming\Smilebox\SmileboxTray.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [PPS Accelerator] C:\PROGRA~1\PPStream\ppsap.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: 傳送影像到 Bluetooth 裝置(&B)… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: 傳送頁面到 Bluetooth 裝置(&B)… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O15 - Trusted Zone: http://*.pps.tv
O15 - Trusted Zone: http://*.ppstream.com
O15 - Trusted Zone: http://*.webscache.com
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O15 - ESC Trusted Zone: http://*.pps.tv
O15 - ESC Trusted Zone: http://*.ppstream.com
O15 - ESC Trusted Zone: http://*.webscache.com
O16 - DPF: {134607FB-69C2-44ED-8EEC-3D67B5E6CEFE} (RunupGameActX Control) - http://fgcpatch.funmily.com/fgc/RunupGameActX.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://ivenue.webex.com/client/T27L/support/ieatgpc1.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: mbox - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\system32\mshtml.dll
O18 - Protocol: mboxflash - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\system32\mshtml.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\system32\atashost.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: IntelR PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: IntelR PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Rezip - Unknown owner - C:\Windows\SYSTEM32\Rezip.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe

–
End of file - 11035 bytes


Please advise steps to clean this. Many many thanks.

Best regards,
Stanley
Hello Sandrock and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please do not install/uninstall any programs unless asked to.
Please do not run any scans other than those requested

I am looking at your log and will post instructions shortly.

Satchfan
Hello again Sandrock

There is sign of infection so we’ll have to do some deeper scans to see what else is lurking.

First

P2P - I see you have P2P software, ( BitComet ), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

OTL.txt
Extras.txt
Gmer.txt


Thanks

Satchfan
Bitcomet is removed. I'm having problems with gmer scan, my laptop crashed while it was scanning and went into a blue screen saying it is preventing my computer being harmed, it said it was dumping something.. I didn't catch what it was and it restarted. my screen was all black after it loaded to windows, so now I started my computer in safe mode and gonna upload the logs from OTC.exe first. I'll try to scan with gmer in safe mode see if it will work.

The following log is OTC.txt
======================

OTL logfile created on: 04/04/2011 10:39:18 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\User\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00001009 | Country: 加拿大 | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 142.09 Gb Total Space | 33.78 Gb Free Space | 23.77% Space Free | Partition Type: NTFS
Drive D: | 143.00 Gb Total Space | 15.02 Gb Free Space | 10.50% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\User\AppData\Local\hke.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\System32\Rezip.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (TeamViewer5) – C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Rezip) – C:\Windows\System32\Rezip.exe ()
SRV - (yksvc) – C:\Windows\System32\ykx32mpcoinst.dll (Marvell)
SRV - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (dtsoftbus01) – C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (DgiVecp) – C:\Windows\System32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (SSPORT) – C:\Windows\System32\drivers\SSPORT.SYS (Samsung Electronics)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (VMC326) – C:\Windows\System32\drivers\VMC326.sys (Vimicro Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (KMDFMEMIO) – C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…n&bmod;=smsn
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…N&bmod;=SMSN

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…n&bmod;=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…n&bmod;=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.17
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/01/25 16:26:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\program files\Mozilla Firefox\components [2011/03/24 18:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\program files\Mozilla Firefox\plugins [2011/03/24 18:33:53 | 000,000,000 | —D | M]

[2009/09/17 13:44:27 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Extensions
[2011/04/04 00:47:37 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\n907lw05.default\extensions
[2010/01/08 18:00:14 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\n907lw05.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2011/04/04 00:47:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/17 05:17:49 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/07/07 15:12:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/01/25 16:26:52 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2009/07/17 01:40:12 | 000,704,512 | —- | M] (BitComet) – C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010/07/07 15:11:49 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/03/16 01:48:29 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2010/03/31 14:08:09 | 000,002,310 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\findbook-zh-TW.xml
[2010/03/31 14:08:09 | 000,001,222 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-zh-TW.xml
[2010/03/31 14:08:09 | 000,001,360 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-answer-zh-TW.xml
[2010/03/31 14:08:09 | 000,000,843 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-bid-zh-TW.xml
[2010/03/31 14:08:09 | 000,001,161 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-zh-TW.xml

O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] File not found
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [PPS Accelerator] C:\Program Files\PPStream\PPSAP.exe (PPStream Inc)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\User\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8 - Extra context menu item: 傳送影像到 Bluetooth 裝置(&B;)… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: 傳送頁面到 Bluetooth 裝置(&B;)… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: pps.tv ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: ppstream.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: webscache.com ([]http in Trusted sites)
O16 - DPF: {134607FB-69C2-44ED-8EEC-3D67B5E6CEFE} http://fgcpatch.funmily.com/fgc/RunupGameActX.ocx (RunupGameActX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://ivenue.webex.com/client/T27L/support/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0b982241-e513-11de-bf97-00242cdc4a53}\Shell - "" = AutoRun
O33 - MountPoints2\{0b982241-e513-11de-bf97-00242cdc4a53}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{11c8d9f1-243e-11df-b3ab-00242cdc4a53}\Shell\AutoRun\command - "" = yq.com
O33 - MountPoints2\{11c8d9f1-243e-11df-b3ab-00242cdc4a53}\Shell\open\Command - "" = yq.com
O33 - MountPoints2\{732a59c0-1aab-11e0-8b23-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{732a59c0-1aab-11e0-8b23-806e6f6e6963}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{83148be7-dae1-11de-be1c-00242cdc4a53}\Shell\1\Command - "" = F:\Recycle.exe
O33 - MountPoints2\{83148be7-dae1-11de-be1c-00242cdc4a53}\Shell\2\Command - "" = F:\Recycle.exe
O33 - MountPoints2\{83148be7-dae1-11de-be1c-00242cdc4a53}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Recycle.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "C:\Users\User\AppData\Local\hke.exe" -a "%1" %* ()
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "C:\Users\User\AppData\Local\hke.exe" -a "%1" %* ()

