This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Virus

68 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Need help getting rid of this virus. AVG doesn't seem to be able to get rid of it.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:45:29 PM, on 10/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Applications\iebtm.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Applications\iebtmm.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://windiwsfsearch.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://windiwsfsearch.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: 675873 helper - {030A0F33-5B99-482E-83F5-2EEB8457878B} - C:\WINDOWS\system32\675873\675873.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: VirRLWarningBHO Class - {A81EBFD7-0FA3-41ec-B60D-6DAE78B4D31A} - C:\Program Files\VirRL2009\VirRLWarning.dll
O2 - BHO: (no name) - {BE1A344F-9FF5-4024-949B-52205E6DB2D0} - C:\Program Files\Applications\iebt.dll (file missing)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Internet Service - {144A6B24-0EBC-4D89-BF09-A06A718E57B5} - C:\Program Files\Applications\iebr.dll (file missing)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [VirRL2009] "C:\Program Files\VirRL2009\VirRL2009.exe"
O4 - HKLM\..\Policies\Explorer\Run: [smile] C:\Program Files\Applications\wcs.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\Applications\iebtm.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.howtoiexplorer.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.howtoiexplorer.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.download.com
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {0B96BF84-DA5C-46F4-A7FC-5319CFF74163} (MnetLauncher Control) - http://player.mnet.com/package/cjmuset.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} (DaumBGMCtrl Class) - http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-2062e4c29cecd973.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} - http://www.maxmp3.co.kr/Ver2/App/totalApp/…r/maxhelper.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://cafeimg.hanmail.net/cto/1_2_3_5/xman.cab?ver=1,2,3,5
O16 - DPF: {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} (BugsInstallEx Control) - http://install.bugs.co.kr/install/BugsInstallerEx.cab
O16 - DPF: {BFB6D72C-1030-47E4-88A2-614ACCC92467} (MaxMp3VSet Class) - http://www.maxmp3.co.kr/MaxMP3/Html/MPlaye…ge/p3mxvset.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} (MultiUpload Control) - http://www.clubbox.co.kr/neo.fld/MultiUpload.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O22 - SharedTaskScheduler: headstock - {e517b912-2c97-4a94-8b15-e7fe902b8d86} - C:\WINDOWS\system32\dvxwfz.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 9275 bytes
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Please download SmitfraudFix (by S!Ri) to your Desktop.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.



Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - App Paths, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, File - Lop Check, File - Purity Scan, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
phew, that took a while.
thx so much for helping me out :]
p.s. how do i change my time back to normal?


SmitFraudFix v2.365

Scan done at 18:35:44.96, Sun 10/19/2008
Run from C:\Documents and Settings\winxp\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e517b912-2c97-4a94-8b15-e7fe902b8d86}"="headstock"

[HKEY_CLASSES_ROOT\CLSID\{e517b912-2c97-4a94-8b15-e7fe902b8d86}\InProcServer32]
@="C:\WINDOWS\system32\dvxwfz.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{e517b912-2c97-4a94-8b15-e7fe902b8d86}\InProcServer32]
@="C:\WINDOWS\system32\dvxwfz.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\system32\dvxwfz.dll -> Hoax.Win32.Renos.gen.p
C:\WINDOWS\system32\dvxwfz.dll -> Deleted


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\1024\ Deleted
C:\Documents and Settings\winxp\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusResponse Lab 2009 2.1.lnk Deleted
C:\DOCUME~1\winxp\STARTM~1\VirusResponse Lab 2009 2.1.lnk Deleted
C:\DOCUME~1\winxp\STARTM~1\Programs\VirusResponse Lab 2009 2.1 Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Antivirus Scan.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Spyware Test.url Deleted
C:\Program Files\Applications\ Deleted
C:\Program Files\virrl2009\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

AntiXPVSTFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» RK


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{999D8D0E-013B-4045-B84E-DCE6010AABE2}: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{999D8D0E-013B-4045-B84E-DCE6010AABE2}: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{999D8D0E-013B-4045-B84E-DCE6010AABE2}: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End






OTScanIt2 logfile created on: 10/19/2008 6:45:44 PM - Run 1
OTScanIt2 by OldTimer - Version 1.0.0.17b	 Folder = C:\Documents and Settings\winxp\Desktop\OTScanIt2
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
511.29 Mb Total Physical Memory | 330.68 Mb Available Physical Memory | 64.68% Memory free
1.22 Gb Paging File | 1.15 Gb Available in Paging File | 94.46% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 92.84 Gb Free Space | 62.29% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: WINXP-A88C7D920
Current User Name: winxp
Logged in as Administrator.
 
Current Boot Mode: SafeMode
Scan Mode: Current user
Whitelist: On
File Age = 90 Days
 
[Processes - Safe List]
notepad.exe -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | —- | M] (Microsoft Corporation)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/10/18 12:23:46 | 00,417,280 | —- | M] (OldTimer Tools)
 