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.X264 - C:\Windows\System32\x264vfw.dll ()
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/04/04 10:37:29 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2011/04/04 00:46:30 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\User\Desktop\HijackThis.exe
[2011/04/03 17:06:26 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/04/03 17:06:26 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/04/03 17:06:26 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/04/03 17:06:26 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/04/03 17:06:26 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/04/03 17:06:25 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/04/03 17:06:25 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/04/03 17:06:25 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/04/03 17:06:25 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/04/03 17:06:25 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/04/03 17:06:24 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/04/03 17:06:24 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/04/03 17:06:24 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/04/03 17:06:24 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/04/03 17:06:24 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/04/03 17:06:24 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/04/03 17:06:23 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/04/03 17:03:46 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/04/03 17:03:46 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/04/03 17:03:45 | 000,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/04/03 17:03:45 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2011/04/03 17:03:44 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/04/03 17:03:44 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/04/03 17:03:44 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/04/03 17:03:44 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/04/03 17:03:43 | 000,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/04/03 17:03:43 | 000,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2011/04/03 17:03:43 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/04/03 17:03:43 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/04/03 17:03:43 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/04/03 17:03:43 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/04/03 17:03:42 | 000,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/04/03 17:03:42 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/04/03 17:03:41 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/04/03 17:03:41 | 000,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/04/03 17:03:41 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/04/03 17:03:40 | 003,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/04/03 17:03:40 | 000,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/04/03 17:03:39 | 000,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2011/04/03 17:03:39 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/04/03 17:03:39 | 000,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/04/03 17:03:39 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2011/03/31 19:18:48 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Tibia
[2011/03/31 18:58:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tibia
[2011/03/31 18:58:04 | 000,000,000 | —D | C] – C:\Program Files\Tibia
[2011/03/24 20:50:06 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FP Solutions 2009
[2011/03/24 20:49:44 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.023
[2011/03/24 20:49:43 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.022
[2011/03/24 20:49:43 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01E
[2011/03/24 20:49:43 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01F
[2011/03/24 20:49:43 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.020
[2011/03/24 20:49:43 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.021
[2011/03/24 20:33:54 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01C
[2011/03/24 20:33:54 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01D
[2011/03/24 20:33:54 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.019
[2011/03/24 20:33:54 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01A
[2011/03/24 20:33:54 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01B
[2011/03/24 20:33:53 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.018
[2011/03/24 14:05:41 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.016
[2011/03/24 14:05:41 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.012
[2011/03/24 14:05:41 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.017
[2011/03/24 14:05:41 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.013
[2011/03/24 14:05:41 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.014
[2011/03/24 14:05:41 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.015
[2011/03/24 14:05:41 | 000,000,000 | —D | C] – C:\Users\User\FPS2009
[2011/03/24 14:01:13 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.010
[2011/03/24 14:01:13 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00C
[2011/03/24 14:01:13 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.011
[2011/03/24 14:01:13 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00D
[2011/03/24 14:01:13 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00E
[2011/03/24 14:01:13 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00F
[2011/03/24 13:55:20 | 000,000,000 | —D | C] – C:\ProgramData\FPS2009
[2011/03/24 13:55:19 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00B
[2011/03/24 13:55:17 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00A
[2011/03/24 13:55:17 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.006
[2011/03/24 13:55:17 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.007
[2011/03/24 13:55:17 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.008
[2011/03/24 13:55:17 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.009
[2011/03/24 13:38:48 | 000,000,000 | —D | C] – C:\Users\User\Application Data
[2011/03/24 13:37:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FP Solutions 2009
[2011/03/24 13:36:48 | 000,000,000 | —D | C] – C:\CCH FinancialWorks
[2011/03/24 13:36:47 | 000,368,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbar332.dll
[2011/03/24 13:36:47 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.005
[2011/03/24 13:36:45 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.004
[2011/03/24 13:36:45 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.001
[2011/03/24 13:36:45 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.002
[2011/03/24 13:36:45 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.003
[2011/03/24 13:36:44 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.000
[2011/03/18 16:07:43 | 000,000,000 | —D | C] – C:\Users\User\Documents\OneNote Notebooks
[2011/03/08 12:43:33 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/08 12:43:33 | 000,323,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/08 12:43:33 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/08 12:43:33 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/03/08 12:32:40 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast
[2011/03/08 12:32:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast
[2011/03/08 12:32:40 | 000,000,000 | —D | C] – C:\Program Files\SopCast
[2011/03/07 15:50:46 | 000,000,000 | —D | C] – C:\Windows\FLV Player
[2011/03/07 15:50:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FLV Player
[2011/03/07 15:50:46 | 000,000,000 | —D | C] – C:\Program Files\FLV Player

========== Files Created - No Company Name ==========

[2011/04/04 10:41:30 | 000,301,568 | —- | C] () – C:\Users\User\Desktop\gmer.exe
[2011/04/04 00:35:18 | 000,000,374 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{967B0F62-047B-476C-9458-AEB3A37DC7A8}.job
[2011/04/04 00:27:29 | 3215,572,992 | -HS- | C] () – C:\hiberfil.sys
[2011/04/03 17:06:24 | 000,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/04/03 15:47:32 | 000,008,968 | -HS- | C] () – C:\Users\User\AppData\Local\08a4u2o670p0ms3ur18g20l873t74n
[2011/04/03 15:47:32 | 000,008,968 | -HS- | C] () – C:\ProgramData\08a4u2o670p0ms3ur18g20l873t74n
[2011/04/03 15:47:31 | 000,228,990 | -HS- | C] () – C:\Users\User\AppData\Local\vhh.exe
[2011/04/03 15:47:09 | 000,228,990 | -HS- | C] () – C:\Users\User\AppData\Local\vpk.exe
[2011/04/03 15:47:04 | 000,228,990 | -HS- | C] () – C:\Users\User\AppData\Local\Update.exe
[2011/04/03 15:47:04 | 000,228,990 | -HS- | C] () – C:\Users\User\AppData\Local\hke.exe
[2011/03/29 17:42:39 | 005,201,920 | —- | C] () – C:\Users\User\Desktop\愛在不在 主題曲 愛在一線之差.mp3
[2011/03/27 20:11:25 | 000,000,680 | —- | C] () – C:\Users\User\AppData\Local\d3d9caps.dat
[2011/03/27 14:13:46 | 617,297,023 | —- | C] () – C:\Users\User\Desktop\skgaming_msi_vs_dwi_1.flv
[2011/03/27 14:13:28 | 468,166,547 | —- | C] () – C:\Users\User\Desktop\skgaming_msi_vs_dwi_2.flv
[2011/03/24 20:50:27 | 000,000,776 | —- | C] () – C:\Users\User\Desktop\Annual Review Tool.lnk
[2011/03/24 20:50:26 | 000,000,746 | —- | C] () – C:\Users\User\Desktop\Report Editor.lnk
[2011/03/24 20:50:24 | 000,000,791 | —- | C] () – C:\Users\User\Desktop\Financial Calculators.lnk
[2011/03/24 20:50:23 | 000,000,786 | —- | C] () – C:\Users\User\Desktop\Fact Finder Business.lnk
[2011/03/24 20:50:22 | 000,000,786 | —- | C] () – C:\Users\User\Desktop\Fact Finder Personal.lnk
[2011/03/24 20:50:20 | 000,000,746 | —- | C] () – C:\Users\User\Desktop\FP Solutions Help.lnk
[2011/03/24 20:50:19 | 000,000,896 | —- | C] () – C:\Users\User\Desktop\FP Solutions User Guide.lnk
[2011/03/24 20:50:18 | 000,000,746 | —- | C] () – C:\Users\User\Desktop\FP Solutions.lnk
[2011/03/24 13:40:24 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/03/24 13:40:24 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/03/24 13:35:53 | 000,164,864 | —- | C] () – C:\Program Files\UNWISE.EXE
[2011/03/18 16:07:42 | 000,001,111 | —- | C] () – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2011/03/17 18:50:48 | 433,798,207 | —- | C] () – C:\Users\User\Desktop\zqxs.dvd.yueyu.rmvb
[2011/03/17 18:32:52 | 000,161,605 | —- | C] () – C:\Users\User\Desktop\IMG00066-20101231-1928.jpg
[2011/03/08 12:32:40 | 000,000,788 | —- | C] () – C:\Users\User\Desktop\SopCast.lnk
[2011/03/07 15:50:46 | 000,001,695 | —- | C] () – C:\Users\Public\Desktop\FLV Player.lnk
[2010/08/09 13:09:01 | 000,479,232 | —- | C] () – C:\Windows\ssndii.exe
[2010/08/09 13:08:08 | 000,022,723 | —- | C] () – C:\Windows\System32\ssp1ml3.dll
[2010/05/24 12:33:00 | 004,670,829 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2010/05/24 12:33:00 | 001,529,856 | —- | C] () – C:\Windows\System32\ff_samplerate.dll
[2010/05/24 12:33:00 | 001,447,921 | —- | C] () – C:\Windows\System32\ffmpegmt.dll
[2010/05/24 12:33:00 | 000,877,385 | —- | C] () – C:\Windows\System32\ff_x264.dll
[2010/05/24 12:33:00 | 000,810,113 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/05/24 12:33:00 | 000,336,384 | —- | C] () – C:\Windows\System32\ff_libfaad2.dll
[2010/05/24 12:33:00 | 000,324,096 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2010/05/24 12:33:00 | 000,248,320 | —- | C] () – C:\Windows\System32\ff_kernelDeint.dll
[2010/05/24 12:33:00 | 000,216,576 | —- | C] () – C:\Windows\System32\ff_libdts.dll
[2010/05/24 12:33:00 | 000,151,552 | —- | C] () – C:\Windows\System32\ff_libmad.dll
[2010/05/24 12:33:00 | 000,145,408 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2010/05/24 12:33:00 | 000,139,944 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2010/05/24 12:33:00 | 000,121,856 | —- | C] () – C:\Windows\System32\ff_liba52.dll
[2010/05/24 12:33:00 | 000,116,736 | —- | C] () – C:\Windows\System32\ff_tremor.dll
[2010/05/24 12:33:00 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/05/24 12:33:00 | 000,100,864 | —- | C] () – C:\Windows\System32\ff_wmv9.dll
[2010/05/24 12:33:00 | 000,097,792 | —- | C] () – C:\Windows\System32\ff_unrar.dll
[2010/05/19 13:59:20 | 000,150,528 | —- | C] () – C:\Windows\System32\mkx.dll
[2010/05/19 13:59:10 | 000,109,568 | —- | C] () – C:\Windows\System32\avi.dll
[2010/05/19 13:59:02 | 000,141,824 | —- | C] () – C:\Windows\System32\mp4.dll
[2010/05/19 13:58:52 | 000,123,392 | —- | C] () – C:\Windows\System32\ogm.dll
[2010/05/19 13:58:24 | 000,113,152 | —- | C] () – C:\Windows\System32\dsmux.exe
[2010/05/19 13:58:18 | 000,154,112 | —- | C] () – C:\Windows\System32\ts.dll
[2010/05/19 13:58:08 | 000,249,856 | —- | C] () – C:\Windows\System32\dxr.dll
[2010/05/19 13:57:42 | 000,097,792 | —- | C] () – C:\Windows\System32\avs.dll
[2010/05/19 13:57:38 | 000,137,728 | —- | C] () – C:\Windows\System32\mkv2vfr.exe
[2010/05/19 13:57:26 | 000,093,184 | —- | C] () – C:\Windows\System32\avss.dll
[2010/05/19 13:57:20 | 000,358,400 | —- | C] () – C:\Windows\System32\gdsmux.exe
[2010/05/19 13:55:40 | 000,080,384 | —- | C] () – C:\Windows\System32\mkzlib.dll
[2010/05/19 13:55:36 | 000,024,576 | —- | C] () – C:\Windows\System32\mkunicode.dll
[2010/04/17 05:20:00 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/03/26 12:04:54 | 000,041,872 | —- | C] () – C:\Windows\System32\xfcodec.dll
[2009/11/30 16:07:26 | 000,550,418 | —- | C] () – C:\Windows\System32\x264vfw.dll
[2009/11/11 17:04:27 | 000,138,464 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2009/11/11 17:04:26 | 000,022,328 | —- | C] () – C:\Users\User\AppData\Roaming\PnkBstrK.sys
[2009/11/11 17:04:11 | 000,111,928 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2009/11/11 17:04:08 | 000,682,280 | —- | C] () – C:\Windows\System32\pbsvc.exe
[2009/11/11 17:04:08 | 000,066,872 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2009/09/25 08:50:44 | 000,000,534 | —- | C] () – C:\Windows\eReg.dat
[2009/09/23 18:32:16 | 000,145,854 | —- | C] () – C:\Windows\War3Unin.dat
[2009/09/20 06:28:56 | 000,075,776 | —- | C] () – C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/17 13:30:15 | 000,000,378 | —- | C] () – C:\Windows\NJCOM.INI
[2009/08/11 14:21:26 | 000,087,552 | —- | C] () – C:\Windows\System32\ac3config.exe
[2009/07/02 18:55:26 | 000,208,064 | —- | C] () – C:\ProgramData\nvModes.001
[2009/07/02 18:55:13 | 000,208,064 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/06/07 09:24:04 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2009/06/02 15:43:56 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2009/06/02 01:14:13 | 000,307,200 | —- | C] () – C:\Windows\SetDisplayResolution.exe
[2009/06/02 00:19:55 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/06/02 00:19:54 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/06/02 00:07:59 | 000,000,135 | R— | C] () – C:\Windows\System32\lngEng.ini
[2009/06/02 00:07:59 | 000,000,117 | —- | C] () – C:\Windows\System32\lngKor.ini
[2009/06/01 23:55:43 | 000,311,296 | —- | C] () – C:\Windows\System32\Rezip.exe
[2009/06/01 23:54:58 | 000,040,960 | —- | C] () – C:\Windows\System32\IhDEV.exe
[2009/06/01 23:54:58 | 000,024,576 | —- | C] () – C:\Windows\System32\IhINF.exe
[2009/06/01 23:54:45 | 000,003,990 | —- | C] () – C:\Windows\HotFixList.ini
[2009/06/01 22:34:09 | 000,381,558 | —- | C] () – C:\Windows\System32\prfh0404.dat
[2009/06/01 22:34:09 | 000,121,430 | —- | C] () – C:\Windows\System32\prfc0404.dat
[2009/06/01 22:34:09 | 000,116,540 | —- | C] () – C:\Windows\System32\prfi0404.dat
[2009/06/01 22:34:09 | 000,030,674 | —- | C] () – C:\Windows\System32\prfd0404.dat
[2009/06/01 22:17:23 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2009/01/10 15:15:44 | 000,159,744 | —- | C] () – C:\Windows\System32\mmfinfo.dll
[2008/11/06 08:37:32 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/09/11 01:45:02 | 000,057,344 | —- | C] () – C:\Windows\System32\BtwNamespaceExt2.dll
[2008/02/09 09:03:07 | 000,024,576 | —- | C] () – C:\Windows\System32\drivers\Marker.exe
[2007/10/13 02:30:20 | 000,000,137 | —- | C] () – C:\Windows\System32\Registration.ini
[2007/04/15 12:24:16 | 000,023,752 | —- | C] () – C:\Windows\System32\providers.bin
[2007/02/26 00:49:12 | 006,139,774 | —- | C] () – C:\Windows\imagine digital freedom.dat
[2007/02/07 20:12:10 | 000,000,021 | —- | C] () – C:\Windows\KwYl.dat
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 001,765,264 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,642,704 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,121,592 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/11/13 22:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2011/01/07 15:19:23 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DAEMON Tools Lite
[2010/04/01 10:40:22 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Facebook
[2009/12/18 23:03:36 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\NCH Swift Sound
[2009/10/09 11:04:35 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\NJStar
[2011/03/23 10:02:14 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PPStream
[2009/12/10 00:45:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Research In Motion
[2010/03/11 19:45:04 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Smilebox
[2011/01/07 15:39:22 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Sports Interactive
[2010/03/01 16:08:42 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TeamViewer
[2011/03/31 19:20:15 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tibia
[2011/04/03 17:17:32 | 000,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/04/04 10:35:35 | 000,000,374 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{967B0F62-047B-476C-9458-AEB3A37DC7A8}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 14:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 19:24:42 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2008/02/08 02:31:21 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/03/16 02:04:41 | 768,309,223 | —- | M] () – C:\Flyff_Client.exe
[2011/04/04 10:31:29 | 3215,572,992 | -HS- | M] () – C:\hiberfil.sys
[2011/03/24 13:40:24 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/03/24 13:40:24 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/04/04 10:31:27 | 3529,375,744 | -HS- | M] () – C:\pagefile.sys
[2009/06/01 23:52:19 | 000,001,618 | —- | M] () – C:\RHDSetup.log
[2009/06/02 00:08:00 | 000,000,191 | —- | M] () – C:\Setup.log

< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 05:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2007/11/28 06:55:36 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\Windows\System32\spool\prtprocs\w32x86\ssp1mpc.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2007/02/26 00:49:10 | 001,744,896 | —- | M] (TopThinks, INC.) – C:\Windows\imagine digital freedom.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2011/03/24 20:46:40 | 000,001,527 | —- | M] () – C:\Program Files\INSTALL.LOG
[2001/09/28 17:00:28 | 000,164,864 | —- | M] () – C:\Program Files\UNWISE.EXE