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/07/22 20:42:12 | 00,116,040 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation)
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2evxx.exe -> [2007/08/21 21:57:14 | 00,487,424 | —- | M] (ATI Technologies Inc.)
(ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2sgag.exe -> [2007/08/21 21:05:00 | 00,593,920 | —- | M] ()
(avg8emc) AVG Free8 E-mail Scanner [Win32_Own | Auto | Stopped] -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2008/09/30 15:13:43 | 00,875,288 | —- | M] (AVG Technologies CZ, s.r.o.)
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Stopped] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/09/30 15:13:41 | 00,231,704 | —- | M] (AVG Technologies CZ, s.r.o.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Stopped] ->  -> File not found
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation)
(InCDsrv) InCD Helper [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Ahead\InCD\InCDsrv.exe -> [2005/06/10 18:19:38 | 00,869,888 | —- | M] (Nero AG)
(iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/07/30 10:47:48 | 00,532,264 | —- | M] (Apple Inc.)
(MDM) Machine Debug Manager [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 00:25:00 | 00,322,120 | —- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 13:28:22 | 00,089,136 | —- | M] (Microsoft Corporation)
(PnkBstrA) PnkBstrA [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\PnkBstrA.exe -> [2008/01/05 22:24:53 | 00,066,872 | —- | M] ()
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\MSN Messenger\usnsvc.exe -> [2007/01/19 12:54:14 | 00,097,136 | —- | M] (Microsoft Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\alcxwdm.sys -> [2008/01/24 16:36:16 | 04,127,488 | R— | M] (Realtek Semiconductor Corp.)
(ASPI) Advanced SCSI Programming Interface Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ASPI32.SYS -> [2002/07/17 10:05:10 | 00,016,512 | —- | M] (Adaptec)
(ASPI32) ASPI32 [Kernel | System | Stopped] -> %SystemRoot%\System32\drivers\ASPI32.SYS -> [2002/07/17 10:05:10 | 00,016,512 | —- | M] (Adaptec)
(ati2mtag) ati2mtag [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ati2mtag.sys -> [2007/08/21 22:07:39 | 02,417,664 | —- | M] (ATI Technologies Inc.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Stopped] -> %SystemRoot%\system32\drivers\avgldx86.sys -> [2008/09/30 15:13:58 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Stopped] -> %SystemRoot%\system32\drivers\avgmfx86.sys -> [2008/09/30 15:13:57 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgTdiX) AVG Free8 Network Redirector [Kernel | Auto | Stopped] -> %SystemRoot%\system32\drivers\avgtdix.sys -> [2008/09/30 15:14:01 | 00,076,040 | —- | M] (AVG Technologies CZ, s.r.o.)
(FsVga) FsVga [Kernel | System | Running] -> %SystemRoot%\system32\drivers\fsvga.sys -> [2004/08/04 08:00:00 | 00,012,160 | —- | M] (Microsoft Corporation)
(GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> [2008/01/29 12:01:28 | 00,016,168 | —- | M] (GEAR Software Inc.)
(ialm) ialm [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ialmnt5.sys -> [2004/11/01 21:27:20 | 00,773,565 | R— | M] (Intel Corporation)
(InCDfs) InCD File System [File_System | Disabled | Stopped] -> %SystemRoot%\System32\drivers\InCDfs.sys -> [2005/06/10 18:12:12 | 00,099,584 | —- | M] (Nero AG)
(InCDPass) InCDPass [Kernel | System | Running] -> %SystemRoot%\system32\drivers\InCDpass.sys -> [2005/06/10 18:11:50 | 00,029,696 | —- | M] (Nero AG)
(incdrm) InCD Reader [Kernel | System | Running] -> %SystemRoot%\System32\drivers\InCDrm.sys -> [2005/06/10 10:11:44 | 00,028,160 | —- | M] (Nero AG)
(pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pfc.sys -> [2003/12/05 05:46:36 | 00,010,368 | —- | M] (Padus, Inc.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2004/08/04 08:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> [2007/03/29 03:00:00 | 00,043,528 | —- | M] (Sonic Solutions)
(RTL8023xp) Realtek 10/100/1000 NIC Family all in one NDIS XP Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Rtlnicxp.sys -> [2005/03/03 23:10:26 | 00,074,496 | R— | M] (Realtek Semiconductor Corporation						   )
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\RTL8139.sys -> [2004/08/03 18:31:34 | 00,020,992 | —- | M] (Realtek Semiconductor Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(STEC3) STEC3 [Kernel | Auto | Stopped] -> %SystemRoot%\system32\STEC3.sys -> [2007/11/27 17:38:48 | 00,002,368 | —- | M] (AntiCracking)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usbaapl.sys -> [2008/07/22 20:32:44 | 00,032,000 | —- | M] (Apple, Inc.)
(USB_RNDIS_XP) Westell WireSpeed Dual Connect Modem [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usb8023.sys -> [2008/04/13 14:56:49 | 00,012,800 | —- | M] (Microsoft Corporation)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\windows\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> 
HKEY_LOCAL_MACHINE\: Search\\"" ->  -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
HKEY_LOCAL_MACHINE\: SearchURL\\"" ->  -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\windows\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> 
HKEY_CURRENT_USER\: SearchURL\\"" -> http://home.microsoft.com/access/autosearch.asp?p=%s -> 
HKEY_CURRENT_USER\: SearchURL\\"provider" ->  -> 
HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> 
HKEY_CURRENT_USER\: "ProxyOverride" -> 127.0.0.1;*.local -> 
< HOSTS File > (27 bytes and 1 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
127.0.0.1	   localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{030A0F33-5B99-482E-83F5-2EEB8457878B} [HKLM] -> %SystemRoot%\system32\675873\675873.dll [675873 Class] -> File not found
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2008/09/30 15:13:47 | 00,455,960 | —- | M] (AVG Technologies CZ, s.r.o.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_10\bin\ssv.dll [SSVHelper Class] -> [2006/11/09 16:21:52 | 00,440,056 | —- | M] (Sun Microsystems, Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{D0943516-5076-4020-A3B5-AEFAF26AB263}" [HKLM] -> %ProgramFiles%\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [Veoh Browser Plug-in] -> [2008/02/22 21:31:18 | 00,352,256 | —- | M] (Veoh Networks Inc)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{144A6B24-0EBC-4D89-BF09-A06A718E57B5}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2008/10/01 09:38:16 | 01,234,712 | —- | M] (AVG Technologies CZ, s.r.o.)
"IMJPMIG8.1" -> %SystemRoot%\ime\imjp8_1\imjpmig.exe ["C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] -> [2004/08/04 08:00:00 | 00,208,952 | —- | M] (Microsoft Corporation)
"iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/07/30 10:47:56 | 00,289,064 | —- | M] (Apple Inc.)
"MSConfig" -> %SystemRoot%\pchealth\helpctr\binaries\msconfig.exe [C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto] -> [2008/04/13 20:12:27 | 00,169,984 | —- | M] (Microsoft Corporation)
"MSPY2002" -> %SystemRoot%\system32\IME\PINTLGNT\IMSCINST.EXE [C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC] -> [2004/08/04 08:00:00 | 00,059,392 | —- | M] ()
"PHIME2002A" -> %SystemRoot%\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2004/08/04 08:00:00 | 00,455,168 | —- | M] (Microsoft Corporation)
"PHIME2002ASync" -> %SystemRoot%\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> [2004/08/04 08:00:00 | 00,455,168 | —- | M] (Microsoft Corporation)
"SoundMan" -> %SystemRoot%\soundman.exe [SOUNDMAN.EXE] -> [2007/04/16 15:28:22 | 00,577,536 | —- | M] (Realtek Semiconductor Corp.)
"StartCCC" -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ["C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"] -> [2006/11/10 12:35:24 | 00,090,112 | —- | M] ()
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
< winxp Startup Folder > -> C:\Documents and Settings\winxp\Start Menu\Programs\Startup -> 
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer -> 
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [227] -> File not found
\\"NoDrives" ->  [0] -> File not found
\\"NoDriveAutoRun" ->  [67108863] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"HideLegacyLogonScripts" ->  [0] -> File not found
\\"HideLogoffScripts" ->  [0] -> File not found
\\"RunLogonScriptSync" ->  [1] -> File not found
\\"RunStartupScriptSync" ->  [0] -> File not found
\\"HideStartupScripts" ->  [0] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"HideLegacyLogonScripts" ->  [0] -> File not found
\\"HideLogoffScripts" ->  [0] -> File not found
\\"HideStartupScripts" ->  [0] -> File not found
\\"RunLogonScriptSync" ->  [1] -> File not found
\\"RunStartupScriptSync" ->  [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&D&ownload &with BitComet -> %ProgramFiles%\BitComet\BitComet.exe [res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com)
&D&ownload all video with BitComet -> %ProgramFiles%\BitComet\BitComet.exe [res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com)
&D&ownload all with BitComet -> %ProgramFiles%\BitComet\BitComet.exe [res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com)
E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2008/08/04 16:12:50 | 10,354,176 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_10\bin\NPJPI150_10.dll [Menu: Sun Java Console] -> [2006/11/09 16:21:53 | 00,075,528 | —- | M] (Sun Microsystems, Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2007/04/19 14:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 19:26:26 | 00,947,472 | —- | M] (Microsoft Corporation)
CmdMapping\\"{867AB302-E62F-4e8e-B297-6444A9C81D09}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{9034A523-D068-4BE8-A284-9DF278BE776E}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 14:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4836 domain(s) found. -> 
46 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4880 domain(s) found. -> 
download.com .[*]-> Trusted sites ->
www_google.com [https] -> Trusted sites -> 48 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 37 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=67633[Office Genuine Advantage Validation Tool] -> {0B96BF84-DA5C-46F4-A7FC-5319CFF74163} [HKLM] -> http://player.mnet.com/package/cjmuset.cab[MnetLauncher Control] -> {0CCA191D-13A6-4E29-B746-314DEE697D83} [HKLM] -> http://upload.facebook.com/controls/FacebookPhotoUploader5.cab[Facebook Photo Uploader 5] -> {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} [HKLM] -> http://www.musicnotes.com/download/mnviewer.cab[Musicnotes Viewer] -> {166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab[Shockwave ActiveX Control] -> {17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=39204[Windows Genuine Advantage Validation Tool] -> {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} [HKLM] -> http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB[Tpwin Control] -> {20A60F0D-9AFA-4515-A0FD-83BD84642501} [HKLM] -> http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab[Checkers Class] -> {5C051655-FCD5-4969-9182-770EA5AA5565} [HKLM] -> http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab[Solitaire Showdown Class] -> {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} [HKLM] -> http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab[DaumBGMCtrl Class] -> {7FC1B346-83E6-4774-8D20-1A6B09B0E737} [HKLM] -> http://cid-2062e4c29cecd973.spaces.live.com/PhotoUpload/MsnPUpld.cab[Windows Live Photo Upload Control] -> {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} [HKLM] -> http://www.maxmp3.co.kr/Ver2/App/totalApp/maxhelper/maxhelper.cab[Reg Error: Key does not exist or could not be opened.] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {938527D1-CDB7-4147-998A-B20FCA5CC976} [HKLM] -> http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10[Cdmcco Class] -> {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} [HKLM] -> http://cafeimg.hanmail.net/cto/1_2_3_5/xman.cab?ver=1,2,3,5[Daum ActiveX manager Class] -> {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} [HKLM] -> http://install.bugs.co.kr/install/BugsInstallerEx.cab[BugsInstallEx Control] -> {BFB6D72C-1030-47E4-88A2-614ACCC92467} [HKLM] -> http://www.maxmp3.co.kr/MaxMP3/Html/MPlayer/Movie/__P2P__/Package/p3mxvset.cab[MaxMp3VSet Class] -> {C3F79A2B-B9B4-4A66-B012-3EE46475B072} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab[MessengerStatsClient Class] -> {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab[Java Plug-in 1.5.0_06] -> {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} [HKLM] -> http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab[Minesweeper Flags Class] -> {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} [HKLM] -> http://www.clubbox.co.kr/neo.fld/MultiUpload.cab[MultiUpload Control] -> Microsoft XML Parser for Java [HKLM] -> file://C:\WINDOWS\Java\classes\xmldso.cab[Reg Error: Key does not exist or could not be opened.] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {071D6C45-70FF-4BAF-A962-2492D96B0B6F} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {0A2B9F81-D36A-46CE-8E0B-4700F7709A2B} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {200DD75C-B1D1-49D6-BB6E-79C452CFD4BC} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {286AF6EB-159D-4E76-8AA6-289F273CDF40} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {3075C271-0468-46ED-8465-57D461DCA6CA} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {31542321-274D-4BE1-87C2-6D900C548D20} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {360F233C-3A83-43D1-83A9-A990E66E7007} -> () -> {3839BC48-2BD9-4C36-90C3-BD799DC43DAF} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {38DC29AB-CDDA-4FD0-BCF9-E57929BD9148} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {3B26581C-74C6-4FDA-861E-A40A8FD76B85} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {41999A77-3DE0-44A6-95F5-2A146BA5752A} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {48EDF500-2504-4497-8C0F-5AC6D497B85F} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {4A0ADBC5-EF89-49BC-9246-AA7FE6FE99C0} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {522D2FCE-D13F-41A8-9D27-4630B0EDB16A} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {6BFECF85-09E9-4B7C-BE38-41DC51E48595} -> (1394 Net Adapter) -> {6DE86882-D361-4474-B718-9A7D03892B04} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {75BDDF19-2423-46A9-BF6A-3DEC91CE8F32} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {786699C2-7332-4173-847E-72D757B4FFFF} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {903A496C-52C8-4FB0-9F77-92886AD6F864} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {999D8D0E-013B-4045-B84E-DCE6010AABE2} -> (Westell WireSpeed Dual Connect Modem) -> {9F1B87A7-4840-4940-A317-20636963E260} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {A0B94B5F-1FAA-4CFE-A670-0690221E447F} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {A5A49757-DF49-47F9-972A-A104F92F3FB0} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {A5F8252B-7A53-4B3E-A4F2-3F9E011D2EB8} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {B187D059-C994-477B-B0D0-AF4A61FD0B57} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {B2802976-A05F-427D-8524-274EB9C17B5E} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {B2EE89A9-69F3-4CF7-AD6F-BD5FBF32405C} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {B631C3C0-4499-4E2F-8527-8D865C0D4C50} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {BA012AB4-72DF-4939-86C5-93CE8FEBF682} -> (1394 Net Adapter) -> {C0BC3CD5-5184-42FB-88F7-D860D88D20E2} -> () -> {DBDA3452-D2F5-40F8-A387-9C470D6E2D1C} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {F3F10CFF-2B61-42F1-96F9-D9D3091566FC} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {F7BDF2D4-8AEC-43F3-A8D5-A50E69C69EED} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {F8D71487-3173-478F-B0E6-8BFD0911B767} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll -> [2007/08/21 21:58:42 | 00,122,880 | —- | M] (ATI Technologies Inc.) igfxcui -> %SystemRoot%\system32\igfxsrvc.dll -> [2004/11/01 20:59:20 | 00,348,160 | R— | M] (Intel Corporation) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | —- | M] (Microsoft Corporation) "C:\Program Files\AIM\aim.exe" -> C:\Program Files\AIM\aim.exe [C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger] -> File not found "C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe [C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe:*:Enabled:AOL Services] -> [2005/08/02 15:33:02 | 00,151,640 | —- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 03:17:27 | 00,010,800 | —- | M] (AOL LLC) "C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | —- | M] (Microsoft Corporation) "C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme" -> C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme [C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme:*:Enabled:GunBound] -> [2008/05/16 16:08:10 | 01,359,872 | —- | M] (Softnyx) "C:\ijji\ENGLISH\u_gbound.exe" -> C:\ijji\ENGLISH\u_gbound.exe [C:\ijji\ENGLISH\u_gbound.exe:*:Enabled:] -> [2008/05/19 22:06:06 | 00,868,352 | —- | M] (NHN USA inc.) "C:\Program Files\AIM6\aim6.exe" -> C:\Program Files\AIM6\aim6.exe [C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM] -> [2008/01/03 12:15:06 | 00,050,528 | —- | M] (AOL LLC) "C:\Program Files\AVG\AVG8\avgemc.exe" -> C:\Program Files\AVG\AVG8\avgemc.exe [C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe] -> [2008/09/30 15:13:43 | 00,875,288 | —- | M] (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG8\avgupd.exe" -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> [2008/09/30 15:13:44 | 00,641,304 | —- | M] (AVG Technologies CZ, s.r.o.) "C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe [C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe:*:Enabled:AIM] -> [2006/08/28 16:22:24 | 00,050,768 | —- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe [C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe:*:Enabled:AOL Services] -> [2005/08/02 15:33:02 | 00,151,640 | —- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe [C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe:*:Enabled:AOL Services] -> [2006/05/09 20:24:16 | 00,050,760 | —- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 03:17:27 | 00,010,800 | —- | M] (AOL