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 20:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 20:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 20:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/09 15:29:43 | 000,000,574 | -HS- | M] () – C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/03/20 17:07:56 | 000,301,568 | —- | M] () – C:\Users\User\Desktop\gmer.exe
[2011/04/04 00:36:28 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\User\Desktop\HijackThis.exe
[2011/04/04 10:37:29 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-04 00:09:31

< End of report >
The following is Extras.txt
====================

OTL Extras logfile created on: 04/04/2011 10:39:18 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\User\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00001009 | Country: 加拿大 | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 142.09 Gb Total Space | 33.78 Gb Free Space | 23.77% Space Free | Partition Type: NTFS
Drive D: | 143.00 Gb Total Space | 15.02 Gb Free Space | 10.50% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – C:\Users\User\AppData\Local\hke.exe ()
.html [@ = FirefoxHTML] – C:\program files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [kwopen] – "C:\Program Files\KWMUSIC\KwMusic.exe" \dir "%1" (酷我科技)
Directory [kwplaylist] – "C:\Program Files\KWMUSIC\KwMusic.exe" \dirlist "%1" (酷我科技)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WG3Q36F2\ppstreamsetup[1].exe" = C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WG3Q36F2\ppstreamsetup[1].exe:*:Enabled:PPStream Installer
"C:\Program Files\PPStream\PPStream.exe" = C:\Program Files\PPStream\PPStream.exe:*:Enabled:PPS厙釐萇弝 – (PPStream Inc.)
"C:\Program Files\PPStream\PPSAP.exe" = C:\Program Files\PPStream\PPSAP.exe:*:Enabled:PPS 厙釐樓厒 – (PPStream Inc)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12551164-20FF-4891-8921-ADA9A5235566}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{15AA1E2F-EC4C-4BCC-8632-653B1BCB23F0}" = lport=26834 | protocol=6 | dir=in | name=bitcomet 26834 tcp |
"{2E87D2F7-6957-4190-9BF7-0C7F2B239131}" = lport=138 | protocol=17 | dir=in | app=system |
"{39891C4E-BA53-451E-91FD-17881AF37944}" = rport=137 | protocol=17 | dir=out | app=system |
"{44890BAB-4935-48C2-B389-BDA76AAB6ACB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4F5869F6-66B6-4D97-8CE5-ECABEC5B5D82}" = lport=139 | protocol=6 | dir=in | app=system |
"{51D696EB-73F3-470E-9CD8-EE95231ECCC0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{52C7406E-0243-47A9-ACC8-9D2B2D458C26}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{57E27780-3A32-4E14-817A-25E716AE2D4B}" = lport=445 | protocol=6 | dir=in | app=system |
"{5D5855AD-C138-4EED-8256-3F90CAC722B5}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{66E4A03A-0C5B-4EA5-94DD-9CFF6F3EAD86}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{718BE863-1AC4-4302-9E48-DF1CBA7CAC75}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{7B13E142-84A6-4E51-8E66-7A6D9D97C5CF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7BDA2FED-835D-412A-B7F5-B7975AC80724}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9226D79B-146E-4BAC-9B19-6FF1A7EB349D}" = lport=26834 | protocol=17 | dir=in | name=bitcomet 26834 udp |
"{9E446E46-6720-47B6-97EB-4D7E22C1ED12}" = lport=137 | protocol=17 | dir=in | app=system |
"{A229B9F1-0E45-4F56-900B-DA0DA017036B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{A29FDE98-656F-47B8-8FCA-09B2A6BB0550}" = rport=139 | protocol=6 | dir=out | app=system |
"{B03ECE80-4FEE-4C24-9B43-E89CBA1AEF75}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B4DC4C75-3AA4-4764-9B2D-CFEB3A37F8F1}" = rport=138 | protocol=17 | dir=out | app=system |
"{B7255DF6-06FF-4F63-95AE-D00899D719D8}" = rport=445 | protocol=6 | dir=out | app=system |
"{B75002D1-B1C2-4C30-A5EF-6C2537F253E8}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{BBC05B79-183B-49C3-9D4E-EF6F7D71868C}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0889E658-ED70-44D7-BB94-B4D87BDC4E91}" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"{10360008-FED9-437F-AF23-233EE86BF1F5}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{15F87589-EF4F-43F2-BD71-0102FF4AD5FB}" = protocol=17 | dir=in | app=c:\program files\elsword\data\x2.exe |
"{1646E914-8F32-4046-85CD-D53EE91E1DBA}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{1F80D1AD-BA7C-4278-A9B3-245AC71FA1F7}" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"{2EAFB60A-FD8E-4697-B836-9D4E6C2B6D32}" = protocol=17 | dir=in | app=c:\program files\ppstream\ppsap.exe |
"{2F85C8D4-3A6F-4CB4-A2E1-D43AE2DC542D}" = protocol=17 | dir=in | app=c:\program files\kwmusic\kwmv.exe |
"{2F88AB2D-06EA-4078-8162-004D289E5678}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{30AC68E4-73B6-4E10-94F9-1F0DD0D42E59}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{33CB81B4-DBDB-4221-9256-C24B8A5DF2BC}" = protocol=6 | dir=in | app=c:\users\user\documents\steam\steamapps\common\left 4 dead\left4dead.exe |
"{3C8E155F-948D-47D4-BE6E-63E0D369FCDF}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{3EC73C20-A884-48ED-A117-420B00D6E7A8}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{436BE321-E4E2-4174-BFDB-9835E31380CB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{456F800C-8DAE-4FEB-9E92-D6204577AB7F}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty - world at war\codwaw.exe |
"{45A46E5B-AD6A-40E5-AF86-8CAA0F9DF858}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{47CD2FF2-17A3-43C7-B3C1-D87C73097BD3}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{486AF2A9-77DB-46DC-B2AE-2A42010F5AFC}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{489712F7-44F9-4322-851E-25DC115B3964}" = protocol=6 | dir=in | app=c:\program files\ppstream\ppstream.exe |
"{4B1625B2-6144-4518-8A82-204839D901A6}" = protocol=6 | dir=in | app=c:\program files\ppstream\ppstream.exe |
"{4BE37D96-D431-4B87-ACCE-2325078E5067}" = protocol=6 | dir=in | app=c:\program files\elsword\data\x2.exe |
"{4CC47D23-3B3A-4271-A0DD-9EF9C586F924}" = protocol=6 | dir=in | app=c:\users\user\documents\steam\steamapps\[removed]\counter-strike\hl.exe |
"{4D075B2A-AB78-4266-85D1-FC757A55B43C}" = protocol=17 | dir=in | app=c:\program files\kwmusic\kwmusic.exe |
"{501BF449-685C-4C68-B3D8-E1176D1B018E}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{5C413F8E-17EB-4FAE-B793-1FC9E3F2528E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{5DD6EF26-14DA-4BB1-B51F-F16478A88904}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{616E8398-DFDD-4D6D-ACE9-FA3BBB4B94DD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{62A25179-E7EF-4A3B-95D8-4D4E1C8030EA}" = protocol=17 | dir=in | app=d:\pps.tv\ppsgame\ppsgame.exe |
"{63FD5513-704A-4BF8-A9AD-F6999BDB86B5}" = protocol=17 | dir=in | app=c:\program files\sports interactive\football manager 2011 russian\fm.exe |
"{6454FD76-439A-4F63-A28A-23056D9CD3A0}" = protocol=17 | dir=in | app=c:\users\user\documents\steam\steamapps\[removed]\counter-strike\hl.exe |
"{69F89559-BA76-4A56-97CD-736762A48CF7}" = protocol=6 | dir=in | app=c:\program files\kwmusic\kwmusic.exe |
"{7248667B-1D87-4F5A-87A2-D2063738C1BE}" = protocol=6 | dir=in | app=c:\program files\ppstream\ppsap.exe |
"{7A2E2404-5261-413C-B4E7-AB9F944EE5B5}" = protocol=17 | dir=in | app=c:\users\user\documents\steam\steamapps\common\left 4 dead\left4dead.exe |
"{80E90070-9446-4A94-AF11-F13438A982B1}" = protocol=17 | dir=in | app=c:\program files\ppstream\ppsap.exe |
"{83F010C0-2F86-4180-AF17-FB47D0A0745E}" = dir=in | app=c:\program files\cyberlink\powerdvd8\powerdvd8.exe |
"{890A3638-1BC4-4045-8868-BC4C66B3D9D3}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{8AC40FE7-8185-4E8F-BA4A-5F91B29D6E5E}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty - world at war\codwawmp.exe |
"{8EAEC2E9-ECD9-46C1-9A21-C1F3922D5649}" = protocol=6 | dir=in | app=c:\program files\kwmusic\kwmv.exe |
"{9125FC9C-446B-4A8A-82D6-0048E6252F1E}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{95CEDC9D-B62D-42CE-BC03-DCCE91EF96EA}" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"{97574BDD-ACB8-407D-A7D8-992FD6791E62}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{9BABAF0B-1469-46D1-BE23-937FDEFDB65B}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{9D857800-6534-4549-BB02-83948AF45BFF}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{AB1E998C-96A0-4EB2-9E01-675FD65C434F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{ABFB8C9E-D91F-481A-8487-5C702214E9E3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{ADD3B68D-920A-456F-87AC-E77101B1E631}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B148CA0E-23E5-4DF9-A7EF-E5366DE655D6}" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"{B373674B-B597-4AED-ADBD-D33C4D907AE3}" = protocol=6 | dir=in | app=c:\program files\sports interactive\football manager 2011 russian\fm.exe |
"{BA2CB911-DEFD-4F19-9EC7-8B88E1160539}" = protocol=17 | dir=in | app=c:\program files\ppstream\ppstream.exe |
"{BF2E6403-AB1B-4220-976C-2866BE1D3769}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{C0C44FC8-71F7-46CA-BE4A-7CA56F645523}" = protocol=17 | dir=in | app=c:\program files\ppstream\ppstream.exe |
"{C732C8C3-A602-46B1-A46F-A648C88A9E75}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{C880632B-7A00-41BC-9FEE-D6CDDA31D559}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{C8BAC4A2-AD1A-4E58-8688-B98300364F68}" = protocol=17 | dir=in | app=c:\users\user\documents\steam\steamapps\[removed]\counter-strike\hl.exe |
"{CDD9F996-9DB8-4B52-8E76-E1D59669C996}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D6D0BA44-2B5C-42F8-82CA-933A3A7D9B51}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe |
"{DBD1CC64-D9BB-45D6-BA5C-19BD6619439C}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe |
"{E1E9F068-F49F-422D-9314-540792480C1A}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty - world at war\codwaw.exe |
"{E2CD8AF6-C5CE-4DBD-AA14-3010679B6E76}" = protocol=6 | dir=in | app=c:\program files\ppstream\ppsap.exe |
"{E61E99BB-F5D5-419B-8F8C-C14A97B9A203}" = protocol=6 | dir=in | app=d:\pps.tv\ppsgame\ppsgame.exe |
"{EAD00DB3-4911-4156-9B4D-87234571DAF5}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty - world at war\codwawmp.exe |
"{F779F77F-A791-435D-ADFD-AD5EF3E7CB1D}" = protocol=6 | dir=in | app=c:\users\user\documents\steam\steamapps\[removed]\counter-strike\hl.exe |
"{FED1D1B1-0EA6-4C49-B207-D9A838E0ECF1}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"TCP Query User{06E27BA6-2188-4DCD-B3B7-99AF23477A6C}C:\users\user\desktop\pem_0.7.15-0.8.2.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\pem_0.7.15-0.8.2.exe |
"TCP Query User{11F09142-6D15-46B5-BFCF-B14BEB495D85}C:\program files\tvuplayer\tvuplayer.exe" = protocol=6 | dir=in | app=c:\program files\tvuplayer\tvuplayer.exe |
"TCP Query User{16322A05-C453-4554-BA4A-4AFF8887A280}C:\program files\warcraft iii chinese\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii chinese\war3.exe |
"TCP Query User{179F82DE-D7E4-45CA-83B0-414055D3D363}C:\program files\tvants\tvants.exe" = protocol=6 | dir=in | app=c:\program files\tvants\tvants.exe |
"TCP Query User{1BDD16D7-2160-4A49-B960-43A042A831F5}C:\users\user\documents\steam\steamapps\[removed]\day of defeat\hl.exe" = protocol=6 | dir=in | app=c:\users\user\documents\steam\steamapps\[removed]\day of defeat\hl.exe |
"TCP Query User{22217347-ED91-4D0F-812D-DC789348FD79}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{2CA9982C-6C81-48BC-9B7E-DF1A4FA2E835}C:\program files\warcraft iii english\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii english\war3.exe |
"TCP Query User{3BDB4FBA-0150-49F6-AAFD-C7086FBFA205}C:\program files\kwmusic\kwmv.exe" = protocol=6 | dir=in | app=c:\program files\kwmusic\kwmv.exe |
"TCP Query User{3D621104-A9D3-4F17-9ED6-4C900E4ACC92}C:\users\user\appdata\local\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\google\chrome\application\chrome.exe |
"TCP Query User{54FFFEEF-93F6-4A65-888B-BAC6F28BEBA6}C:\program files\steam\steamapps\[removed]\half-life blue shift\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\[removed]\half-life blue shift\hl.exe |
"TCP Query User{6A0B006E-D0EA-41F5-806D-A65EEB5DC201}C:\program files\heroes of newerth\hon.exe" = protocol=6 | dir=in | app=c:\program files\heroes of newerth\hon.exe |
"TCP Query User{6CEAA3A1-7955-440A-AE9E-7E1720068576}C:\program files\tvuplayer\tvuplayer.exe" = protocol=6 | dir=in | app=c:\program files\tvuplayer\tvuplayer.exe |
"TCP Query User{71CAB1ED-B954-4A31-A81A-C879DEDE7C23}C:\program files\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"TCP Query User{72CDF5EA-1905-4B12-9A04-1050F90DC875}C:\program files\tvants\tvants.exe" = protocol=6 | dir=in | app=c:\program files\tvants\tvants.exe |
"TCP Query User{97D81B66-E183-4D8A-9358-1465FB7FFBAE}C:\program files\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"TCP Query User{97F830E9-8E92-430D-AC6F-4906AE26115D}C:\users\user\desktop\lancraft\lancraft.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\lancraft\lancraft.exe |
"TCP Query User{9DCC1894-0576-42C3-BEE0-F64BA273E45D}C:\users\user\desktop\smdl_ob_20101016_0.8.0.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\smdl_ob_20101016_0.8.0.exe |
"TCP Query User{B040DF40-8D0E-487A-9EB7-ABF63E0F5A29}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{B3F12BF2-90AD-4481-AE98-0E5C2369B06A}C:\program files\warcraft iii english\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii english\war3.exe |
"TCP Query User{B83DF663-20F2-4847-9C10-9922678D3C87}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe |
"TCP Query User{C4E68393-E844-4A54-BF65-A7FC81DD4581}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |
"TCP Query User{D39C187E-E4C5-4520-8656-8CD42C0D0706}C:\program files\steam\steamapps\[removed]\counter-strike\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\[removed]\counter-strike\hl.exe |
"TCP Query User{D7BD22EB-FC3B-4126-96E5-A6D7F3818A95}C:\program files\kwmusic\kwmusic.exe" = protocol=6 | dir=in | app=c:\program files\kwmusic\kwmusic.exe |
"TCP Query User{E9E7E0E1-661C-470D-BB1D-4CEE6CCC4002}C:\program files\heroes of newerth\hon.exe" = protocol=6 | dir=in | app=c:\program files\heroes of newerth\hon.exe |
"TCP Query User{F1E97CC4-AE3B-4A9A-B7C0-A7604380D422}C:\program files\warcraft iii chinese\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii chinese\war3.exe |
"TCP Query User{FD0A0FF6-AC07-441D-AFD3-748ABF2A0D7C}C:\program files\steam\steamapps\[removed]\counter-strike\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\[removed]\counter-strike\hl.exe |
"UDP Query User{057B0320-48B6-41D6-8245-67921B75167C}C:\program files\heroes of newerth\hon.exe" = protocol=17 | dir=in | app=c:\program files\heroes of newerth\hon.exe |
"UDP Query User{16A33995-3D1F-4809-9C88-7F6087E8A3FC}C:\program files\tvuplayer\tvuplayer.exe" = protocol=17 | dir=in | app=c:\program files\tvuplayer\tvuplayer.exe |
"UDP Query User{1F07B28C-D83B-49D1-A083-486898E84ABF}C:\program files\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"UDP Query User{1FFA51D7-D0DB-4B40-BD3C-3343E56ED201}C:\program files\steam\steamapps\[removed]\half-life blue shift\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\[removed]\half-life blue shift\hl.exe |
"UDP Query User{2184F7FE-A93D-4D0F-9A87-54C3DCD2EFAB}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{36089889-9D49-46D8-8C3F-E4F40788C6ED}C:\program files\warcraft iii english\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii english\war3.exe |