LLC) "C:\Program Files\EA GAMES\Battlefield 2\BF2.exe" -> C:\Program Files\EA GAMES\Battlefield 2\BF2.exe [C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2] -> [2006/09/26 18:53:22 | 07,574,463 | —- | M] () "C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/07/30 10:47:50 | 20,252,968 | —- | M] (Apple Inc.) "C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> [2006/02/10 19:14:27 | 00,081,920 | —- | M] (Lime Wire, LLC) "C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) "C:\WINDOWS\system32\BugsSvr.exe" -> C:\WINDOWS\system32\BugsSvr.exe [C:\WINDOWS\system32\BugsSvr.exe:*:Enabled:Bugs Music Player Control] -> [2005/12/23 17:03:32 | 00,167,936 | —- | M] () "C:\WINDOWS\system32\cjmvsvr.exe" -> C:\WINDOWS\system32\cjmvsvr.exe [C:\WINDOWS\system32\cjmvsvr.exe:*:Enabled:CJMUSIC VoD Control] -> [2007/05/03 18:50:05 | 00,176,128 | —- | M] (© CJ MUSIC) "C:\WINDOWS\system32\clubbox.exe" -> C:\WINDOWS\system32\clubbox.exe [C:\WINDOWS\system32\clubbox.exe:*:Enabled:CLUBBOX File Transfer Manager] -> [2008/02/28 06:58:00 | 01,536,000 | R— | M] (Nowcom, Co. LTD.) "C:\WINDOWS\system32\fscagent.exe" -> C:\WINDOWS\system32\fscagent.exe [C:\WINDOWS\system32\fscagent.exe:*:Enabled:???? ???? ??] -> [2008/02/25 12:24:40 | 00,159,744 | R— | M] (Nowcom Co., Ltd.) "C:\WINDOWS\system32\p3bvsvr.exe" -> C:\WINDOWS\system32\p3bvsvr.exe [C:\WINDOWS\system32\p3bvsvr.exe:*:Enabled:Bugs Music VoD Control] -> [2006/02/18 11:38:09 | 00,167,936 | —- | M] (© PeeringPortal) "C:\WINDOWS\system32\P3MxSvr.exe" -> C:\WINDOWS\system32\P3MxSvr.exe [C:\WINDOWS\system32\P3MxSvr.exe:*:Enabled:Maxmp3 AoD Control] -> [2007/06/20 12:17:54 | 00,159,744 | —- | M] () "C:\WINDOWS\system32\p3mxvsvr.exe" -> C:\WINDOWS\system32\p3mxvsvr.exe [C:\WINDOWS\system32\p3mxvsvr.exe:*:Enabled:MAXMP3 VOD Control] -> [2007/02/12 11:12:48 | 00,202,520 | —- | M] (Maxmp3) "C:\WINDOWS\system32\skcbgm.exe" -> C:\WINDOWS\system32\skcbgm.exe [C:\WINDOWS\system32\skcbgm.exe:*:Enabled:SK Communications Cyworld BGM Player] -> [2007/01/09 18:15:26 | 00,163,840 | —- | M] (© SK Communications) < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 14:40:46 | 00,062,976 | —- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2006/01/26 16:44:23 | 00,000,000 | —- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell \I\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell\AutoRun \I\Shell\AutoRun\\"" -> [Auto&Play] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell\AutoRun\command \I\Shell\AutoRun\command\\"" -> I:\LaunchU3.exe [I:\LaunchU3.exe -a] -> File not found [Registry - Additional Scans - Safe List] < App Paths [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ -> AcroRd32.exe -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AcroRd32.exe [C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe] -> [2006/05/16 23:15:10 | 00,071,288 | —- | M] (Adobe Systems Incorporated) AVGSE.DLL -> %ProgramFiles%\AVG\AVG8\avgse.dll [C:\PROGRA~1\AVG\AVG8\avgse.dll] -> [2008/09/30 15:13:46 | 00,099,608 | —- | M] (AVG Technologies CZ, s.r.o.) BackItUp.EXE -> %ProgramFiles%\Ahead\Nero BackItUp\BackItUp.exe [C:\Program Files\Ahead\Nero BackItUp\BackItUp.exe] -> [2005/05/19 20:36:56 | 05,758,976 | —- | M] (Ahead Software AG) bckgzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\bckgzm.exe [C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe] -> [2004/08/04 08:00:00 | 00,042,577 | —- | M] (Microsoft Corporation) BitComet.exe -> %ProgramFiles%\BitComet\BitComet.exe [C:\Program Files\BitComet\BitComet.exe] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com) chkrzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\chkrzm.exe [C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe] -> [2004/08/04 08:00:00 | 00,042,575 | —- | M] (Microsoft Corporation) cmmgr32.exe -> %SystemRoot%\system32\cmmgr32.exe [C:\WINDOWS\system32\cmmgr32.exe] -> File not found CONF.EXE -> %ProgramFiles%\NetMeeting\conf.exe [C:\Program Files\NetMeeting\conf.exe] -> [2008/04/13 20:12:15 | 01,032,192 | —- | M] (Microsoft Corporation) ConvertMovie 3.0 -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found dialer.exe -> %ProgramFiles%\Windows NT\dialer.exe [C:\Program Files\Windows NT\dialer.exe] -> [2008/04/13 20:12:17 | 00,539,136 | —- | M] (Microsoft Corporation) DVD Solution -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found EPSON CardMonitor1.1.exe -> %ProgramFiles%\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe [C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe] -> [2003/07/25 01:00:00 | 00,258,048 | —- | M] (SEIKO EPSON CORPORATION) EPSON PhotoStarter3.0.exe -> %ProgramFiles%\EPSON\EPSON PhotoStarter3.0\EPSON PhotoStarter3.0.exe [C:\Program Files\EPSON\EPSON PhotoStarter3.0\EPSON PhotoStarter3.0.exe] -> [2002/02/27 02:16:00 | 04,841,472 | —- | M] (SEIKO EPSON CORPORATION) EPSONCD.exe -> %ProgramFiles%\EPSON Print CD\EPSONCD.exe [C:\Program Files\EPSON Print CD\EPSONCD.exe] -> [2003/08/14 01:20:00 | 02,723,840 | —- | M] (EPSON) excel.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE] -> [2008/08/04 16:12:50 | 10,354,176 | —- | M] (Microsoft Corporation) gimp-2.4.exe -> %ProgramFiles%\GIMP-2.0\bin\gimp-2.4.exe [C:\Program Files\GIMP-2.0\bin\gimp-2.4.exe] -> File not found HELPCTR.EXE -> %SystemRoot%\pchealth\helpctr\binaries\helpctr.exe [C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe] -> [2008/04/13 20:12:21 | 00,769,024 | —- | M] (Microsoft Corporation) HijackThis.exe -> %ProgramFiles%\Trend Micro\HijackThis\HijackThis.exe [C:\Program Files\Trend Micro\HijackThis\hijackthis.exe] -> [2008/09/29 20:51:14 | 00,396,288 | —- | M] (Trend Micro Inc.) hrtzzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\hrtzzm.exe [C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe] -> [2004/08/04 08:00:00 | 00,042,573 | —- | M] (Microsoft Corporation) hypertrm.exe -> %ProgramFiles%\Windows NT\hypertrm.exe ["C:\Program Files\Windows NT\hypertrm.exe"] -> [2004/08/04 08:00:00 | 00,028,160 | —- | M] (Hilgraeve, Inc.) ICWCONN1.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE"] -> [2008/04/13 20:12:22 | 00,214,528 | —- | M] (Microsoft Corporation) ICWCONN2.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn2.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE"] -> [2008/04/13 20:12:22 | 00,086,016 | —- | M] (Microsoft Corporation) IEXPLORE.EXE -> %ProgramFiles%\Internet Explorer\iexplore.exe [C:\Program Files\Internet Explorer\iexplore.exe] -> [2008/04/13 20:12:22 | 00,093,184 | —- | M] (Microsoft Corporation) InCD.exe -> %ProgramFiles%\Ahead\InCD\InCD.exe [C:\Program Files\Ahead\InCD\InCD.exe] -> [2005/06/10 10:20:06 | 01,397,760 | —- | M] (Nero AG) INETWIZ.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\inetwiz.exe ["C:\Program Files\Internet Explorer\Connection Wizard\INETWIZ.EXE"] -> [2008/04/13 20:12:22 | 00,020,480 | —- | M] (Microsoft Corporation) install.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found InstallHelper.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found IPHSend.exe -> %CommonProgramFiles%\AOL\IPHSend\IPHSend.exe [C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe] -> [2006/02/17 12:59:46 | 00,124,520 | —- | M] (America Online, Inc.) ISIGNUP.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\isignup.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ISIGNUP.EXE"] -> [2004/08/04 08:00:00 | 00,016,384 | —- | M] (Microsoft Corporation) iTunes.exe -> %ProgramFiles%\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe] -> [2008/07/30 10:47:50 | 20,252,968 | —- | M] (Apple Inc.) javaws.exe -> %ProgramFiles%\Java\jre1.5.0_10\bin\javaws.exe [C:\Program Files\Java\jre1.5.0_10\bin\javaws.exe] -> [2006/11/09 16:07:32 | 00,127,078 | —- | M] (Sun Microsystems, Inc.) mbam.exe -> %ProgramFiles%\Malwarebytes' Anti-Malware\mbam.exe [C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe] -> [2008/09/10 00:03:54 | 01,253,040 | —- | M] (Malwarebytes Corporation) migwiz.exe -> %SystemRoot%\system32\usmt\migwiz.exe [%SystemRoot%\system32\usmt\migwiz.exe] -> [2008/04/13 20:12:25 | 00,245,248 | —- | M] (Microsoft Corporation) moviemk.exe -> %ProgramFiles%\Movie Maker\moviemk.exe [C:\Program Files\Movie Maker\moviemk.exe] -> [2008/04/13 20:12:27 | 03,558,912 | —- | M] (Microsoft Corporation) mplayer2.exe -> %ProgramFiles%\Windows Media Player\mplayer2.exe ["C:\Program Files\Windows Media Player\mplayer2.exe"] -> [2008/04/13 20:12:27 | 00,004,639 | —- | M] (Microsoft Corporation) MSCONFIG.EXE -> %SystemRoot%\pchealth\helpctr\binaries\msconfig.exe [C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE] -> [2008/04/13 20:12:27 | 00,169,984 | —- | M] (Microsoft Corporation) msimn.exe -> %ProgramFiles%\Outlook Express\msimn.exe [%ProgramFiles%\Outlook Express\msimn.exe] -> [2008/04/13 20:12:28 | 00,060,416 | —- | M] (Microsoft Corporation) msinfo32.exe -> %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe [C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe] -> [2004/08/04 08:00:00 | 00,039,936 | —- | M] (Microsoft Corporation) MSMSGS.EXE -> %ProgramFiles%\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation) MSN.EXE -> %ProgramFiles%\MSN\MSNCoreFiles\msn.exe [C:\Program Files\MSN\MSNCoreFiles\msn.exe] -> [2006/05/30 13:19:20 | 00,093,696 | —- | M] (Microsoft Corporation) MSNMSGR.EXE -> %ProgramFiles%\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\MsnMsgr.Exe] -> [2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) MsoHtmEd.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found msoxmled.exe -> %CommonProgramFiles%\Microsoft Shared\OFFICE11\MSOXMLED.EXE [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLED.EXE] -> [2007/03/22 19:13:38 | 00,058,720 | —- | M] (Microsoft Corporation) mspview.exe -> %CommonProgramFiles%\Microsoft Shared\MODI\11.0\MSPVIEW.EXE [C:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0\MSPVIEW.EXE] -> [2007/04/09 13:24:00 | 00,367,496 | —- | M] (Microsoft Corporation) NCoverEd.exe -> %ProgramFiles%\Ahead\CoverDesigner\CoverDes.exe [C:\Program Files\Ahead\CoverDesigner\CoverDes.exe] -> [2005/05/24 20:48:44 | 02,441,216 | —- | M] (Nero AG) nero.exe -> %ProgramFiles%\Ahead\Nero\nero.exe [C:\Program Files\Ahead\nero\nero.exe] -> [2005/06/16 10:30:44 | 15,413,318 | —- | M] (Ahead Software AG) NeroStartSmart.exe -> %ProgramFiles%\Ahead\Nero StartSmart\NeroStartSmart.exe [C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart.exe] -> [2005/05/23 22:19:36 | 04,735,065 | —- | M] (Ahead Software AG) ois.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\OIS.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\OIS.EXE] -> [2007/03/22 19:06:22 | 00,287,576 | —- | M] (Microsoft Corporation) OUTLOOK.EXE -> %ProgramFiles%\Microsoft Office\OFFICE11\OUTLOOK.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE] -> [2008/04/23 15:09:50 | 00,199,688 | —- | M] (Microsoft Corporation) pbrush.exe -> %SystemRoot%\system32\mspaint.exe [%SystemRoot%\system32\mspaint.exe] -> [2008/04/13 20:12:28 | 00,343,040 | —- | M] (Microsoft Corporation) PictureViewer.exe -> %ProgramFiles%\K-Lite Codec Pack\QuickTime\PictureViewer.exe [C:\Program Files\K-Lite Codec Pack\QuickTime\PictureViewer.exe] -> [2008/05/27 10:50:24 | 00,548,864 | —- | M] (Apple Inc.) pinball.exe -> %ProgramFiles%\Windows NT\Pinball\pinball.exe [C:\Program Files\Windows NT\Pinball\pinball.exe] -> [2008/04/13 20:12:31 | 00,281,088 | —- | M] (Cinematronics) PowerBar -> %ProgramFiles%\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe [C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe] -> [2004/04/21 11:26:28 | 00,086,016 | —- | M] (Cyberlink, Corp.) powerpnt.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\POWERPNT.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\POWERPNT.EXE] -> [2008/07/03 18:33:40 | 06,421,512 | —- | M] (Microsoft Corporation) QuickTimePlayer.exe -> %ProgramFiles%\K-Lite Codec Pack\QuickTime\QuickTimePlayer.exe [C:\Program Files\K-Lite Codec Pack\QuickTime\QuickTimePlayer.exe] -> [2008/05/27 10:50:48 | 07,677,232 | —- | M] (Apple Inc.) RKVideoConverter.exe -> %ProgramFiles%\Red Kawa\Video Converter 3\RKVideoConverter.exe [C:\Program Files\Red Kawa\Video Converter 3\RKVideoConverter.exe] -> [2007/12/17 22:07:04 | 00,733,184 | —- | M] (Red Kawa Inc.) rvsezm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\Rvsezm.exe [C:\Program Files\MSN Gaming Zone\Windows\rvsezm.exe] -> [2004/08/04 08:00:00 | 00,042,574 | —- | M] (Microsoft Corporation) schdpl32.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\1033\SCHDPL32.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\1033\SCHDPL32.EXE] -> [2003/04/03 22:21:40 | 00,190,848 | —- | M] (Microsoft Corporation) setup.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found shvlzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\shvlzm.exe [C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe] -> [2004/08/04 08:00:00 | 00,042,573 | —- | M] (Microsoft Corporation) sinf.exe -> %CommonProgramFiles%\AOL\System Information\sinf.exe [C:\Program Files\Common Files\AOL\System Information\sinf.exe] -> File not found table30.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found wab.exe -> %ProgramFiles%\Outlook Express\wab.exe [%ProgramFiles%\Outlook Express\wab.exe] -> [2008/04/13 20:12:38 | 00,046,080 | —- | M] (Microsoft Corporation) wabmig.exe -> %ProgramFiles%\Outlook Express\wabmig.exe [%ProgramFiles%\Outlook Express\wabmig.exe] -> [2008/04/13 20:12:39 | 00,030,208 | —- | M] (Microsoft Corporation) winnt32.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found WinRAR.exe -> %ProgramFiles%\WinRAR\WinRAR.exe [C:\Program Files\WinRAR\WinRAR.exe] -> [2005/10/10 11:14:38 | 00,881,664 | —- | M] () Winword.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\WINWORD.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\WINWORD.EXE] -> [2008/07/03 18:36:56 | 12,313,096 | —- | M] (Microsoft Corporation) WMPBurn.exe -> %ProgramFiles%\Ahead\WMPBurn\WMPBurn.exe [C:\Program Files\Ahead\WMPBurn\WMPBurn.exe] -> [2004/01/08 18:19:24 | 01,265,664 | —- | M] (Ahead Software AG) wmplayer.exe -> %ProgramFiles%\Windows Media Player\wmplayer.exe [C:\Program Files\Windows Media Player\wmplayer.exe] -> [2006/10/18 21:46:20 | 00,064,000 | —- | M] (Microsoft Corporation) WORDPAD.EXE -> %ProgramFiles%\Windows NT\Accessories\wordpad.exe ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008/04/13 20:12:40 | 00,214,528 | —- | M] (Microsoft Corporation) WRITE.EXE -> %ProgramFiles%\Windows NT\Accessories\wordpad.exe ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008/04/13 20:12:40 | 00,214,528 | —- | M] (Microsoft Corporation) yourapp.Exe -> %ProgramFiles%\VisionWork\ReadPhonics\yourapp.Exe [C:\Program Files\VisionWork\ReadPhonics\yourapp.Exe] -> File not found < Disabled MSConfig Folder Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\ -> C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> [2005/09/23 22:05:26 | 00,029,696 | —- | M] (Adobe Systems Incorporated) < Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ -> AppleSyncNotifier hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe -> [2008/07/22 20:42:24 | 00,116,040 | —- | M] (Apple Inc.) ClubBox hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemRoot%\system32\clubbox.exe -> [2008/02/28 06:58:00 | 01,536,000 | R— | M] (Nowcom, Co. LTD.) EPSON Stylus Photo R300 Series hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemRoot%\system32\spool\drivers\w32x86\3\E_S4I2F1.EXE -> [2003/06/04 03:00:00 | 00,099,840 | —- | M] (SEIKO EPSON CORPORATION) HostManager hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\AOL\1140128537\ee\aolsoftware.exe -> [2006/05/09 20:24:16 | 00,050,760 | —- | M] (America Online, Inc.) HotKeysCmds hkey= key= -> -> File not found IgfxTray hkey= key= -> -> File not found InCD hkey= key= -> -> File not found IPHSend hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\AOL\IPHSend\IPHSend.exe -> [2006/02/17 12:59:46 | 00,124,520 | —- | M] (America Online, Inc.) iPlusAgent2 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\iriver\iriver plus 2\iAgent2.exe -> [2005/06/07 08:27:06 | 00,237,568 | —- | M] (Yurion, Inc.) iTunesHelper hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008/07/30 10:47:56 | 00,289,064 | —- | M] (Apple Inc.) NeroFilterCheck hkey= key= -> -> File not found PlaxoUpdate hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Plaxo\2.13.1.6\PlaxoHelper.exe -> [2008/04/14 17:36:46 | 00,227,914 | —- | M] (Plaxo, Inc.) PowerBar hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe -> [2004/04/21 11:26:28 | 00,086,016 | —- | M] (Cyberlink, Corp.) QuickTime Task hkey= key= -> -> File not found SFP hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\Verizon Online\SFP\vzSFPWin.exe -> [2003/09/05 16:30:18 | 00,561,152 | —- | M] (Verizon Internet Solutions) SoundMan hkey= key= -> -> File not found Steam hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Steam\steam.exe -> [2008/03/27 19:30:27 | 01,271,032 | —- | M] (Valve Corporation) SunJavaUpdateSched hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Java\jre1.5.0_10\bin\jusched.exe -> [2006/11/09 16:07:30 | 00,049,263 | —- | M] (Sun Microsystems, Inc.) updateMgr hkey= key= -> -> File not found VirRL2009 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\VirRL2009\VirRL2009.exe -> File not found < Disabled MSConfig State [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state -> "bootini" -> 0 -> "services" -> 0 -> "startup" -> 2 -> "system.ini" -> 0 -> "win.ini" -> 0 -> < File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .bat [@ = batfile] -> "%1" %* -> .chm [@ = chm.file] -> %SystemRoot%\hh.exe -> [2008/04/13 20:12:21 | 00,010,752 | —- | M] (Microsoft Corporation) .cmd [@ = cmdfile] -> "%1" %* -> .com [@ = ComFile] -> "%1" %* -> .exe [@ = exefile] -> "%1" %* -> .hlp [@ = hlpfile] -> %SystemRoot%\system32\winhlp32.exe -> [2004/08/04 08:00:00 | 00,008,192 | —- | M] (Microsoft Corporation) .hta [@ = htafile] -> %SystemRoot%\system32\mshta.exe -> [2008/04/13 20:12:27 | 00,029,184 | —- | M] (Microsoft Corporation) .html [@ = aol_htm] -> %ProgramFiles%\AOL\Explorer\1.2\AOLExplorer.exe -> [2005/11/02 23:01:14 | 00,050,792 | —- | M] (America Online, Inc.) .inf [@ = inffile] -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | —- | M] (Microsoft Corporation) .ini [@ = inifile] -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | —- | M] (Microsoft Corporation) .js [@ = JSFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .jse [@ = JSEFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .pif [@ = piffile] -> "%1" %* -> .reg [@ = regfile] -> %SystemRoot%\regedit.exe -> [2008/04/13 20:12:32 | 00,146,432 | —- | M] (Microsoft Corporation) .scr [@ = scrfile] -> "%1" /S -> .txt [@ = txtfile] -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | —- | M] (Microsoft Corporation) .vbe [@ = VBEFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .vbs [@ = VBSFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .wsf [@ = WSFFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .wsh [@ = WSHFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) < EventViewer Logs - Last 10 Errors > -> Event Information -> Description Application [ Error ] 2/1/2008 4:36:48 PM Computer Name = WINXP-A88C7D920 | Source = crypt32 | ID = 131083 -> Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Application [ Error ] 2/1/2008 4:36:48 PM Computer Name = WINXP-A88C7D920 | Source = crypt32 | ID = 131083 -> Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Application [ Error ] 7/23/2008 1:41:27 PM Computer Name = WINXP-A88C7D920 | Source = SecurityCenter | ID = 1802 -> Description = The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus and Firewall. Application [ Error ] 8/26/2008 11:50:28 PM Computer Name = WINXP-A88C7D920 | Source = MsiInstaller | ID = 11905 -> Description = Product: ESScore – Error 1905.Module C:\Program Files\Kodak\Kodak EasyShare software\bin\vdt.dll failed to unregister. HRESULT -2147220472. Contact your support personnel. Application [ Error ] 8/26/2008 11:50:53 PM Computer Name = WINXP-A88C7D920 | Source = MsiInstaller | ID = 11905 -> Description = Product: ESSgui – Error 1905.Module C:\Program Files\Kodak\Kodak EasyShare software\bin\ESCom.dll failed to unregister. HRESULT -2147220472. Contact your support personnel. System [ Error ] 10/19/2008 6:34:57 PM Computer Name = WINXP-A88C7D920 | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7026 -> Description = The following boot-start or system-start driver(s) failed to load: AFD ASPI32 AvgLdx86 AvgMfx86 Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip System [ Error ] 10/19/2008 6:42:56 PM Computer Name = WINXP-A88C7D920 | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} System [ Error ] 10/19/2008 6:44:37 PM Computer Name = WINXP-A88C7D920 | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} [Files/Folders - Created Within 90 Days] 1 C:\*.tmp files -> C:\*.tmp -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2008/10/19 18:43:49 | 00,000,000 | —D | C] tmp.reg -> %SystemRoot%\System32\tmp.reg -> [2008/10/19 18:35:54 | 00,002,340 | —- | C] () VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe -> [2008/10/19 18:35:31 | 00,289,144 | —- | C] (S!Ri) SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe -> [2008/10/19 18:35:31 | 00,288,417 | —- | C] (S!Ri) swreg.exe -> %SystemRoot%\System32\swreg.exe -> [2008/10/19 18:35:31 | 00,135,168 | —- | C] (SteelWerX) AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe -> [2008/10/19 18:35:31 | 00,088,576 | —- | C] (S!Ri.URZ) VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> [2008/10/19 18:35:31 | 00,087,552 | —- | C] (S!Ri.URZ) o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe -> [2008/10/19 18:35:31 | 00,082,944 | —- | C] (S!Ri.URZ) IEDFix.exe -> %SystemRoot%\System32\IEDFix.exe -> [2008/10/19 18:35:31 | 00,082,944 | —- | C] (S!Ri.URZ) IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe -> [2008/10/19 18:35:31 | 00,082,944 | —- | C] (S!Ri.URZ) 404Fix.exe -> %SystemRoot%\System32\404Fix.exe -> [2008/10/19 18:35:31 | 00,082,432 | —- | C] (S!Ri.URZ) swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe -> [2008/10/19 18:35:31 | 00,079,360 | —- | C] (SteelWerX) Process.exe -> %SystemRoot%\System32\Process.exe -> [2008/10/19 18:35:31 | 00,053,248 | —- | C] (http://www.beyondlogic.org) dumphive.exe -> %SystemRoot%\System32\dumphive.exe -> [2008/10/19 18:35:31 | 00,051,200 | —- | C] () swsc.exe -> %SystemRoot%\System32\swsc.exe -> [2008/10/19 18:35:31 | 00,040,960 | —- | C] () WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe -> [2008/10/19 18:35:31 | 00,025,600 | —- | C] () SmitfraudFix -> %UserProfile%\Desktop\SmitfraudFix -> [2008/10/19 18:35:26 | 00,000,000 | —D | C] 123.doc -> %UserProfile%\My Documents\123.doc -> [2008/10/19 18:31:51 | 00,019,968 | —- | C] () OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/10/19 18:27:53 | 00,587,711 | —- | C] () SmitfraudFix.exe -> %UserProfile%\Desktop\SmitfraudFix.exe -> [2008/10/19 18:26:28 | 01,662,674 | —- | C] () tmp3.reg -> %SystemDrive%\tmp3.reg -> [2008/10/19 17:36:51 | 00,000,126 | —- | C] () 675873 -> %SystemRoot%\System32\675873 -> [2008/10/19 17:36:29 | 00,000,000 | —D | C] My Documents.url -> %UserProfile%\My Documents\My Documents.url -> [2008/10/19 17:36:24 | 00,000,133 | —- | C] () $AVG8.VAULT$ -> %SystemDrive%\$AVG8.VAULT$ -> [2008/10/19 17:35:28 | 00,000,000 | -H-D | C] srv.sys -> %SystemRoot%\System32\dllcache\srv.sys -> [2008/10/14 19:23:24 | 00,333,824 | —- | C] (Microsoft Corporation) win32k.sys -> %SystemRoot%\System32\dllcache\win32k.sys -> [2008/10/14 19:22:01 | 01,846,400 | —- | C] (Microsoft Corporation) ntkrnlmp.exe -> %SystemRoot%\System32\dllcache\ntkrnlmp.exe -> [2008/10/14 19:21:41 | 02,145,280 | —- | C] (Microsoft Corporation) ntoskrnl.exe -> %SystemRoot%\System32\dllcache\ntoskrnl.exe -> [2008/10/14 19:21:40 | 02,189,184 | —- | C] (Microsoft Corporation) ntkrpamp.exe -> %SystemRoot%\System32\dllcache\ntkrpamp.exe -> [2008/10/14 19:21:39 | 02,023,936 | —- | C] (Microsoft Corporation) ntkrnlpa.exe -> %SystemRoot%\System32\dllcache\ntkrnlpa.exe -> [2008/10/14 19:21:38 | 02,066,048 | —- | C] (Microsoft Corporation) ijji -> %SystemDrive%\ijji -> [2008/10/05 13:42:40 | 00,000,000 | —D | C] ChCfg.exe -> %SystemRoot%\System32\ChCfg.exe -> [2008/09/30 23:23:36 | 00,049,152 | —- | C] () Realtek AC97 -> %ProgramFiles%\Realtek AC97 -> [2008/09/30 23:22:24 | 00,000,000 | —D | C] alsndmgr.wav -> %SystemRoot%\System32\alsndmgr.wav -> [2008/09/30 23:22:17 | 00,141,016 | —- | C] () RtlCPAPI.dll -> %SystemRoot%\System32\RtlCPAPI.dll -> [2008/09/30 23:22:12 | 00,147,456 | —- | C] () RECYCLER -> %SystemDrive%\RECYCLER -> [2008/09/30 23:10:45 | 00,000,000 | -HSD | C] ComboFix -> %SystemDrive%\ComboFix -> [2008/09/30 21:38:44 | 00,000,000 | —D | C] temp -> %SystemRoot%\temp -> [2008/09/30 21:12:39 | 00,000,000 | —D | C] USetup.iss -> %SystemRoot%\USetup.iss -> [2008/09/30 16:41:44 | 00,000,553 | —- | C] () Realtek -> %ProgramFiles%\Realtek -> [2008/09/30 16:40:51 | 00,000,000 | —D | C] avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2008/09/30 15:14:02 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2008/09/30 15:14:01 | 00,076,040 | —- | C] (AVG Technologies CZ, s.r.o.) avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2008/09/30 15:13:58 | 00,097,928 | —- | C] (AVG Technologies CZ, s.r.o.) avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2008/09/30 15:13:57 | 00,026,824 | —- | C] (AVG Technologies CZ, s.r.o.) incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2008/09/30 15:13:50 | 29,045,884 | —- | C] () miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2008/09/30 15:13:50 | 00,307,238 | —- | C] () microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2008/09/30 15:13:50 | 00,043,628 | —- | C] () avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2008/09/30 15:13:49 | 06,061,540 | —- | C] () Avg -> %SystemRoot%\System32\drivers\Avg -> [2008/09/30 15:13:49 | 00,000,000 | —D | C] Malwarebytes -> %AppData%\Malwarebytes -> [2008/09/30 12:50:56 | 00,000,000 | —D | C] mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2008/09/30 12:50:29 | 00,017,200 | —- | C] (Malwarebytes Corporation) mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2008/09/30 12:50:27 | 00,038,528 | —- | C] (Malwarebytes Corporation) Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2008/09/30 12:50:25 | 00,000,000 | —D | C] Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2008/09/30 12:50:23 | 00,000,000 | —D | C] Download Manager -> %CommonProgramFiles%\Download Manager -> [2008/09/30 12:49:33 | 00,000,000 | —D | C] ERDNT -> %SystemRoot%\ERDNT -> [2008/09/30 12:21:21 | 00,000,000 | —D | C] ERUNT -> %ProgramFiles%\ERUNT -> [2008/09/30 12:20:01 | 00,000,000 | —D | C] Trend Micro -> %ProgramFiles%\Trend Micro -> [2008/09/29 20:51:14 | 00,000,000 | —D | C] Avg8 -> %AllUsersProfile%\Application Data\Avg8 -> [2008/09/28 13:41:56 | 00,000,000 | —D | C] udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll -> [2008/09/28 13:10:23 | 00,105,984 | —- | C] () Yahoo! -> %ProgramFiles%\Yahoo! -> [2008/09/27 21:35:35 | 00,000,000 | —D | C] AVG -> %ProgramFiles%\AVG -> [2008/09/27 21:29:28 | 00,000,000 | —D | C] Spybot - Search & Destroy -> %ProgramFiles%\Spybot - Search & Destroy -> [2008/09/27 21:17:47 | 00,000,000 | —D | C] Spybot - Search & Destroy -> %AllUsersProfile%\Application Data\Spybot - Search & Destroy -> [2008/09/27 21:17:47 | 00,000,000 | —D | C] PubPlugin.dll -> %SystemRoot%\System32\PubPlugin.dll -> [2008/09/20 22:52:02 | 00,157,152 | —- | C] (NHN Corporation) Robota.INI -> %SystemRoot%\Robota.INI -> [2008/09/17 23:27:20 | 00,000,028 | —- | C] () MAGIX -> %AppData%\MAGIX -> [2008/09/17 23:27:05 | 00,000,000 | —D | C] msxml4a.dll -> %SystemRoot%\System32\msxml4a.dll -> [2008/09/17 23:25:39 | 00,044,544 | —- | C] (Microsoft Corporation) DLLAV32.dll -> %SystemRoot%\System32\DLLAV32.dll -> [2008/09/17 23:25:36 | 00,487,424 | —- | C] (PoINT Software & Systems GmbH) MXRestore.exe -> %SystemRoot%\System32\MXRestore.exe -> [2008/09/17 23:25:36 | 00,430,080 | —- | C] (MAGIX AG) DLLRES32.dll -> %SystemRoot%\System32\DLLRES32.dll -> [2008/09/17 23:25:36 | 00,188,416 | —- | C] (PoINT Software & Systems GmbH) DLLDEV32.dll -> %SystemRoot%\System32\DLLDEV32.dll -> [2008/09/17 23:25:36 | 00,163,840 | —- | C] (PoINT Software & Systems GmbH) DLLDRV32.dll -> %SystemRoot%\System32\DLLDRV32.dll -> [2008/09/17 23:25:36 | 00,151,552 | —- | C] (PoINT Software & Systems GmbH) DLLCDA32.dll -> %SystemRoot%\System32\DLLCDA32.dll -> [2008/09/17 23:25:36 | 00,114,688 | —- | C] (PoINT Software & Systems GmbH) DLLCPY32.dll -> %SystemRoot%\System32\DLLCPY32.dll -> [2008/09/17 23:25:36 | 00,094,208 | —- | C] (PoINT Software & Systems GmbH) DLLPTL32.dll -> %SystemRoot%\System32\DLLPTL32.dll -> [2008/09/17 23:25:36 | 00,065,536 | —- | C] (PoINT Software & Systems GmbH) DLLCDF32.dll -> %SystemRoot%\System32\DLLCDF32.dll -> [2008/09/17 23:25:36 | 00,061,440 | —- | C] (PoINT Software & Systems GmbH) DLLTPO32.dll -> %SystemRoot%\System32\DLLTPO32.dll -> [2008/09/17 23:25:36 | 00,057,344 | —- | C] (PoINT Software & Systems GmbH) DLLPRJ32.dll -> %SystemRoot%\System32\DLLPRJ32.dll -> [2008/09/17 23:25:36 | 00,053,248 | —- | C] (PoINT Software & Systems GmbH) DLLIO32.dll -> %SystemRoot%\System32\DLLIO32.dll -> [2008/09/17 23:25:36 | 00,053,248 | —- | C] (PoINT Software & Systems GmbH) mgxasio2.dll -> %SystemRoot%\System32\mgxasio2.dll -> [2008/09/17 23:25:36 | 00,053,248 | —- | C] () DLLPRF32.dll -> %SystemRoot%\System32\DLLPRF32.dll -> [2008/09/17 23:25:36 | 00,049,152 | —- | C] (PoINT Software & Systems GmbH) DLLIMG32.dll -> %SystemRoot%\System32\DLLIMG32.dll -> [2008/09/17 23:25:36 | 00,045,056 | —- | C] (PoINT Software & Systems GmbH) DLLRD32.dll -> %SystemRoot%\System32\DLLRD32.dll -> [2008/09/17 23:25:36 | 00,040,960 | —- | C] (PoINT Software & Systems GmbH) DLLPNT32.dll -> %SystemRoot%\System32\DLLPNT32.dll -> [2008/09/17 23:25:36 | 00,036,864 | —- | C] (PoINT Software & Systems GmbH) STRING32.dll -> %SystemRoot%\System32\STRING32.dll -> [2008/09/17 23:25:36 | 00,032,768 | —- | C] (PoINT Software & Systems GmbH) DLLMSC32.dll -> %SystemRoot%\System32\DLLMSC32.dll -> [2008/09/17 23:25:36 | 00,032,768 | —- | C] (PoINT Software & Systems GmbH) DLLISO32.dll -> %SystemRoot%\System32\DLLISO32.dll -> [2008/09/17 23:25:36 | 00,032,768 | —- | C] (PoINT Software & Systems GmbH) DLLDIR32.dll -> %SystemRoot%\System32\DLLDIR32.dll -> [2008/09/17 23:25:36 | 00,032,768 | —- | C] (PoINT Software & Systems GmbH) TTIC32.dll -> %SystemRoot%\System32\TTIC32.dll -> [2008/09/17 23:25:36 | 00,024,576 | —- | C] (PoINT Software & Systems GmbH) TTI32.dll -> %SystemRoot%\System32\TTI32.dll -> [2008/09/17 23:25:36 | 00,024,576 | —- | C] (PoINT Software & Systems GmbH) DLLIX.dll -> %SystemRoot%\System32\DLLIX.dll -> [2008/09/17 23:25:36 | 00,024,576 | —- | C] (PoINT Software & Systems GmbH) DLLAV32.lib -> %SystemRoot%\System32\DLLAV32.lib -> [2008/09/17 23:25:36 | 00,014,182 | —- | C] () MAGIX -> %AllUsersProfile%\Application Data\MAGIX -> [2008/09/17 23:24:57 | 00,000,000 | —D | C] DLLDEV32i.dll -> %SystemRoot%\System32\DLLDEV32i.dll -> [2008/09/17 23:24:34 | 00,120,200 | —- | C] () MAGIX -> %ProgramFiles%\MAGIX -> [2008/09/17 23:24:34 | 00,000,000 | —D | C] mgxoschk.dll -> %SystemRoot%\System32\mgxoschk.dll -> [2008/09/17 23:24:02 | 00,700,416 | —- | C] (MAGIX AG) mgxoschk.ini -> %SystemRoot%\mgxoschk.ini -> [2008/09/17 23:24:02 | 00,005,937 | —- | C] () MAGIX -> %SystemRoot%\System32\MAGIX -> [2008/09/17 23:24:02 | 00,000,000 | —D | C] Aotoload.ocx -> %SystemRoot%\System32\Aotoload.ocx -> [2008/09/14 01:35:17 | 00,000,000 | —- | C] () U3 -> %AppData%\U3 -> [2008/09/14 00:42:59 | 00,000,000 | —D | C] MSECache -> %ProgramFiles%\MSECache -> [2008/09/03 21:31:33 | 00,000,000 | —D | C] Prefetch -> %SystemRoot%\Prefetch -> [2008/08/29 20:09:49 | 00,000,000 | —D | C] en-us -> %SystemRoot%\System32\en-us -> [2008/08/29 19:59:35 | 00,000,000 | —D | C] scripting -> %SystemRoot%\System32\scripting -> [2008/08/29 19:59:33 | 00,000,000 | —D | C] l2schemas -> %SystemRoot%\l2schemas -> [2008/08/29 19:59:31 | 00,000,000 | —D | C] en -> %SystemRoot%\System32\en -> [2008/08/29 19:59:30 | 00,000,000 | —D | C] bits -> %SystemRoot%\System32\bits -> [2008/08/29 19:59:29 | 00,000,000 | —D | C] ServicePackFiles -> %SystemRoot%\ServicePackFiles -> [2008/08/29 19:55:53 | 00,000,000 | —D | C] network diagnostic -> %SystemRoot%\network diagnostic -> [2008/08/29 19:53:09 | 00,000,000 | —D | C] $NtServicePackUninstall$ -> %SystemRoot%\$NtServicePackUninstall$ -> [2008/08/29 19:48:02 | 00,000,000 | -H-D | C] EHome -> %SystemRoot%\EHome -> [2008/08/29 19:47:59 | 00,000,000 | —D | C] xmllite.dll -> %SystemRoot%\System32\xmllite.dll -> [2008/08/29 13:54:52 | 00,121,856 | —- | C] (Microsoft Corporation) wmphoto.dll -> %SystemRoot%\System32\wmphoto.dll -> [2008/08/29 13:54:49 | 00,276,992 | —- | C] (Microsoft Corporation) wlanapi.dll -> %SystemRoot%\System32\wlanapi.dll -> [2008/08/29 13:54:47 | 00,069,120 | —- | C] (Microsoft Corporation) windowscodecsext.dll -> %SystemRoot%\System32\windowscodecsext.dll -> [2008/08/29 13:54:45 | 00,346,112 | —- | C] (Microsoft Corporation) windowscodecs.dll -> %SystemRoot%\System32\windowscodecs.dll -> [2008/08/29 13:54:44 | 00,712,704 | —- | C] (Microsoft Corporation) wacompen.sys -> %SystemRoot%\System32\drivers\wacompen.sys -> [2008/08/29 13:54:42 | 00,014,208 | —- | C] (Microsoft Corporation) viaagp.sys -> %SystemRoot%\System32\drivers\viaagp.sys -> [2008/08/29 13:54:41 | 00,042,240 | —- | C] (Microsoft Corporation) vidcap.ax -> %SystemRoot%\System32\vidcap.ax -> [2008/08/29 13:54:41 | 00,028,672 | —- | C] (Microsoft Corporation) usbvideo.sys -> %SystemRoot%\System32\drivers\usbvideo.sys -> [2008/08/29 13:54:39 | 00,121,984 | —- | C] (Microsoft Corporation) usb8023x.sys -> %SystemRoot%\System32\drivers\usb8023x.sys -> [2008/08/29 13:54:38 | 00,012,800 | —- | C] (Microsoft Corporation) uagp35.sys -> %SystemRoot%\System32\drivers\uagp35.sys -> [2008/08/29 13:54:36 | 00,044,672 | —- | C] (Microsoft Corporation) tsgqec.dll -> %SystemRoot%\System32\tsgqec.dll -> [2008/08/29 13:54:35 | 00,053,248 | —- | C] (Microsoft Corporation) tspkg.dll -> %SystemRoot%\System32\tspkg.dll -> [2008/08/29 13:54:35 | 00,050,688 | —- | C] (Microsoft Corporation) spupdwxp.exe -> %SystemRoot%\System32\spupdwxp.exe -> [2008/08/29 13:54:28 | 00,020,992 | —- | C] (Microsoft Corporation) spdwnwxp.exe -> %SystemRoot%\System32\spdwnwxp.exe -> [2008/08/29 13:54:27 | 00,007,680 | —- | C] (Microsoft Corporation) smbali.sys -> %SystemRoot%\System32\drivers\smbali.sys -> [2008/08/29 13:54:25 | 00,005,888 | —- | C] (Microsoft Corporation) setupn.exe -> %SystemRoot%\System32\setupn.exe -> [2008/08/29 13:54:21 | 00,032,768 | —- | C] (Microsoft Corporation) sffp_mmc.sys -> %SystemRoot%\System32\drivers\sffp_mmc.sys -> [2008/08/29 13:54:21 | 00,010,240 | —- | C] (Microsoft Corporation) rhttpaa.dll -> %SystemRoot%\System32\rhttpaa.dll -> [2008/08/29 13:54:17 | 00,290,304 | —- | C] (Microsoft Corporation) rfcomm.sys -> %SystemRoot%\System32\drivers\rfcomm.sys -> [2008/08/29 13:54:17 | 00,059,136 | —- | C] (Microsoft Corporation) rndismpx.sys -> %SystemRoot%\System32\drivers\rndismpx.sys -> [2008/08/29 13:54:17 | 00,030,592 | —- | C] (Microsoft Corporation) rasqec.dll -> %SystemRoot%\System32\rasqec.dll -> [2008/08/29 13:54:13 | 00,061,952 | —- | C] (Microsoft Corporation) qutil.dll -> %SystemRoot%\System32\qutil.dll -> [2008/08/29 13:54:11 | 00,076,800 | —- | C] (Microsoft Corporation) qagentrt.dll -> %SystemRoot%\System32\qagentrt.dll -> [2008/08/29 13:54:09 | 00,291,328 | —- | C] (Microsoft Corporation) qagent.dll -> %SystemRoot%\System32\qagent.dll -> [2008/08/29 13:54:09 | 00,150,528 | —- | C] (Microsoft Corporation) qcliprov.dll -> %SystemRoot%\System32\qcliprov.dll -> [2008/08/29 13:54:09 | 00,062,464 | —- | C] (Microsoft Corporation) photometadatahandler.dll -> %SystemRoot%\System32\photometadatahandler.dll -> [2008/08/29 13:54:07 | 00,412,160 | —- | C] (Microsoft Corporation) onex.dll -> %SystemRoot%\System32\onex.dll -> [2008/08/29 13:54:04 | 00,144,384 | —- | C] (Microsoft Corporation) netwlan5.img -> %SystemRoot%\System32\drivers\netwlan5.img -> [2008/08/29 13:53:52 | 00,067,866 | —- | C] () napmontr.dll -> %SystemRoot%\System32\napmontr.dll -> [2008/08/29 13:53:50 | 00,193,024 | —- | C] (Microsoft Corporation) napstat.exe -> %SystemRoot%\System32\napstat.exe -> [2008/08/29 13:53:50 | 00,176,640 | —- | C] (Microsoft Corporation) napipsec.dll -> %SystemRoot%\System32\napipsec.dll -> [2008/08/29 13:53:50 | 00,030,208 | —- | C] (Microsoft Corporation) mutohpen.sys -> %SystemRoot%\System32\drivers\mutohpen.sys -> [2008/08/29 13:53:50 | 00,012,672 | —- | C] (Microsoft Corporation) msxml6.dll -> %SystemRoot%\System32\msxml6.dll -> [2008/08/29 13:53:48 | 01,306,624 | —- | C] (Microsoft Corporation) msxml6.dll -> %SystemRoot%\System32\dllcache\msxml6.dll -> [2008/08/29 13:53:48 | 01,306,624 | —- | C] (Microsoft Corporation) msxml6r.dll -> %SystemRoot%\System32\msxml6r.dll -> [2008/08/29 13:53:48 | 00,079,872 | —- | C] (Microsoft Corporation) msxml6r.dll -> %SystemRoot%\System32\dllcache\msxml6r.dll -> [2008/08/29 13:53:48 | 00,079,872 | —- | C] (Microsoft Corporation) mssha.dll -> %SystemRoot%\System32\mssha.dll -> [2008/08/29 13:53:46 | 00,155,136 | —- | C] (Microsoft Corporation) msshavmsg.dll -> %SystemRoot%\System32\msshavmsg.dll -> [2008/08/29 13:53:46 | 00,076,800 | —- | C] (Microsoft Corporation) mmcex.dll -> %SystemRoot%\System32\mmcex.dll -> [2008/08/29 13:53:33 | 00,397,312 | —- | C] (Microsoft Corporation) microsoft.managementconsole.dll -> %SystemRoot%\System32\microsoft.managementconsole.dll -> [2008/08/29 13:53:33 | 00,184,320 | —- | C] (Microsoft Corporation) mmcfxcommon.dll -> %SystemRoot%\System32\mmcfxcommon.dll -> [2008/08/29 13:53:33 | 00,106,496 | —- | C] (Microsoft Corporation) mmcperf.exe -> %SystemRoot%\System32\mmcperf.exe -> [2008/08/29 13:53:33 | 00,033,792 | —- | C] (Microsoft Corporation) l2gpstore.dll -> %SystemRoot%\System32\l2gpstore.dll -> [2008/08/29 13:53:21 | 00,037,376 | —- | C] (Microsoft Corporation) kmsvc.dll -> %SystemRoot%\System32\kmsvc.dll -> [2008/08/29 13:53:20 | 00,061,440 | —- | C] (Microsoft Corporation) kbdpash.dll -> %SystemRoot%\System32\kbdpash.dll -> [2008/08/29 13:53:19 | 00,006,144 | —- | C] (Microsoft Corporation) kbdnepr.dll -> %SystemRoot%\System32\kbdnepr.dll -> [2008/08/29 13:53:19 | 00,006,144 | —- | C] (Microsoft Corporation) kbdiultn.dll -> %SystemRoot%\System32\kbdiultn.dll -> [2008/08/29 13:53:19 | 00,006,144 | —- | C] (Microsoft Corporation) kbdbhc.dll -> %SystemRoot%\System32\kbdbhc.dll -> [2008/08/29 13:53:18 | 00,006,144 | —- | C] (Microsoft Corporation) pid.inf -> %SystemRoot%\System32\pid.inf -> [2008/08/29 13:53:08 | 00,001,261 | —- | C] () hidbth.sys -> %SystemRoot%\System32\drivers\hidbth.sys -> [2008/08/29 13:53:04 | 00,025,600 | —- | C] (Microsoft Corporation) hidir.sys -> %SystemRoot%\System32\drivers\hidir.sys -> [2008/08/29 13:53:04 | 00,019,200 | —- | C] (Microsoft Corporation) gagp30kx.sys -> %SystemRoot%\System32\drivers\gagp30kx.sys -> [2008/08/29 13:53:02 | 00,046,464 | —- | C] (Microsoft Corporation) faxpatch.exe -> %SystemRoot%\System32\faxpatch.exe -> [2008/08/29 13:52:58 | 00,020,992 | —- | C] (Microsoft Corporation) eapp3hst.dll -> %SystemRoot%\System32\eapp3hst.dll -> [2008/08/29 13:52:55 | 00,184,832 | —- | C] (Microsoft Corporation) eapphost.dll -> %SystemRoot%\System32\eapphost.dll -> [2008/08/29 13:52:55 | 00,180,224 | —- | C] (Microsoft Corporation) eappcfg.dll -> %SystemRoot%\System32\eappcfg.dll -> [2008/08/29 13:52:55 | 00,126,976 | —- | C] (Microsoft Corporation) eappgnui.dll -> %SystemRoot%\System32\eappgnui.dll -> [2008/08/29 13:52:55 | 00,094,208 | —- | C] (Microsoft Corporation) eapqec.dll -> %SystemRoot%\System32\eapqec.dll -> [2008/08/29 13:52:55 | 00,059,392 | —- | C] (Microsoft Corporation) eappprxy.dll -> %SystemRoot%\System32\eappprxy.dll -> [2008/08/29 13:52:55 | 00,040,960 | —- | C] (Microsoft Corporation) eapsvc.dll -> %SystemRoot%\System32\eapsvc.dll -> [2008/08/29 13:52:55 | 00,033,792 | —- | C] (Microsoft Corporation) eapolqec.dll -> %SystemRoot%\System32\eapolqec.dll -> [2008/08/29 13:52:55 | 00,030,720 | —- | C] (Microsoft Corporation) dot3ui.dll -> %SystemRoot%\System32\dot3ui.dll -> [2008/08/29 13:52:52 | 00,650,752 | —- | C] (Microsoft Corporation) dot3svc.dll -> %SystemRoot%\System32\dot3svc.dll -> [2008/08/29 13:52:52 | 00,132,096 | —- | C] (Microsoft Corporation) dot3cfg.dll -> %SystemRoot%\System32\dot3cfg.dll -> [2008/08/29 13:52:52 | 00,057,856 | —- | C] (Microsoft Corporation) dot3msm.dll -> %SystemRoot%\System32\dot3msm.dll -> [2008/08/29 13:52:52 | 00,056,320 | —- | C] (Microsoft Corporation) dot3gpclnt.dll -> %SystemRoot%\System32\dot3gpclnt.dll -> [2008/08/29 13:52:52 | 00,039,936 | —- | C] (Microsoft Corporation) dot3api.dll -> %SystemRoot%\System32\dot3api.dll -> [2008/08/29 13:52:52 | 00,026,112 | —- | C] (Microsoft Corporation) dot3dlg.dll -> %SystemRoot%\System32\dot3dlg.dll -> [2008/08/29 13:52:52 | 00,009,216 | —- | C] (Microsoft Corporation) dimsroam.dll -> %SystemRoot%\System32\dimsroam.dll -> [2008/08/29 13:52:49 | 00,039,936 | —- | C] (Microsoft Corporation) dimsntfy.dll -> %SystemRoot%\System32\dimsntfy.dll -> [2008/08/29 13:52:49 | 00,019,456 | —- | C] (Microsoft Corporation) dhcpqec.dll -> %SystemRoot%\System32\dhcpqec.dll -> [2008/08/29 13:52:48 | 00,048,640 | —- | C] (Microsoft Corporation) cxthsfs2.cty -> %SystemRoot%\System32\drivers\cxthsfs2.cty -> [2008/08/29 13:52:46 | 00,129,045 | —- | C] () credssp.dll -> %SystemRoot%\System32\credssp.dll -> [2008/08/29 13:52:45 | 00,012,800 | —- | C] (Microsoft Corporation) bthpan.sys -> %SystemRoot%\System32\drivers\bthpan.sys -> [2008/08/29 13:52:40 | 00,101,120 | —- | C] (Microsoft Corporation) bthprint.sys -> %SystemRoot%\System32\drivers\bthprint.sys -> [2008/08/29 13:52:40 | 00,036,480 | —- | C] (Microsoft Corporation) bthusb.sys -> %SystemRoot%\System32\drivers\bthusb.sys -> [2008/08/29 13:52:40 | 00,018,944 | —- | C] (Microsoft Corporation) bthmodem.sys -> %SystemRoot%\System32\drivers\bthmodem.sys -> [2008/08/29 13:52:39 | 00,037,888 | —- | C] (Microsoft Corporation) bthenum.sys -> %SystemRoot%\System32\drivers\bthenum.sys -> [2008/08/29 13:52:39 | 00,017,024 | —- | C] (Microsoft Corporation) bitsprx4.dll -> %SystemRoot%\System32\bitsprx4.dll -> [2008/08/29 13:52:39 | 00,007,168 | —- | C] (Microsoft Corporation) azroles.dll -> %SystemRoot%\System32\azroles.dll -> [2008/08/29 13:52:38 | 00,233,472 | —- | C] (Microsoft Corporation) ativmc20.cod -> %SystemRoot%\System32\drivers\ativmc20.cod -> [2008/08/29 13:52:36 | 00,064,352 | —- | C] () alim1541.sys -> %SystemRoot%\System32\drivers\alim1541.sys -> [2008/08/29 13:52:32 | 00,042,752 | —- | C] (Microsoft Corporation) agpcpq.sys -> %SystemRoot%\System32\drivers\agpcpq.sys -> [2008/08/29 13:52:29 | 00,044,928 | —- | C] (Microsoft Corporation) agp440.sys -> %SystemRoot%\System32\drivers\agp440.sys -> [2008/08/29 13:52:29 | 00,042,368 | —- | C] (Microsoft Corporation) aaclient.dll -> %SystemRoot%\System32\aaclient.dll -> [2008/08/29 13:52:27 | 00,136,192 | —- | C] (Microsoft Corporation) inetcomm.dll -> %SystemRoot%\System32\dllcache\inetcomm.dll -> [2008/08/29 13:21:36 | 00,691,712 | —- | C] (Microsoft Corporation) AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [2008/08/10 23:27:08 | 00,000,284 | —- | C] () iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2008/08/10 23:21:23 | 00,002,137 | —- | C] () iPod -> %ProgramFiles%\iPod -> [2008/08/10 23:19:17 | 00,000,000 | —D | C] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [2008/08/09 09:59:04 | 00,054,156 | -H– | C] () QTFont.for -> %SystemRoot%\QTFont.for -> [2008/08/09 09:59:04 | 00,001,409 | —- | C] () [Files/Folders - Modified Within 90 Days] 1 C:\*.tmp files -> C:\*.tmp -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 1 C:\Documents and Settings\winxp\My Documents\*.tmp files -> C:\Documents and Settings\winxp\My Documents\*.tmp -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [2006/01/26 16:50:18 | 00,000,000 | —D | M] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2008/10/14 19:23:55 | 00,004,232 | —- | M] () qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2008/10/14 19:23:55 | 00,004,646 | —- | M] () C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA -> [2006/02/28 21:14:06 | 00,000,000 | —D | M] opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [2006/02/28 21:14:22 | 00,011,108 | —- | M] () C:\WINDOWS\Temp\ -> C:\WINDOWS\temp -> [2008/10/19 18:32:08 | 00,000,000 | —D | M] alcrmv.exe -> C:\WINDOWS\temp\alcrmv.exe -> [2006/07/31 11:27:30 | 00,217,088 | —- | M] (Realtek Semiconductor Corp.) alcupd.exe -> C:\WINDOWS\temp\alcupd.exe -> [2006/07/31 11:19:00 | 00,315,392 | —- | M] (Realtek Semiconductor Corp.) ChCfg.exe -> C:\WINDOWS\temp\ChCfg.exe -> [2006/08/01 15:02:00 | 00,049,152 | —- | M] () RTLCPL.exe -> C:\WINDOWS\temp\RTLCPL.exe -> [2006/12/08 15:20:14 | 10,528,768 | —- | M] (Realtek Semiconductor Corp.) soundman.exe -> C:\WINDOWS\temp\soundman.exe -> [2007/04/16 15:28:22 | 00,577,536 | —- | M] (Realtek Semiconductor Corp.) C:\WINDOWS\Temp\ -> C:\WINDOWS\temp -> [2008/10/19 18:32:08 | 00,000,000 | —D | M] newdev.dll -> C:\WINDOWS\temp\newdev.dll -> [2008/04/13 20:12:02 | 00,247,808 | —- | M] (Microsoft Corporation) RtlCPAPI.dll -> C:\WINDOWS\temp\RtlCPAPI.dll -> [2006/10/18 02:53:26 | 00,147,456 | —- | M] () tmp.reg -> %SystemRoot%\System32\tmp.reg -> [2008/10/19 18:35:54 | 00,002,340 | —- | M] () hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [2008/10/19 18:35:50 | 00,000,027 | —- | M] () bootstat.dat -> %SystemRoot%\bootstat.dat -> [2008/10/19 18:34:08 | 00,002,048 | –S- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/10/19 18:32:05 | 00,000,006 | -H– | M] () 123.doc -> %UserProfile%\My Documents\123.doc -> [2008/10/19 18:31:52 | 00,019,968 | —- | M] () OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/10/19 18:27:56 | 00,587,711 | —- | M] () SmitfraudFix.exe -> %UserProfile%\Desktop\SmitfraudFix.exe -> [2008/10/19 18:26:41 | 01,662,674 | —- | M] () Microsoft Office Word 2003.lnk -> %UserProfile%\Desktop\Microsoft Office Word 2003.lnk -> [2008/10/19 18:24:31 | 00,002,497 | —- | M] () wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2008/10/19 17:54:03 | 00,012,598 | —- | M] () win.ini -> %SystemRoot%\win.ini -> [2008/10/19 17:52:13 | 00,000,624 | —- | M] () system.ini -> %SystemRoot%\system.ini -> [2008/10/19 17:52:13 | 00,000,227 | —- | M] () boot.ini -> %SystemDrive%\boot.ini -> [2008/10/19 17:52:13 | 00,000,210 | -HS- | M] () incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2008/10/19 17:44:53 | 29,045,884 | —- | M] () tmp3.reg -> %SystemDrive%\tmp3.reg -> [2008/10/19 17:36:53 | 00,000,126 | —- | M] () My Documents.url -> %UserProfile%\My Documents\My Documents.url -> [2008/10/19 17:36:24 | 00,000,133 | —- | M] () iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2008/10/18 20:39:25 | 00,002,137 | —- | M] () winamp.ini -> %SystemRoot%\winamp.ini -> [2008/10/16 23:20:14 | 00,001,125 | —- | M] () microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2008/10/15 20:07:24 | 00,043,628 | —- | M] () FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2008/10/15 12:32:18 | 00,246,312 | —- | M] () imsins.BAK -> %SystemRoot%\imsins.BAK -> [2008/10/14 23:18:26 | 00,001,393 | —- | M] () PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2008/10/14 23:05:39 | 00,478,288 | —- | M] () perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [2008/10/14 23:05:39 | 00,409,232 | —- | M] () perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [2008/10/14 23:05:39 | 00,064,372 | —- | M] () o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe -> [2008/10/10 08:58:08 | 00,082,944 | —- | M] (S!Ri.URZ) IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe -> [2008/10/10 08:58:08 | 00,082,944 | —- | M] (S!Ri.URZ) miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2008/10/09 21:10:22 | 00,307,238 | —- | M] () MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2008/10/07 15:19:40 | 16,721,856 | —- | M] (Microsoft Corporation) IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/10/05 22:26:14 | 01,577,134 | -H– | M] () VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> [2008/10/01 15:51:40 | 00,087,552 | —- | M] (S!Ri.URZ) PDBOXGame.html -> %SystemRoot%\System32\PDBOXGame.html -> [2008/09/30 15:23:23 | 00,000,000 | —- | M] () avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2008/09/30 15:14:02 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2008/09/30 15:14:01 | 00,076,040 | —- | M] (AVG Technologies CZ, s.r.o.) avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2008/09/30 15:13:58 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.) avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2008/09/30 15:13:57 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.) avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2008/09/30 15:13:50 | 06,061,540 | —- | M] () udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll -> [2008/09/28 13:10:24 | 00,105,984 | —- | M] () WININIT.INI -> %SystemRoot%\WININIT.INI -> [2008/09/28 13:08:41 | 00,000,810 | —- | M] () GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2008/09/18 15:50:51 | 00,067,616 | —- | M] () Robota.INI -> %SystemRoot%\Robota.INI -> [2008/09/17 23:27:20 | 00,000,028 | —- | M] () mgxoschk.ini -> %SystemRoot%\mgxoschk.ini -> [2008/09/17 23:25:59 | 00,005,937 | —- | M] () win32k.sys -> %SystemRoot%\System32\win32k.sys -> [2008/09/15 08:12:56 | 01,846,400 | —- | M] (Microsoft Corporation) win32k.sys -> %SystemRoot%\System32\dllcache\win32k.sys -> [2008/09/15 08:12:56 | 01,846,400 | —- | M] (Microsoft Corporation) Aotoload.ocx -> %SystemRoot%\System32\Aotoload.ocx -> [2008/09/14 01:35:17 | 00,000,000 | —- | M] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2008/09/10 00:04:02 | 00,038,528 | —- | M] (Malwarebytes Corporation) mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2008/09/10 00:03:56 | 00,017,200 | —- | M] (Malwarebytes Corporation) AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe -> [2008/09/08 23:38:55 | 00,088,576 | —- | M] (S!Ri.URZ) srv.sys -> %SystemRoot%\System32\drivers\srv.sys -> [2008/09/08 06:41:42 | 00,333,824 | —- | M] (Microsoft Corporation) srv.sys -> %SystemRoot%\System32\dllcache\srv.sys -> [2008/09/08 06:41:42 | 00,333,824 | —- | M] (Microsoft Corporation) DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2008/08/31 20:56:43 | 00,036,352 | —- | M] () desktop.ini -> %UserProfile%\My Documents\desktop.ini -> [2008/08/29 20:12:27 | 00,000,076 | -HS- | M] () ntldr -> %SystemDrive%\ntldr -> [2008/08/29 19:52:30 | 00,250,048 | RHS- | M] () AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [2008/08/29 14:28:10 | 00,000,284 | —- | M] () logfile -> %SystemDrive%\logfile -> [2008/08/26 23:44:40 | 00,035,052 | —- | M] () fscagent.ini -> %SystemRoot%\System32\fscagent.ini -> [2008/08/23 21:18:44 | 00,000,080 | —- | M] () mshtml.dll -> %SystemRoot%\System32\mshtml.dll -> [2008/08/20 01:30:53 | 03,067,904 | —- | M] (Microsoft Corporation) mshtml.dll -> %SystemRoot%\System32\dllcache\mshtml.dll -> [2008/08/20 01:30:53 | 03,067,904 | —- | M] (Microsoft Corporation) urlmon.dll -> %SystemRoot%\System32\urlmon.dll -> [2008/08/20 01:30:52 | 00,619,520 | —- | M] (Microsoft Corporation) urlmon.dll -> %SystemRoot%\System32\dllcache\urlmon.dll -> [2008/08/20 01:30:52 | 00,619,520 | —- | M] (Microsoft Corporation) shdocvw.dll -> %SystemRoot%\System32\shdocvw.dll -> [2008/08/20 01:30:51 | 01,499,136 | —- | M] (Microsoft Corporation) shdocvw.dll -> %SystemRoot%\System32\dllcache\shdocvw.dll -> [2008/08/20 01:30:51 | 01,499,136 | —- | M] (Microsoft Corporation) wininet.dll -> %SystemRoot%\System32\wininet.dll -> [2008/08/20 01:30:51 | 00,666,112 | —- | M] (Microsoft Corporation) wininet.dll -> %SystemRoot%\System32\dllcache\wininet.dll -> [2008/08/20 01:30:51 | 00,666,112 | —- | M] (Microsoft Corporation) 404Fix.exe -> %SystemRoot%\System32\404Fix.exe -> [2008/08/18 12:19:03 | 00,082,432 | —- | M] (S!Ri.URZ) ntoskrnl.exe -> %SystemRoot%\System32\dllcache\ntoskrnl.exe -> [2008/08/14 06:11:02 | 02,189,184 | —- | M] (Microsoft Corporation) ntoskrnl.exe -> %SystemRoot%\System32\ntoskrnl.exe -> [2008/08/14 06:09:26 | 02,145,280 | —- | M] (Microsoft Corporation) ntkrnlmp.exe -> %SystemRoot%\System32\dllcache\ntkrnlmp.exe -> [2008/08/14 06:09:26 | 02,145,280 | —- | M] (Microsoft Corporation) afd.sys -> %SystemRoot%\System32\drivers\afd.sys -> [2008/08/14 06:04:36 | 00,138,496 | —- | M] (Microsoft Corporation) afd.sys -> %SystemRoot%\System32\dllcache\afd.sys -> [2008/08/14 06:04:36 | 00,138,496 | —- | M] (Microsoft Corporation) ntkrnlpa.exe -> %SystemRoot%\System32\dllcache\ntkrnlpa.exe -> [2008/08/14 05:33:16 | 02,066,048 | —- | M] (Microsoft Corporation) ntkrpamp.exe -> %SystemRoot%\System32\dllcache\ntkrpamp.exe -> [2008/08/14 05:33:16 | 02,023,936 | —- | M] (Microsoft Corporation) ntkrnlpa.exe -> %SystemRoot%\System32\ntkrnlpa.exe -> [2008/08/14 05:33:16 | 02,023,936 | —- | M] (Microsoft Corporation) QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [2008/08/10 16:08:17 | 00,054,156 | -H– | M] () QTFont.for -> %SystemRoot%\QTFont.for -> [2008/08/09 09:59:04 | 00,001,409 | —- | M] () cmiset.inf -> %SystemRoot%\cmiset.inf -> [2008/08/04 22:25:36 | 00,000,093 | —- | M] () [File - Lop Check] Application Data -> C:\Documents and Settings\All Users\Application Data -> [2008/09/30 15:12:15 | 00,000,000 | RH-D | M] Adobe -> C:\Documents and Settings\All Users\Application Data\Adobe -> [2006/08/21 20:31:11 | 00,000,000 | —D | M] AOL -> C:\Documents and Settings\All Users\Application Data\AOL -> [2006/02/16 18:22:27 | 00,000,000 | —D | M] AOL Downloads -> C:\Documents and Settings\All Users\Application Data\AOL Downloads -> [2008/02/19 14:12:41 | 00,000,000 | —D | M] AOL OCP -> C:\Documents and Settings\All Users\Application Data\AOL OCP -> [2007/06/07 20:25:06 | 00,000,000 | —D | M] Apple -> C:\Documents and Settings\All Users\Application Data\Apple -> [2008/03/04 22:33:25 | 00,000,000 | —D | M] Apple Computer -> C:\Documents and Settings\All Users\Application Data\Apple Computer -> [2008/03/04 22:38:04 | 00,000,000 | —D | M] ATI -> C:\Documents and Settings\All Users\Application Data\ATI -> [2007/09/14 00:10:24 | 00,000,000 | —D | M] Avg8 -> C:\Documents and Settings\All Users\Application Data\Avg8 -> [2008/09/30 15:13:39 | 00,000,000 | —D | M] Kodak -> C:\Documents and Settings\All Users\Application Data\Kodak -> [2008/08/27 00:08:55 | 00,000,000 | —D | M] MAGIX -> C:\Documents and Settings\All Users\Application Data\MAGIX -> [2008/09/17 23:26:20 | 00,000,000 | —D | M] Malwarebytes -> C:\Documents and Settings\All