"UDP Query User{3634CC6C-6848-4B9D-BFCE-8404DDF53E9F}C:\users\user\desktop\pem_0.7.15-0.8.2.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\pem_0.7.15-0.8.2.exe |
"UDP Query User{45619D97-02B5-48B1-9D76-1C160EA5D05D}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe |
"UDP Query User{54841001-08CB-4493-ADF5-379417CBC526}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |
"UDP Query User{58F868F1-1C39-4747-9F0D-EC19A17E2A3A}C:\program files\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"UDP Query User{60350473-18E3-4D95-9015-B61577E55E48}C:\program files\kwmusic\kwmv.exe" = protocol=17 | dir=in | app=c:\program files\kwmusic\kwmv.exe |
"UDP Query User{693A9AD5-3470-4C8E-8EAF-865D6C03BD1D}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{6AF93C13-0F97-44FD-8933-6AAD71B92206}C:\program files\steam\steamapps\[removed]\counter-strike\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\[removed]\counter-strike\hl.exe |
"UDP Query User{75DEF1C0-CD03-4235-8F43-C58E08DC603B}C:\users\user\desktop\lancraft\lancraft.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\lancraft\lancraft.exe |
"UDP Query User{804949CE-E0AC-406A-A472-33E136CEEC0A}C:\program files\warcraft iii english\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii english\war3.exe |
"UDP Query User{8363FEB3-9A1E-4EEE-BCB9-3438D502920B}C:\program files\tvants\tvants.exe" = protocol=17 | dir=in | app=c:\program files\tvants\tvants.exe |
"UDP Query User{94D11FDD-8110-48F7-BFCB-FDDF152D0F42}C:\program files\kwmusic\kwmusic.exe" = protocol=17 | dir=in | app=c:\program files\kwmusic\kwmusic.exe |
"UDP Query User{9B235B81-55FD-47D0-897B-0196F5C3A9B9}C:\program files\heroes of newerth\hon.exe" = protocol=17 | dir=in | app=c:\program files\heroes of newerth\hon.exe |
"UDP Query User{B1A3C6E5-8C42-4FF3-A516-C9FCB036DA9B}C:\program files\warcraft iii chinese\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii chinese\war3.exe |
"UDP Query User{C003A184-FEDB-4A16-B533-4BC668C043B0}C:\program files\tvants\tvants.exe" = protocol=17 | dir=in | app=c:\program files\tvants\tvants.exe |
"UDP Query User{CA45C9AC-D0E5-4F87-8F2E-08D56C21585A}C:\program files\warcraft iii chinese\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii chinese\war3.exe |
"UDP Query User{CFA2DD4F-BC1B-4763-9D62-F1EF87749400}C:\program files\steam\steamapps\[removed]\counter-strike\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\[removed]\counter-strike\hl.exe |
"UDP Query User{D11E2432-29F8-46A5-91CA-A6990DD4987E}C:\users\user\appdata\local\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\google\chrome\application\chrome.exe |
"UDP Query User{EDF85501-75F3-4DBC-9ADD-3FC4A3728E59}C:\users\user\desktop\smdl_ob_20101016_0.8.0.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\smdl_ob_20101016_0.8.0.exe |
"UDP Query User{F04EF17E-86D7-42FA-BAF8-137FA273E2C1}C:\users\user\documents\steam\steamapps\[removed]\day of defeat\hl.exe" = protocol=17 | dir=in | app=c:\users\user\documents\steam\steamapps\[removed]\day of defeat\hl.exe |
"UDP Query User{F32A1AEB-3CEE-4879-A59A-D0C850E9653E}C:\program files\tvuplayer\tvuplayer.exe" = protocol=17 | dir=in | app=c:\program files\tvuplayer\tvuplayer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.1.0.5200
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution III
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live 上載工具
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23C12370-3A82-4558-B727-F345B473AD87}" = BlackBerry Device Software Updater
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32D36E99-46CF-4C1B-B260-368202E0853D}" = Windows Live Call
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E4F8EE0-43EC-4AB9-9A04-702F2AE7E229}" = Windows Live 登入小幫手
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{689E0AB3-50B2-4E5A-9DCE-6DA9F5BE1314}" = BlackBerry?Media Sync
"{68CAE442-579C-4D84-AA5F-253852522ED5}" = PCTroubleshooting
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A1F72DD-2465-43A2-A137-8A849399B7A8}" = REALTEK Wireless LAN Software
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{71A51B59-E7D3-11DB-A386-005056C00008}" = Namuga 1.3M Webcam
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}" = Microsoft SQL Server Native Client
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E106A57-A17E-431D-B48F-175E42EB9F74}" = imagine digital freedom - Samsung
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims?3 Ambitions
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A35682B-4C64-4F37-B1A0-3E21063C80DC}" = Windows Live Messenger
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AA16A9E5-40E9-44F5-801E-6B3D3CFE79E5}" = BatteryLifeExtender
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AED53CDF-1046-4C6B-B5E2-C195125ECDA0}" = Intel® PROSet/Wireless WiFi Software
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
"{B98BE95C-E76F-4246-B8E6-BEB8EE791D06}" = Roxio Media Manager
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims?3
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D5A9DA4B-E4F9-FB49-017D-769FC540F1F0}" = EA Download Manager UI
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E7084B89-69E0-46B3-A118-8F99D06988CD}" = Microsoft SQL Server VSS Writer
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F353BD3E-1BBC-491C-A0A7-A93D6B56FFD4}" = Windows Live 程式集
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"Cisco Connect" = Cisco Connect
"com.ea.Vault.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Download Manager UI
"Cross Fire_is1" = Cross Fire En
"DAEMON Tools Lite" = DAEMON Tools Lite
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"EA Download Manager" = 下載管理員
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FLV Player2.0.25" = FLV Player
"Football Manager 2011 Russian" = Football Manager 2011 Russian
"FP Solutions 2009 Standalone" = FP Solutions 2009 Standalone
"GOM Player" = GOM Player
"hon" = Heroes of Newerth
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"KwMusic" = 蹄扂秞氈碟 2009
"Marvell Miniport Driver" = Marvell Miniport Driver
"McAfee Security Scan" = McAfee Security Scan Plus
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.6
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"NJStar Communicator" = NJStar Communicator
"NVIDIA Drivers" = NVIDIA Drivers
"ObjectDock" = ObjectDock
"PPSGame" = PPS蚔牁 V1.0.1.322
"PPStream" = PPStream V2.7.0.1212 Final
"ProInst" = Intel PROSet Wireless
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 12.0" = RealPlayer
"Samsung ML-2240 Series" = Samsung ML-2240 Series
"Slice" = Slice Audio File Splitter
"SopCast" = SopCast 3.3.2
"Steam App 10" = Counter-Strike
"Steam App 130" = Half-Life: Blue Shift
"Steam App 17410" = Mirror's Edge
"Steam App 30" = Day of Defeat
"Steam App 500" = Left 4 Dead
"Switch" = Switch Sound File Converter
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 5" = TeamViewer 5
"Tibia_is1" = Tibia
"TVAnts 1.0" = TVAnts 1.0
"Warcraft III" = Warcraft III
"WavePad" = WavePad Sound Editor
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinLiveSuite_Wave3" = Windows Live 程式集
"WinRAR archiver" = WinRAR archiver
"x264 Revision 483 x264.nl" = x264 Revision 483 x264.nl (remove only)
"Xfire" = Xfire (remove only)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Smilebox" = Smilebox
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 13/02/2011 3:55:07 PM | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = "C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll" 的啟用內容產生失敗。 找不到依存組合
Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"。
請使用
sxstrace.exe 進行詳細的診斷。

Error - 13/02/2011 3:55:13 PM | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = "C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll" 的啟用內容產生失敗。 找不到依存組合
Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"。
請使用
sxstrace.exe 進行詳細的診斷。

Error - 13/02/2011 3:59:33 PM | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = "C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll" 的啟用內容產生失敗。 找不到依存組合
Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"。
請使用
sxstrace.exe 進行詳細的診斷。

Error - 13/02/2011 4:01:28 PM | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = "C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll" 的啟用內容產生失敗。 找不到依存組合
Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"。
請使用
sxstrace.exe 進行詳細的診斷。

Error - 14/02/2011 2:06:29 PM | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = 失敗的應用程式 GOM.exe,版本 2.1.28.5039,時間戳記 0x4cd8f983,失敗的模組 GVF.ax,版本 0.0.0.0,時間戳記
0x4c6c873b,例外狀況碼 0xc0000005,錯誤位移 0x0003e8bc, 處理程序識別碼 0x1b4c,應用程式開始時間 0x01cbcc70cf4aa450。

Error - 16/02/2011 12:33:15 AM | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = "C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll" 的啟用內容產生失敗。 找不到依存組合
Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"。
請使用
sxstrace.exe 進行詳細的診斷。

Error - 17/02/2011 5:55:32 PM | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = "C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll" 的啟用內容產生失敗。 找不到依存組合
Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"。
請使用
sxstrace.exe 進行詳細的診斷。

Error - 17/02/2011 5:55:58 PM | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = "C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll" 的啟用內容產生失敗。 找不到依存組合
Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"。
請使用
sxstrace.exe 進行詳細的診斷。

Error - 17/02/2011 5:55:58 PM | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = "C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll" 的啟用內容產生失敗。 找不到依存組合
Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"。
請使用
sxstrace.exe 進行詳細的診斷。

Error - 17/02/2011 5:58:55 PM | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = "C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll" 的啟用內容產生失敗。 找不到依存組合
Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"。
請使用
sxstrace.exe 進行詳細的診斷。

[ System Events ]
Error - 31/12/2009 7:08:02 AM | Computer Name = User-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 31/12/2009 7:08:02 AM | Computer Name = User-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 31/12/2009 7:08:21 AM | Computer Name = User-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 31/12/2009 7:08:21 AM | Computer Name = User-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 01/01/2010 8:24:48 PM | Computer Name = User-PC | Source = bowser | ID = 8003
Description =

Error - 02/01/2010 7:05:30 AM | Computer Name = User-PC | Source = DCOM | ID = 10005
Description =

Error - 02/01/2010 7:05:30 AM | Computer Name = User-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 02/01/2010 7:05:30 AM | Computer Name = User-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 02/01/2010 7:05:30 AM | Computer Name = User-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 02/01/2010 7:05:30 AM | Computer Name = User-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
Windows force shutdown the gmer.exe scan even in safe mode. However I was able to restart my computer into regular screen.
Windows force shutdown the gmer.exe scan even in safe mode. However I was able to restart my computer into regular screen.
Sandrock

It is not surprising that your computer is infected due to the use of peer to peer software plus the lack of evidence of an active antivirus or firewall.

Unfortunately, one or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would suggest that you disconnect this PC from the Internet when you are not using it to download programs we request. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall


I can help you in the cleaning if you don't want to reformat but I can't promise that we'll get you 100% clean.

Please let us know what you have decided to do in your next post.

Please do nothing about antivirus or firewall until we are finished cleaning your computer.

===================================================

If you wish to continue, please do the following:

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

When you've done this, please try running GMER again but this time uncheck everything EXCEPT "Sections" and "C:\" .

Thanks

Satchfan
Hi there, as suggested, I will reformat my computer. However, should I still be cleaning the virus/trojan? Or should I begin saving files I want to keep into my storage drive and format my computer? Thanks so much for your help! Here is the log for gmer attached.

====
edited:

it says im not allowed to upload these type of files. So I'll just copy and paste the log here

GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-05 10:09:51
Windows 6.0.6001 Service Pack 1
Running: gmer.exe; Driver: C:\Users\User\AppData\Local\Temp\kxldapob.sys


—- Kernel code sections - GMER 1.0.15 —-

.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8EC08320, 0x3EEB57, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[3528] ntdll.dll!LdrLoadDll 77AB79B3 5 Bytes JMP 013413F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- EOF - GMER 1.0.15 —-
Hi sandrock

Hi there, as suggested, I will reformat my computer. However, should I still be cleaning the virus/trojan?

I did not suggest formatting, it is just an option when you have an infection such as this. We could very likely clean your computer of this infection but I need to point out the possibilities.

If you decide to reformat there is no need to clean up the infection as it will not survive a format.

You can find instructions on how to reformat here. Please print out the instructions so you can follow them as needed during your reformat.

===================================================

After reinstalling the operating system you will want to visit Microsoft's Windows Update Site at http://www.windowsupdate.com. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Please remember, if data was backed up prior to the format, before placing that data back into a clean hard drive, have it scanned with AntiVirus programs. Use more than one program, since AntiVirus scanners use databases that are not identical, and one may find malware that another does not. If the data is reported as clean after running a few virus scans (IMO would use three or more), it should be safe to place it in the clean hard drive.

===================================================

Some additional information you should consider:

AntiVirus Software

You had no active antivirus on your computer. It is very important that your computer has an anti-virus software running.: this alone can save you a lot of trouble with malware in the future. It is imperative that you update your Antivirus software at least once a week, (even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Here are some of the better AV products.

Download and install one of the following free antivirus programs: • AVG 2011 Free
• Free Avast Home Edition
• Avira AntiVir® Personal Edition Classic
• Microsoft Security Essentials
===================================================

Please let me know if you have any more questions.

Satchfan
Hi Satchfan, Since I want to make sure the trojan is 100% cleaned form my system, I decided to do a system restore on my Samsung laptop. I've now finish the restoration and did a hijackthis scan, just want to make sure the system is clean. I've also downloaded avast! home anti virus. here is the hijackthis log =================== Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:11:13, on 6/4/2011 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\rundll32.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\rundll32.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\User\Desktop\HijackThis.exe C:\Program Files\Mozilla Firefox\plugin-container.exe O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.0" O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0" O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe" O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe" O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerProducer" update "Software\CyberLink\PowerProducer\5.0" O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: 傳送影像到 Bluetooth 裝置(&B)… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: 傳送頁面到 Bluetooth 裝置(&B)… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O15 - ESC Trusted Zone: http://*.update.microsoft.com O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: IntelR PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: IntelR PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: Rezip - Unknown owner - C:\Windows\SYSTEM32\Rezip.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe – End of file - 5686 bytes
Hi sandrock It's late here now and I have an early start tomorrow but I'll have a look at your log and reply tomorrow Satchfan
Hi sandrock

Your HijackThis log looks clean but that is not looking deep enough. We need to look deeper to make sure that there are no infections.