Users\Application Data\Malwarebytes -> [2008/09/30 12:50:25 | 00,000,000 | —D | M] Microsoft -> C:\Documents and Settings\All Users\Application Data\Microsoft -> [2007/10/28 19:39:17 | 00,000,000 | –SD | M] Motive -> C:\Documents and Settings\All Users\Application Data\Motive -> [2006/06/29 14:09:35 | 00,000,000 | —D | M] MSN Messenger 6.1.0155 -> C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.1.0155 -> [2006/02/14 22:45:39 | 00,000,000 | —D | M] MSN6 -> C:\Documents and Settings\All Users\Application Data\MSN6 -> [2006/02/14 22:45:46 | 00,000,000 | —D | M] Musicnotes -> C:\Documents and Settings\All Users\Application Data\Musicnotes -> [2008/06/28 10:49:10 | 00,000,000 | —D | M] Office Genuine Advantage -> C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage -> [2008/01/24 21:21:03 | 00,000,000 | —D | M] Real -> C:\Documents and Settings\All Users\Application Data\Real -> [2006/05/21 21:43:41 | 00,000,000 | —D | M] Skype -> C:\Documents and Settings\All Users\Application Data\Skype -> [2007/08/25 20:11:31 | 00,000,000 | —D | M] Spybot - Search & Destroy -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy -> [2008/09/28 13:37:20 | 00,000,000 | —D | M] Viewpoint -> C:\Documents and Settings\All Users\Application Data\Viewpoint -> [2008/09/30 16:07:09 | 00,000,000 | —D | M] Windows Genuine Advantage -> C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage -> [2006/01/26 16:52:43 | 00,000,000 | —D | M] Application Data -> C:\Documents and Settings\winxp\Application Data -> [2008/10/19 18:35:55 | 00,000,000 | RH-D | M] acccore -> C:\Documents and Settings\winxp\Application Data\acccore -> [2006/02/16 18:23:13 | 00,000,000 | —D | M] Adobe -> C:\Documents and Settings\winxp\Application Data\Adobe -> [2008/02/13 16:04:07 | 00,000,000 | —D | M] AdobeUM -> C:\Documents and Settings\winxp\Application Data\AdobeUM -> [2007/05/01 20:56:39 | 00,000,000 | —D | M] Aim -> C:\Documents and Settings\winxp\Application Data\Aim -> [2006/08/18 20:01:07 | 00,000,000 | —D | M] Apple Computer -> C:\Documents and Settings\winxp\Application Data\Apple Computer -> [2008/03/04 22:43:57 | 00,000,000 | —D | M] ATI -> C:\Documents and Settings\winxp\Application Data\ATI -> [2007/09/14 00:10:23 | 00,000,000 | —D | M] BSplayer -> C:\Documents and Settings\winxp\Application Data\BSplayer -> [2006/06/29 15:43:21 | 00,000,000 | —D | M] CyberLink -> C:\Documents and Settings\winxp\Application Data\CyberLink -> [2006/08/18 16:40:58 | 00,000,000 | —D | M] gtk-2.0 -> C:\Documents and Settings\winxp\Application Data\gtk-2.0 -> [2008/05/23 00:08:58 | 00,000,000 | —D | M] Help -> C:\Documents and Settings\winxp\Application Data\Help -> [2008/05/02 19:04:47 | 00,000,000 | —D | M] Identities -> C:\Documents and Settings\winxp\Application Data\Identities -> [2006/01/26 16:48:55 | 00,000,000 | —D | M] ijjigame -> C:\Documents and Settings\winxp\Application Data\ijjigame -> [2008/05/01 21:33:24 | 00,000,000 | -H-D | M] Leadertech -> C:\Documents and Settings\winxp\Application Data\Leadertech -> [2006/04/14 18:09:53 | 00,000,000 | —D | M] LimeWire -> C:\Documents and Settings\winxp\Application Data\LimeWire -> [2008/04/13 17:49:15 | 00,000,000 | —D | M] Macromedia -> C:\Documents and Settings\winxp\Application Data\Macromedia -> [2006/04/05 21:18:09 | 00,000,000 | —D | M] MAGIX -> C:\Documents and Settings\winxp\Application Data\MAGIX -> [2008/09/17 23:27:05 | 00,000,000 | —D | M] Malwarebytes -> C:\Documents and Settings\winxp\Application Data\Malwarebytes -> [2008/09/30 12:50:56 | 00,000,000 | —D | M] Microsoft -> C:\Documents and Settings\winxp\Application Data\Microsoft -> [2008/09/30 15:19:57 | 00,000,000 | –SD | M] Move Networks -> C:\Documents and Settings\winxp\Application Data\Move Networks -> [2007/10/22 16:40:37 | 00,000,000 | —D | M] Mozilla -> C:\Documents and Settings\winxp\Application Data\Mozilla -> [2006/10/29 00:10:43 | 00,000,000 | —D | M] MSN6 -> C:\Documents and Settings\winxp\Application Data\MSN6 -> [2006/09/08 10:48:36 | 00,000,000 | —D | M] MSNInstaller -> C:\Documents and Settings\winxp\Application Data\MSNInstaller -> [2006/07/29 09:24:04 | 00,000,000 | —D | M] Real -> C:\Documents and Settings\winxp\Application Data\Real -> [2006/10/29 00:14:42 | 00,000,000 | —D | M] Registry Booster -> C:\Documents and Settings\winxp\Application Data\Registry Booster -> [2006/10/22 12:34:58 | 00,000,000 | —D | M] Seven Zip -> C:\Documents and Settings\winxp\Application Data\Seven Zip -> [2006/06/04 23:23:07 | 00,000,000 | —D | M] Skype -> C:\Documents and Settings\winxp\Application Data\Skype -> [2007/08/25 20:11:31 | 00,000,000 | —D | M] Sun -> C:\Documents and Settings\winxp\Application Data\Sun -> [2006/05/14 19:07:19 | 00,000,000 | —D | M] Talkback -> C:\Documents and Settings\winxp\Application Data\Talkback -> [2006/10/29 00:10:53 | 00,000,000 | —D | M] U3 -> C:\Documents and Settings\winxp\Application Data\U3 -> [2008/09/14 01:30:25 | 00,000,000 | —D | M] Uniblue -> C:\Documents and Settings\winxp\Application Data\Uniblue -> [2007/04/15 21:15:40 | 00,000,000 | —D | M] Ventrilo -> C:\Documents and Settings\winxp\Application Data\Ventrilo -> [2006/04/07 20:37:58 | 00,000,000 | —D | M] Viewpoint -> C:\Documents and Settings\winxp\Application Data\Viewpoint -> [2006/07/25 14:08:43 | 00,000,000 | —D | M] vlc -> C:\Documents and Settings\winxp\Application Data\vlc -> [2007/12/06 19:06:02 | 00,000,000 | —D | M] Vso -> C:\Documents and Settings\winxp\Application Data\Vso -> [2006/06/04 22:08:52 | 00,000,000 | —D | M] C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2008/08/10 23:27:08 | 00,000,000 | –SD | M] AppleSoftwareUpdate.job -> C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -> [2008/08/29 14:28:10 | 00,000,284 | —- | M] () desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/04 08:00:00 | 00,000,065 | RH– | M] () SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2008/10/19 18:32:05 | 00,000,006 | -H– | M] () [File - Purity Scan] [CatchMe Rootkit Scan by GMER] < Windows folder & sub-folders > scanning hidden processes … scanning hidden services & system hive … scanning hidden registry entries … scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 6 < Document and Settings folder & sub folders > scanning hidden files … C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\Sharing Folders\[removed]\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\01\10-{44B5AFD8-2E05-5F03-028F-DE5DADF03011}-v1-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\12\12-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v12-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7032 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\12\12-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v12-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\13\13-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v13-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8346 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\13\13-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v13-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\14\14-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v14-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9354 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\14\14-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v14-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\15\15-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v15-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7158 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\15\15-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v15-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\16\16-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v16-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8184 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\16\16-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v16-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 912 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\17\17-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v17-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8904 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\17\17-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v17-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1008 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\18\18-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v18-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8670 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\18\18-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v18-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1000 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\19\19-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v19-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8058 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\19\19-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v19-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 896 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\20\20-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v20-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7410 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\20\20-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v20-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 840 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\21\21-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v21-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7590 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\21\21-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v21-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 864 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\22\22-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v22-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7374 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\22\22-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v22-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\23\23-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v23-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8364 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\23\23-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v23-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\24\24-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v24-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7536 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\24\24-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v24-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\25\25-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v25-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7140 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\25\25-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v25-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\26\26-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v26-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6942 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\26\26-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v26-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 784 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\27\27-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v27-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7410 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\27\27-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v27-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\28\28-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v28-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8166 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\28\28-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v28-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 936 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\29\29-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v29-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6654 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\29\29-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v29-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 744 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\30\30-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v30-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8346 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\30\30-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v30-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\31\31-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v31-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7086 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\31\31-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v31-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\32\32-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v32-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8094 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\32\32-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v32-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 880 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\33\33-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v33-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7140 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\33\33-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v33-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\34\34-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v34-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6654 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\34\34-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v34-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 744 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\35\35-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v35-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7320 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\35\35-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v35-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API C:\Documents and Settings\winxp\My Documents\Memory Card\my_pix\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\Memory Card\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Downloads\LimeWire PRO 4.10.7\AC#ACM\AC3ACM\ReadMe\New Folder (3)\New Folder (3)\New Folder (3)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Downloads\LimeWire PRO 4.10.7\AC#ACM\AC3ACM\ReadMe\New Folder (3)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Downloads\LimeWire PRO 4.10.7\AC#ACM\AC3ACM\ReadMe\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\3-3-08\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Albums\BoA\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Albums\KARA (Fin.K.L 2) - The First Blooming\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Albums\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\Praise\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\Review\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\SS\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\TKD\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\ C:\Documents and Settings\winxp\My Documents\My Music\Sancho\ C:\Documents and Settings\winxp\My Documents\My Music\Sancho\ C:\Documents and Settings\winxp\My Documents\My Music\Sancho\ C:\Documents and Settings\winxp\My Documents\My Music\Sancho\English\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\Japanese\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Dance\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Sg wanna be+ & SeeYa\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Sonx\Se7en\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Sonx\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Favorites\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\iTunes\Album Artwork\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\iTunes\iTunes Music\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\iTunes\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Luis Miguel\Segundo Romance\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Luis Miguel\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\Ssantz\School\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\Ssantz\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\Canon\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\Cell Phone\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\CIA\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\Lobster\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\MOMA\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\NY\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\SM Audition\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\TKD\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\ C:\Documents and Settings\winxp\My Documents\My Received Files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Movies\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Music Videos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Performances\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Veoh\thumbs\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Veoh\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\ C:\Documents and Settings\winxp\My Documents\My Videos\ C:\Documents and Settings\winxp\My Documents\My Videos\ C:\Documents and Settings\winxp\My Documents\School Work\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\V3 2007 Ç÷¡Æ¼´½-Æò»ý¾÷µ¥ÀÌÆ®\V3 2007 Platinum(v3 2007 ÀÚµ¿¾÷µ¥ÀÌÆ® )\_Setup\AutoRun\Thumbs.db:encryptable 0 bytes scan completed successfully hidden files: 517 < End of report >
OTScanIt2 logfile created on: 10/19/2008 6:45:44 PM - Run 1
OTScanIt2 by OldTimer - Version 1.0.0.17b	 Folder = C:\Documents and Settings\winxp\Desktop\OTScanIt2
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
511.29 Mb Total Physical Memory | 330.68 Mb Available Physical Memory | 64.68% Memory free
1.22 Gb Paging File | 1.15 Gb Available in Paging File | 94.46% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 92.84 Gb Free Space | 62.29% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: WINXP-A88C7D920
Current User Name: winxp
Logged in as Administrator.
 
Current Boot Mode: SafeMode
Scan Mode: Current user
Whitelist: On
File Age = 90 Days
 
[Processes - Safe List]
notepad.exe -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | —- | M] (Microsoft Corporation)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/10/18 12:23:46 | 00,417,280 | —- | M] (OldTimer Tools)
 
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/07/22 20:42:12 | 00,116,040 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation)
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2evxx.exe -> [2007/08/21 21:57:14 | 00,487,424 | —- | M] (ATI Technologies Inc.)
(ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2sgag.exe -> [2007/08/21 21:05:00 | 00,593,920 | —- | M] ()
(avg8emc) AVG Free8 E-mail Scanner [Win32_Own | Auto | Stopped] -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2008/09/30 15:13:43 | 00,875,288 | —- | M] (AVG Technologies CZ, s.r.o.)
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Stopped] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/09/30 15:13:41 | 00,231,704 | —- | M] (AVG Technologies CZ, s.r.o.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Stopped] ->  -> File not found
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation)
(InCDsrv) InCD Helper [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Ahead\InCD\InCDsrv.exe -> [2005/06/10 18:19:38 | 00,869,888 | —- | M] (Nero AG)
(iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/07/30 10:47:48 | 00,532,264 | —- | M] (Apple Inc.)
(MDM) Machine Debug Manager [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 00:25:00 | 00,322,120 | —- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 13:28:22 | 00,089,136 | —- | M] (Microsoft Corporation)
(PnkBstrA) PnkBstrA [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\PnkBstrA.exe -> [2008/01/05 22:24:53 | 00,066,872 | —- | M] ()
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\MSN Messenger\usnsvc.exe -> [2007/01/19 12:54:14 | 00,097,136 | —- | M] (Microsoft Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\alcxwdm.sys -> [2008/01/24 16:36:16 | 04,127,488 | R— | M] (Realtek Semiconductor Corp.)
(ASPI) Advanced SCSI Programming Interface Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ASPI32.SYS -> [2002/07/17 10:05:10 | 00,016,512 | —- | M] (Adaptec)
(ASPI32) ASPI32 [Kernel | System | Stopped] -> %SystemRoot%\System32\drivers\ASPI32.SYS -> [2002/07/17 10:05:10 | 00,016,512 | —- | M] (Adaptec)
(ati2mtag) ati2mtag [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ati2mtag.sys -> [2007/08/21 22:07:39 | 02,417,664 | —- | M] (ATI Technologies Inc.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Stopped] -> %SystemRoot%\system32\drivers\avgldx86.sys -> [2008/09/30 15:13:58 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Stopped] -> %SystemRoot%\system32\drivers\avgmfx86.sys -> [2008/09/30 15:13:57 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgTdiX) AVG Free8 Network Redirector [Kernel | Auto | Stopped] -> %SystemRoot%\system32\drivers\avgtdix.sys -> [2008/09/30 15:14:01 | 00,076,040 | —- | M] (AVG Technologies CZ, s.r.o.)
(FsVga) FsVga [Kernel | System | Running] -> %SystemRoot%\system32\drivers\fsvga.sys -> [2004/08/04 08:00:00 | 00,012,160 | —- | M] (Microsoft Corporation)
(GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> [2008/01/29 12:01:28 | 00,016,168 | —- | M] (GEAR Software Inc.)
(ialm) ialm [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ialmnt5.sys -> [2004/11/01 21:27:20 | 00,773,565 | R— | M] (Intel Corporation)
(InCDfs) InCD File System [File_System | Disabled | Stopped] -> %SystemRoot%\System32\drivers\InCDfs.sys -> [2005/06/10 18:12:12 | 00,099,584 | —- | M] (Nero AG)
(InCDPass) InCDPass [Kernel | System | Running] -> %SystemRoot%\system32\drivers\InCDpass.sys -> [2005/06/10 18:11:50 | 00,029,696 | —- | M] (Nero AG)
(incdrm) InCD Reader [Kernel | System | Running] -> %SystemRoot%\System32\drivers\InCDrm.sys -> [2005/06/10 10:11:44 | 00,028,160 | —- | M] (Nero AG)
(pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pfc.sys -> [2003/12/05 05:46:36 | 00,010,368 | —- | M] (Padus, Inc.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2004/08/04 08:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> [2007/03/29 03:00:00 | 00,043,528 | —- | M] (Sonic Solutions)
(RTL8023xp) Realtek 10/100/1000 NIC Family all in one NDIS XP Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Rtlnicxp.sys -> [2005/03/03 23:10:26 | 00,074,496 | R— | M] (Realtek Semiconductor Corporation						   )
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\RTL8139.sys -> [2004/08/03 18:31:34 | 00,020,992 | —- | M] (Realtek Semiconductor Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(STEC3) STEC3 [Kernel | Auto | Stopped] -> %SystemRoot%\system32\STEC3.sys -> [2007/11/27 17:38:48 | 00,002,368 | —- | M] (AntiCracking)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usbaapl.sys -> [2008/07/22 20:32:44 | 00,032,000 | —- | M] (Apple, Inc.)
(USB_RNDIS_XP) Westell WireSpeed Dual Connect Modem [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usb8023.sys -> [2008/04/13 14:56:49 | 00,012,800 | —- | M] (Microsoft Corporation)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\windows\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> 
HKEY_LOCAL_MACHINE\: Search\\"" ->  -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
HKEY_LOCAL_MACHINE\: SearchURL\\"" ->  -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\windows\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> 
HKEY_CURRENT_USER\: SearchURL\\"" -> http://home.microsoft.com/access/autosearch.asp?p=%s -> 
HKEY_CURRENT_USER\: SearchURL\\"provider" ->  -> 
HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> 
HKEY_CURRENT_USER\: "ProxyOverride" -> 127.0.0.1;*.local -> 
< HOSTS File > (27 bytes and 1 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
127.0.0.1	   localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{030A0F33-5B99-482E-83F5-2EEB8457878B} [HKLM] -> %SystemRoot%\system32\675873\675873.dll [675873 Class] -> File not found
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2008/09/30 15:13:47 | 00,455,960 | —- | M] (AVG Technologies CZ, s.r.o.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_10\bin\ssv.dll [SSVHelper Class] -> [2006/11/09 16:21:52 | 00,440,056 | —- | M] (Sun Microsystems, Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{D0943516-5076-4020-A3B5-AEFAF26AB263}" [HKLM] -> %ProgramFiles%\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [Veoh Browser Plug-in] -> [2008/02/22 21:31:18 | 00,352,256 | —- | M] (Veoh Networks Inc)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{144A6B24-0EBC-4D89-BF09-A06A718E57B5}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2008/10/01 09:38:16 | 01,234,712 | —- | M] (AVG Technologies CZ, s.r.o.)
"IMJPMIG8.1" -> %SystemRoot%\ime\imjp8_1\imjpmig.exe ["C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] -> [2004/08/04 08:00:00 | 00,208,952 | —- | M] (Microsoft Corporation)
"iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/07/30 10:47:56 | 00,289,064 | —- | M] (Apple Inc.)
"MSConfig" -> %SystemRoot%\pchealth\helpctr\binaries\msconfig.exe [C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto] -> [2008/04/13 20:12:27 | 00,169,984 | —- | M] (Microsoft Corporation)
"MSPY2002" -> %SystemRoot%\system32\IME\PINTLGNT\IMSCINST.EXE [C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC] -> [2004/08/04 08:00:00 | 00,059,392 | —- | M] ()
"PHIME2002A" -> %SystemRoot%\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2004/08/04 08:00:00 | 00,455,168 | —- | M] (Microsoft Corporation)
"PHIME2002ASync" -> %SystemRoot%\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> [2004/08/04 08:00:00 | 00,455,168 | —- | M] (Microsoft Corporation)
"SoundMan" -> %SystemRoot%\soundman.exe [SOUNDMAN.EXE] -> [2007/04/16 15:28:22 | 00,577,536 | —- | M] (Realtek Semiconductor Corp.)
"StartCCC" -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ["C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"] -> [2006/11/10 12:35:24 | 00,090,112 | —- | M] ()
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
< winxp Startup Folder > -> C:\Documents and Settings\winxp\Start Menu\Programs\Startup -> 
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer -> 
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [227] -> File not found
\\"NoDrives" ->  [0] -> File not found
\\"NoDriveAutoRun" ->  [67108863] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"HideLegacyLogonScripts" ->  [0] -> File not found
\\"HideLogoffScripts" ->  [0] -> File not found
\\"RunLogonScriptSync" ->  [1] -> File not found
\\"RunStartupScriptSync" ->  [0] -> File not found
\\"HideStartupScripts" ->  [0] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"HideLegacyLogonScripts" ->  [0] -> File not found
\\"HideLogoffScripts" ->  [0] -> File not found
\\"HideStartupScripts" ->  [0] -> File not found
\\"RunLogonScriptSync" ->  [1] -> File not found
\\"RunStartupScriptSync" ->  [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&D&ownload &with BitComet -> %ProgramFiles%\BitComet\BitComet.exe [res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com)
&D&ownload all video with BitComet -> %ProgramFiles%\BitComet\BitComet.exe [res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com)
&D&ownload all with BitComet -> %ProgramFiles%\BitComet\BitComet.exe [res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com)
E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2008/08/04 16:12:50 | 10,354,176 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_10\bin\NPJPI150_10.dll [Menu: Sun Java Console] -> [2006/11/09 16:21:53 | 00,075,528 | —- | M] (Sun Microsystems, Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2007/04/19 14:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 19:26:26 | 00,947,472 | —- | M] (Microsoft Corporation)
CmdMapping\\"{867AB302-E62F-4e8e-B297-6444A9C81D09}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{9034A523-D068-4BE8-A284-9DF278BE776E}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 14:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4836 domain(s) found. -> 
46 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4880 domain(s) found. -> 
download.com .[*]-> Trusted sites ->
www_google.com [https] -> Trusted sites -> 48 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 37 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=67633[Office Genuine Advantage Validation Tool] -> {0B96BF84-DA5C-46F4-A7FC-5319CFF74163} [HKLM] -> http://player.mnet.com/package/cjmuset.cab[MnetLauncher Control] -> {0CCA191D-13A6-4E29-B746-314DEE697D83} [HKLM] -> http://upload.facebook.com/controls/FacebookPhotoUploader5.cab[Facebook Photo Uploader 5] -> {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} [HKLM] -> http://www.musicnotes.com/download/mnviewer.cab[Musicnotes Viewer] -> {166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab[Shockwave ActiveX Control] -> {17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=39204[Windows Genuine Advantage Validation Tool] -> {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} [HKLM] -> http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB[Tpwin Control] -> {20A60F0D-9AFA-4515-A0FD-83BD84642501} [HKLM] -> http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab[Checkers Class] -> {5C051655-FCD5-4969-9182-770EA5AA5565} [HKLM] -> http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab[Solitaire Showdown Class] -> {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} [HKLM] -> http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab[DaumBGMCtrl Class] -> {7FC1B346-83E6-4774-8D20-1A6B09B0E737} [HKLM] -> http://cid-2062e4c29cecd973.spaces.live.com/PhotoUpload/MsnPUpld.cab[Windows Live Photo Upload Control] -> {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} [HKLM] -> http://www.maxmp3.co.kr/Ver2/App/totalApp/maxhelper/maxhelper.cab[Reg Error: Key does not exist or could not be opened.] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {938527D1-CDB7-4147-998A-B20FCA5CC976} [HKLM] -> http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10[Cdmcco Class] -> {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} [HKLM] -> http://cafeimg.hanmail.net/cto/1_2_3_5/xman.cab?ver=1,2,3,5[Daum ActiveX manager Class] -> {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} [HKLM] -> http://install.bugs.co.kr/install/BugsInstallerEx.cab[BugsInstallEx Control] -> {BFB6D72C-1030-47E4-88A2-614ACCC92467} [HKLM] -> http://www.maxmp3.co.kr/MaxMP3/Html/MPlayer/Movie/__P2P__/Package/p3mxvset.cab[MaxMp3VSet Class] -> {C3F79A2B-B9B4-4A66-B012-3EE46475B072} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab[MessengerStatsClient Class] -> {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab[Java Plug-in 1.5.0_06] -> {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} [HKLM] -> http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab[Minesweeper Flags Class] -> {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} [HKLM] -> http://www.clubbox.co.kr/neo.fld/MultiUpload.cab[MultiUpload Control] -> Microsoft XML Parser for Java [HKLM] -> file://C:\WINDOWS\Java\classes\xmldso.cab[Reg Error: Key does not exist or could not be opened.] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {071D6C45-70FF-4BAF-A962-2492D96B0B6F} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {0A2B9F81-D36A-46CE-8E0B-4700F7709A2B} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {200DD75C-B1D1-49D6-BB6E-79C452CFD4BC} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {286AF6EB-159D-4E76-8AA6-289F273CDF40} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {3075C271-0468-46ED-8465-57D461DCA6CA} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {31542321-274D-4BE1-87C2-6D900C548D20} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {360F233C-3A83-43D1-83A9-A990E66E7007} -> () -> {3839BC48-2BD9-4C36-90C3-BD799DC43DAF} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {38DC29AB-CDDA-4FD0-BCF9-E57929BD9148} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {3B26581C-74C6-4FDA-861E-A40A8FD76B85} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {41999A77-3DE0-44A6-95F5-2A146BA5752A} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {48EDF500-2504-4497-8C0F-5AC6D497B85F} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {4A0ADBC5-EF89-49BC-9246-AA7FE6FE99C0} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {522D2FCE-D13F-41A8-9D27-4630B0EDB16A} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {6BFECF85-09E9-4B7C-BE38-41DC51E48595} -> (1394 Net Adapter) -> {6DE86882-D361-4474-B718-9A7D03892B04} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {75BDDF19-2423-46A9-BF6A-3DEC91CE8F32} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {786699C2-7332-4173-847E-72D757B4FFFF} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {903A496C-52C8-4FB0-9F77-92886AD6F864} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {999D8D0E-013B-4045-B84E-DCE6010AABE2} -> (Westell WireSpeed Dual Connect Modem) -> {9F1B87A7-4840-4940-A317-20636963E260} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {A0B94B5F-1FAA-4CFE-A670-0690221E447F} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {A5A49757-DF49-47F9-972A-A104F92F3FB0} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {A5F8252B-7A53-4B3E-A4F2-3F9E011D2EB8} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {B187D059-C994-477B-B0D0-AF4A61FD0B57} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {B2802976-A05F-427D-8524-274EB9C17B5E} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {B2EE89A9-69F3-4CF7-AD6F-BD5FBF32405C} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {B631C3C0-4499-4E2F-8527-8D865C0D4C50} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {BA012AB4-72DF-4939-86C5-93CE8FEBF682} -> (1394 Net Adapter) -> {C0BC3CD5-5184-42FB-88F7-D860D88D20E2} -> () -> {DBDA3452-D2F5-40F8-A387-9C470D6E2D1C} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {F3F10CFF-2B61-42F1-96F9-D9D3091566FC} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {F7BDF2D4-8AEC-43F3-A8D5-A50E69C69EED} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {F8D71487-3173-478F-B0E6-8BFD0911B767} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll -> [2007/08/21 21:58:42 | 00,122,880 | —- | M] (ATI Technologies Inc.) igfxcui -> %SystemRoot%\system32\igfxsrvc.dll -> [2004/11/01 20:59:20 | 00,348,160 | R— | M] (Intel Corporation) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | —- | M] (Microsoft Corporation) "C:\Program Files\AIM\aim.exe" -> C:\Program Files\AIM\aim.exe [C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger] -> File not found "C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe [C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe:*:Enabled:AOL Services] -> [2005/08/02 15:33:02 | 00,151,640 | —- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 03:17:27 | 00,010,800 | —- | M] (AOL LLC) "C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | —- | M] (Microsoft Corporation) "C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme" -> C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme [C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme:*:Enabled:GunBound] -> [2008/05/16 16:08:10 | 01,359,872 | —- | M] (Softnyx) "C:\ijji\ENGLISH\u_gbound.exe" -> C:\ijji\ENGLISH\u_gbound.exe [C:\ijji\ENGLISH\u_gbound.exe:*:Enabled:] -> [2008/05/19 22:06:06 | 00,868,352 | —- | M] (NHN USA inc.) "C:\Program Files\AIM6\aim6.exe" -> C:\Program Files\AIM6\aim6.exe [C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM] -> [2008/01/03 12:15:06 | 00,050,528 | —- | M] (AOL LLC) "C:\Program Files\AVG\AVG8\avgemc.exe" -> C:\Program Files\AVG\AVG8\avgemc.exe [C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe] -> [2008/09/30 15:13:43 | 00,875,288 | —- | M] (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG8\avgupd.exe" -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> [2008/09/30 15:13:44 | 00,641,304 | —- | M] (AVG Technologies CZ, s.r.o.) "C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe [C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe:*:Enabled:AIM] -> [2006/08/28 16:22:24 | 00,050,768 | —- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe [C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe:*:Enabled:AOL Services] -> [2005/08/02 15:33:02 | 00,151,640 | —- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe [C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe:*:Enabled:AOL Services] -> [2006/05/09 20:24:16 | 00,050,760 | —- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 03:17:27 | 00,010,800 | —- | M] (AOL LLC) "C:\Program Files\EA GAMES\Battlefield 2\BF2.exe" -> C:\Program Files\EA GAMES\Battlefield 2\BF2.exe [C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2] -> [2006/09/26 18:53:22 | 07,574,463 | —- | M] () "C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/07/30 10:47:50 | 20,252,968 | —- | M] (Apple Inc.) "C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> [2006/02/10 19:14:27 | 00,081,920 | —- | M] (Lime Wire, LLC) "C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) "C:\WINDOWS\system32\BugsSvr.exe" -> C:\WINDOWS\system32\BugsSvr.exe [C:\WINDOWS\system32\BugsSvr.exe:*:Enabled:Bugs Music Player Control] -> [2005/12/23 17:03:32 | 00,167,936 | —- | M] () "C:\WINDOWS\system32\cjmvsvr.exe" -> C:\WINDOWS\system32\cjmvsvr.exe [C:\WINDOWS\system32\cjmvsvr.exe:*:Enabled:CJMUSIC VoD Control] -> [2007/05/03 18:50:05 | 00,176,128 | —- | M] (© CJ MUSIC) "C:\WINDOWS\system32\clubbox.exe" -> C:\WINDOWS\system32\clubbox.exe [C:\WINDOWS\system32\clubbox.exe:*:Enabled:CLUBBOX File Transfer Manager] -> [2008/02/28 06:58:00 | 01,536,000 | R— | M] (Nowcom, Co. LTD.) "C:\WINDOWS\system32\fscagent.exe" -> C:\WINDOWS\system32\fscagent.exe [C:\WINDOWS\system32\fscagent.exe:*:Enabled:???? ???? ??] -> [2008/02/25 12:24:40 | 00,159,744 | R— | M] (Nowcom Co., Ltd.) "C:\WINDOWS\system32\p3bvsvr.exe" -> C:\WINDOWS\system32\p3bvsvr.exe [C:\WINDOWS\system32\p3bvsvr.exe:*:Enabled:Bugs Music VoD Control] -> [2006/02/18 11:38:09 | 00,167,936 | —- | M] (© PeeringPortal) "C:\WINDOWS\system32\P3MxSvr.exe" -> C:\WINDOWS\system32\P3MxSvr.exe [C:\WINDOWS\system32\P3MxSvr.exe:*:Enabled:Maxmp3 AoD Control] -> [2007/06/20 12:17:54 | 00,159,744 | —- | M] () "C:\WINDOWS\system32\p3mxvsvr.exe" -> C:\WINDOWS\system32\p3mxvsvr.exe [C:\WINDOWS\system32\p3mxvsvr.exe:*:Enabled:MAXMP3 VOD Control] -> [2007/02/12 11:12:48 | 00,202,520 | —- | M] (Maxmp3) "C:\WINDOWS\system32\skcbgm.exe" -> C:\WINDOWS\system32\skcbgm.exe [C:\WINDOWS\system32\skcbgm.exe:*:Enabled:SK Communications Cyworld BGM Player] -> [2007/01/09 18:15:26 | 00,163,840 | —- | M] (© SK Communications) < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 14:40:46 | 00,062,976 | —- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2006/01/26 16:44:23 | 00,000,000 | —- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell \I\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell\AutoRun \I\Shell\AutoRun\\"" -> [Auto&Play] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell\AutoRun\command \I\Shell\AutoRun\command\\"" -> I:\LaunchU3.exe [I:\LaunchU3.exe -a] -> File not found [Registry - Additional Scans - Safe List] < App Paths [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ -> AcroRd32.exe -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AcroRd32.exe [C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe] -> [2006/05/16 23:15:10 | 00,071,288 | —- | M] (Adobe Systems Incorporated) AVGSE.DLL -> %ProgramFiles%\AVG\AVG8\avgse.dll [C:\PROGRA~1\AVG\AVG8\avgse.dll] -> [2008/09/30 15:13:46 | 00,099,608 | —- | M] (AVG Technologies CZ, s.r.o.) BackItUp.EXE -> %ProgramFiles%\Ahead\Nero BackItUp\BackItUp.exe [C:\Program Files\Ahead\Nero BackItUp\BackItUp.exe] -> [2005/05/19 20:36:56 | 05,758,976 | —- | M] (Ahead Software AG) bckgzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\bckgzm.exe [C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe] -> [2004/08/04 08:00:00 | 00,042,577 | —- | M] (Microsoft Corporation) BitComet.exe -> %ProgramFiles%\BitComet\BitComet.exe [C:\Program Files\BitComet\BitComet.exe] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com) chkrzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\chkrzm.exe [C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe] -> [2004/08/04 08:00:00 | 00,042,575 | —- | M] (Microsoft Corporation) cmmgr32.exe -> %SystemRoot%\system32\cmmgr32.exe [C:\WINDOWS\system32\cmmgr32.exe] -> File not found CONF.EXE -> %ProgramFiles%\NetMeeting\conf.exe [C:\Program Files\NetMeeting\conf.exe] -> [2008/04/13 20:12:15 | 01,032,192 | —- | M] (Microsoft Corporation) ConvertMovie 3.0 -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found dialer.exe -> %ProgramFiles%\Windows NT\dialer.exe [C:\Program Files\Windows NT\dialer.exe] -> [2008/04/13 20:12:17 | 00,539,136 | —- | M] (Microsoft Corporation) DVD Solution -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found EPSON CardMonitor1.1.exe -> %ProgramFiles%\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe [C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe] -> [2003/07/25 01:00:00 | 00,258,048 | —- | M] (SEIKO EPSON CORPORATION) EPSON PhotoStarter3.0.exe -> %ProgramFiles%\EPSON\EPSON PhotoStarter3.0\EPSON PhotoStarter3.0.exe [C:\Program Files\EPSON\EPSON PhotoStarter3.0\EPSON PhotoStarter3.0.exe] -> [2002/02/27 02:16:00 | 04,841,472 | —- | M] (SEIKO EPSON CORPORATION) EPSONCD.exe -> %ProgramFiles%\EPSON Print CD\EPSONCD.exe [C:\Program Files\EPSON Print CD\EPSONCD.exe] -> [2003/08/14 01:20:00 | 02,723,840 | —- | M] (EPSON) excel.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE] -> [2008/08/04 16:12:50 | 10,354,176 | —- | M] (Microsoft Corporation) gimp-2.4.exe -> %ProgramFiles%\GIMP-2.0\bin\gimp-2.4.exe [C:\Program Files\GIMP-2.0\bin\gimp-2.4.exe] -> File not found HELPCTR.EXE -> %SystemRoot%\pchealth\helpctr\binaries\helpctr.exe [C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe] -> [2008/04/13 20:12:21 | 00,769,024 | —- | M] (Microsoft Corporation) HijackThis.exe -> %ProgramFiles%\Trend Micro\HijackThis\HijackThis.exe [C:\Program Files\Trend Micro\HijackThis\hijackthis.exe] -> [2008/09/29 20:51:14 | 00,396,288 | —- | M] (Trend Micro Inc.) hrtzzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\hrtzzm.exe [C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe] -> [2004/08/04 08:00:00 | 00,042,573 | —- | M] (Microsoft Corporation) hypertrm.exe -> %ProgramFiles%\Windows NT\hypertrm.exe ["C:\Program Files\Windows NT\hypertrm.exe"] -> [2004/08/04 08:00:00 | 00,028,160 | —- | M] (Hilgraeve, Inc.) ICWCONN1.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE"] -> [2008/04/13 20:12:22 | 00,214,528 | —- | M] (Microsoft Corporation) ICWCONN2.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn2.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE"] -> [2008/04/13 20:12:22 | 00,086,016 | —- | M] (Microsoft Corporation) IEXPLORE.EXE -> %ProgramFiles%\Internet Explorer\iexplore.exe [C:\Program Files\Internet Explorer\iexplore.exe] -> [2008/04/13 20:12:22 | 00,093,184 | —- | M] (Microsoft Corporation) InCD.exe -> %ProgramFiles%\Ahead\InCD\InCD.exe [C:\Program Files\Ahead\InCD\InCD.exe] -> [2005/06/10 10:20:06 | 01,397,760 | —- | M] (Nero AG) INETWIZ.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\inetwiz.exe ["C:\Program Files\Internet Explorer\Connection Wizard\INETWIZ.EXE"] -> [2008/04/13 20:12:22 | 00,020,480 | —- | M] (Microsoft Corporation) install.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found InstallHelper.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found IPHSend.exe -> %CommonProgramFiles%\AOL\IPHSend\IPHSend.exe [C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe] -> [2006/02/17 12:59:46 | 00,124,520 | —- | M] (America Online, Inc.) ISIGNUP.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\isignup.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ISIGNUP.EXE"] -> [2004/08/04 08:00:00 | 00,016,384 | —- | M] (Microsoft Corporation) iTunes.exe -> %ProgramFiles%\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe] -> [2008/07/30 10:47:50 | 20,252,968 | —- | M] (Apple Inc.) javaws.exe -> %ProgramFiles%\Java\jre1.5.0_10\bin\javaws.exe [C:\Program Files\Java\jre1.5.0_10\bin\javaws.exe] -> [2006/11/09 16:07:32 | 00,127,078 | —- | M] (Sun Microsystems, Inc.) mbam.exe -> %ProgramFiles%\Malwarebytes' Anti-Malware\mbam.exe [C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe] -> [2008/09/10 00:03:54 | 01,253,040 | —- | M] (Malwarebytes Corporation) migwiz.exe -> %SystemRoot%\system32\usmt\migwiz.exe [%SystemRoot%\system32\usmt\migwiz.exe] -> [2008/04/13 20:12:25 | 00,245,248 | —- | M] (Microsoft Corporation) moviemk.exe -> %ProgramFiles%\Movie Maker\moviemk.exe [C:\Program Files\Movie Maker\moviemk.exe] -> [2008/04/13 20:12:27 | 03,558,912 | —- | M] (Microsoft Corporation) mplayer2.exe -> %ProgramFiles%\Windows Media Player\mplayer2.exe ["C:\Program Files\Windows Media Player\mplayer2.exe"] -> [2008/04/13 20:12:27 | 00,004,639 | —- | M] (Microsoft Corporation) MSCONFIG.EXE -> %SystemRoot%\pchealth\helpctr\binaries\msconfig.exe [C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE] -> [2008/04/13 20:12:27 | 00,169,984 | —- | M] (Microsoft Corporation) msimn.exe -> %ProgramFiles%\Outlook Express\msimn.exe [%ProgramFiles%\Outlook Express\msimn.exe] -> [2008/04/13 20:12:28 | 00,060,416 | —- | M] (Microsoft Corporation) msinfo32.exe -> %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe [C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe] -> [2004/08/04 08:00:00 | 00,039,936 | —- | M] (Microsoft Corporation) MSMSGS.EXE -> %ProgramFiles%\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation) MSN.EXE -> %ProgramFiles%\MSN\MSNCoreFiles\msn.exe [C:\Program Files\MSN\MSNCoreFiles\msn.exe] -> [2006/05/30 13:19:20 | 00,093,696 | —- | M] (Microsoft Corporation) MSNMSGR.EXE -> %ProgramFiles%\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\MsnMsgr.Exe] -> [2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) MsoHtmEd.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found msoxmled.exe -> %CommonProgramFiles%\Microsoft Shared\OFFICE11\MSOXMLED.EXE [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLED.EXE] -> [2007/03/22 19:13:38 | 00,058,720 | —- | M] (Microsoft Corporation) mspview.exe -> %CommonProgramFiles%\Microsoft Shared\MODI\11.0\MSPVIEW.EXE [C:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0\MSPVIEW.EXE] -> [2007/04/09 13:24:00 | 00,367,496 | —- | M] (Microsoft Corporation) NCoverEd.exe -> %ProgramFiles%\Ahead\CoverDesigner\CoverDes.exe [C:\Program Files\Ahead\CoverDesigner\CoverDes.exe] -> [2005/05/24 20:48:44 | 02,441,216 | —- | M] (Nero AG) nero.exe -> %ProgramFiles%\Ahead\Nero\nero.exe [C:\Program Files\Ahead\nero\nero.exe] -> [2005/06/16 10:30:44 | 15,413,318 | —- | M] (Ahead Software AG) NeroStartSmart.exe -> %ProgramFiles%\Ahead\Nero StartSmart\NeroStartSmart.exe [C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart.exe] -> [2005/05/23 22:19:36 | 04,735,065 | —- | M] (Ahead Software AG) ois.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\OIS.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\OIS.EXE] -> [2007/03/22 19:06:22 | 00,287,576 | —- | M] (Microsoft Corporation) OUTLOOK.EXE -> %ProgramFiles%\Microsoft Office\OFFICE11\OUTLOOK.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE] -> [2008/04/23 15:09:50 | 00,199,688 | —- | M] (Microsoft Corporation) pbrush.exe -> %SystemRoot%\system32\mspaint.exe [%SystemRoot%\system32\mspaint.exe] -> [2008/04/13 20:12:28 | 00,343,040 | —- | M] (Microsoft Corporation) PictureViewer.exe -> %ProgramFiles%\K-Lite Codec Pack\QuickTime\PictureViewer.exe [C:\Program Files\K-Lite Codec Pack\QuickTime\PictureViewer.exe] -> [2008/05/27 10:50:24 | 00,548,864 | —- | M] (Apple Inc.) pinball.exe -> %ProgramFiles%\Windows NT\Pinball\pinball.exe [C:\Program Files\Windows NT\Pinball\pinball.exe] -> [2008/04/13 20:12:31 | 00,281,088 | —- | M] (Cinematronics) PowerBar -> %ProgramFiles%\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe [C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe] -> [2004/04/21 11:26:28 | 00,086,016 | —- | M] (Cyberlink, Corp.) powerpnt.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\POWERPNT.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\POWERPNT.EXE] -> [2008/07/03 18:33:40 | 06,421,512 | —- | M] (Microsoft Corporation) QuickTimePlayer.exe -> %ProgramFiles%\K-Lite Codec Pack\QuickTime\QuickTimePlayer.exe [C:\Program Files\K-Lite Codec Pack\QuickTime\QuickTimePlayer.exe] -> [2008/05/27 10:50:48 | 07,677,232 | —- | M] (Apple Inc.) RKVideoConverter.exe -> %ProgramFiles%\Red Kawa\Video Converter 3\RKVideoConverter.exe [C:\Program Files\Red Kawa\Video Converter 3\RKVideoConverter.exe] -> [2007/12/17 22:07:04 | 00,733,184 | —- | M] (Red Kawa Inc.) rvsezm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\Rvsezm.exe [C:\Program Files\MSN Gaming Zone\Windows\rvsezm.exe] -> [2004/08/04 08:00:00 | 00,042,574 | —- | M] (Microsoft Corporation) schdpl32.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\1033\SCHDPL32.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\1033\SCHDPL32.EXE] -> [2003/04/03 22:21:40 | 00,190,848 | —- | M] (Microsoft Corporation) setup.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found shvlzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\shvlzm.exe [C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe] -> [2004/08/04 08:00:00 | 00,042,573 | —- | M] (Microsoft Corporation) sinf.exe -> %CommonProgramFiles%\AOL\System Information\sinf.exe [C:\Program Files\Common Files\AOL\System Information\sinf.exe] -> File not found table30.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found wab.exe -> %ProgramFiles%\Outlook Express\wab.exe [%ProgramFiles%\Outlook Express\wab.exe] -> [2008/04/13 20:12:38 | 00,046,080 | —- | M] (Microsoft Corporation) wabmig.exe -> %ProgramFiles%\Outlook Express\wabmig.exe [%ProgramFiles%\Outlook Express\wabmig.exe] -> [2008/04/13 20:12:39 | 00,030,208 | —- | M] (Microsoft Corporation) winnt32.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found WinRAR.exe -> %ProgramFiles%\WinRAR\WinRAR.exe [C:\Program Files\WinRAR\WinRAR.exe] -> [2005/10/10 11:14:38 | 00,881,664 | —- | M] () Winword.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\WINWORD.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\WINWORD.EXE] -> [2008/07/03 18:36:56 | 12,313,096 | —- | M] (Microsoft Corporation) WMPBurn.exe -> %ProgramFiles%\Ahead\WMPBurn\WMPBurn.exe [C:\Program Files\Ahead\WMPBurn\WMPBurn.exe] -> [2004/01/08 18:19:24 | 01,265,664 | —- | M] (Ahead Software AG) wmplayer.exe -> %ProgramFiles%\Windows Media Player\wmplayer.exe [C:\Program Files\Windows Media Player\wmplayer.exe] -> [2006/10/18 21:46:20 | 00,064,000 | —- | M] (Microsoft Corporation) WORDPAD.EXE -> %ProgramFiles%\Windows NT\Accessories\wordpad.exe ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008/04/13 20:12:40 | 00,214,528 | —- | M] (Microsoft Corporation) WRITE.EXE -> %ProgramFiles%\Windows NT\Accessories\wordpad.exe ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008/04/13 20:12:40 | 00,214,528 | —- | M] (Microsoft Corporation) yourapp.Exe -> %ProgramFiles%\VisionWork\ReadPhonics\yourapp.Exe [C:\Program Files\VisionWork\ReadPhonics\yourapp.Exe] -> File not found < Disabled MSConfig Folder Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\ -> C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> [2005/09/23 22:05:26 | 00,029,696 | —- | M] (Adobe Systems Incorporated) < Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ -> AppleSyncNotifier hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe -> [2008/07/22 20:42:24 | 00,116,040 | —- | M] (Apple Inc.) ClubBox hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemRoot%\system32\clubbox.exe -> [2008/02/28 06:58:00 | 01,536,000 | R— | M] (Nowcom, Co. LTD.) EPSON Stylus Photo R300 Series hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemRoot%\system32\spool\drivers\w32x86\3\E_S4I2F1.EXE -> [2003/06/04 03:00:00 | 00,099,840 | —- | M] (SEIKO EPSON CORPORATION) HostManager hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\AOL\1140128537\ee\aolsoftware.exe -> [2006/05/09 20:24:16 | 00,050,760 | —- | M] (America Online, Inc.) HotKeysCmds hkey= key= -> -> File not found IgfxTray hkey= key= -> -