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan
Hi Satchfan, here's the combofix log:

ComboFix 11-04-06.03 - User 4/2011 星期四 10:56:05.1.2 - x86
執行位置: c:\users\User\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( 2011-03-07 至 2011-04-07 的新的檔案 )))))))))))))))))))))))))))))))
.
.
2011-04-07 03:00 . 2011-04-07 03:00 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-04-06 05:56 . 2008-10-09 20:52 452440 —-a-w- c:\windows\system32\d3dx10_40.dll
2011-04-06 05:56 . 2008-10-09 20:52 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2011-04-06 05:56 . 2008-10-09 20:52 2036576 —-a-w- c:\windows\system32\D3DCompiler_40.dll
2011-04-06 05:56 . 2007-04-04 10:53 81768 —-a-w- c:\windows\system32\xinput1_3.dll
2011-04-06 05:55 . 2011-04-06 08:27 ——– d—–w- c:\program files\Heroes of Newerth
2011-04-06 05:34 . 2011-04-06 05:34 ——– d—–w- c:\users\User\AppData\Local\ODUI
2011-04-06 05:34 . 2011-04-06 05:34 ——– d—–w- c:\users\User\AppData\Roaming\Stardock
2011-04-06 05:33 . 2011-04-06 05:33 ——– d—–w- c:\users\User\AppData\Local\Stardock
2011-04-06 05:33 . 2011-04-06 05:33 ——– dc-h–w- c:\programdata\{5486EA6B-AF91-4B4B-868E-F80AB4BCD83A}
2011-04-06 05:33 . 2011-04-06 05:33 ——– d—–w- c:\program files\Stardock
2011-04-06 05:33 . 2011-04-06 05:33 ——– d—–w- c:\users\User\AppData\Local\PackageAware
2011-04-06 05:27 . 2011-04-06 05:28 ——– d—–w- c:\users\User\AppData\Roaming\Tibia
2011-04-06 05:23 . 2011-04-06 05:24 ——– d—–w- c:\program files\Warcraft III English
2011-04-06 05:22 . 2011-04-06 05:23 ——– d—–w- c:\program files\Warcraft III Chinese
2011-04-06 05:22 . 2011-04-06 05:47 ——– d—–w- C:\Tibia
2011-04-06 05:20 . 2011-04-06 05:21 ——– d—–w- c:\users\User\AppData\Roaming\NJStar
2011-04-06 05:20 . 2011-04-06 05:20 ——– d—–w- c:\program files\NJStar Communicator
2011-04-06 05:19 . 2011-04-06 05:19 ——– d—–w- c:\program files\GRETECH
2011-04-06 05:15 . 2011-04-06 05:15 ——– d—–w- c:\windows\LastGood
2011-04-06 04:59 . 2011-02-23 14:56 301528 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-06 04:59 . 2011-02-23 14:54 19544 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-04-06 04:59 . 2011-02-23 14:56 371544 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-06 04:59 . 2011-02-23 14:55 49240 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-06 04:59 . 2011-02-23 14:55 25432 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-06 04:59 . 2011-02-23 14:55 53592 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-04-06 04:55 . 2011-02-23 15:04 40648 —-a-w- c:\windows\avastSS.scr
2011-04-06 04:55 . 2011-02-23 15:04 190016 —-a-w- c:\windows\system32\aswBoot.exe
2011-04-06 04:55 . 2011-04-06 04:55 ——– d—–w- c:\programdata\AVAST Software
2011-04-06 04:55 . 2011-04-06 04:55 ——– d—–w- c:\program files\AVAST Software
2011-04-06 04:47 . 2011-04-06 04:48 ——– d—–w- c:\program files\Common Files\Adobe
2011-04-06 04:27 . 2011-03-23 02:11 6792528 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A71D3F1F-15E9-4AD4-B8CA-B497DE7CE3BC}\mpengine.dll
2011-04-06 04:27 . 2011-02-02 10:11 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-04-06 04:06 . 2011-04-06 04:06 ——– d—–w- c:\users\User\AppData\Local\Mozilla
2011-04-06 04:00 . 2009-08-07 02:24 44768 —-a-w- c:\windows\system32\wups2.dll
2011-04-06 04:00 . 2009-08-07 02:24 53472 —-a-w- c:\windows\system32\wuauclt.exe
2011-04-06 04:00 . 2009-08-07 02:23 1929952 —-a-w- c:\windows\system32\wuaueng.dll
2011-04-06 04:00 . 2009-08-07 01:45 2421760 —-a-w- c:\windows\system32\wucltux.dll
2011-04-06 03:59 . 2009-08-07 02:24 35552 —-a-w- c:\windows\system32\wups.dll
2011-04-06 03:59 . 2009-08-07 02:23 575704 —-a-w- c:\windows\system32\wuapi.dll
2011-04-06 03:59 . 2009-08-07 01:44 87552 —-a-w- c:\windows\system32\wudriver.dll
2011-04-06 03:59 . 2009-08-06 11:23 171608 —-a-w- c:\windows\system32\wuwebv.dll
2011-04-06 03:59 . 2009-08-06 10:44 33792 —-a-w- c:\windows\system32\wuapp.exe
2011-04-06 03:57 . 2011-04-06 04:47 ——– d—–w- c:\users\User\AppData\Local\Adobe
.
.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-18 18:08 . 2011-04-06 04:06 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-21 2153472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-24 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-24 92704]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-12-11 6703648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-28 1049896]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-12-24 103720]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
"UpdatePDRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-01-04 222504]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2009-04-15 91432]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2009-04-15 50472]
"UpdatePPShortCut"="c:\program files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2009-03-12 210216]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockFree\ObjectDock.exe [2010-10-7 3768176]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-11 752168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockFree\ODMenu.dll" [2010-10-04 511344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
S2 KMDFMEMIO;SAMSUNG Kernel Driver;c:\windows\system32\DRIVERS\kmdfmemio.sys [2006-11-14 13312]
S2 Rezip;Rezip;c:\windows\SYSTEM32\Rezip.exe [2009-03-05 311296]
S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe [2008-01-21 21504]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-07-31 29736]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-06-25 3662848]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-09-05 45600]
S3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\Drivers\VMC326.sys [2008-11-21 238464]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
yksvcs REG_MULTI_SZ yksvc
.
.
——- 而外的掃描 ——-
.
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SMSN&bmod=SMSN
IE: 傳送影像到 Bluetooth 裝置(&B)… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: 傳送頁面到 Bluetooth 裝置(&B)… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\hg5tgdnq.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-07 11:00
Windows 6.0.6001 Service Pack 1 NTFS
.
掃描被隱藏的進程 …
.
掃描被隱藏的啟動組 …
.
掃描被隱藏的文件 …
.
掃描完成
被隱藏的檔案: 0
.
**************************************************************************
.
——————— 運行進程下的動態鏈接庫 ———————
.
- - - - - - - > 'Explorer.exe'(4936)
c:\windows\system32\btmmhook.dll
c:\program files\NJStar Communicator\Njhook32.dll
c:\program files\NJStar Communicator\NJDBCS32.DLL
c:\program files\NJStar Communicator\NJTEXT32.DLL
c:\program files\Stardock\ObjectDockFree\ODMenu.dll
.
完成時間: 2011-04-07 11:01:39
ComboFix-quarantined-files.txt 2011-04-07 03:01
.
Pre-Run: 106,023,698,432 bytes free
Post-Run: 105,691,119,616 bytes free
.
- - End Of File - - 946B43113AEDEA66308B311305DF23B0

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI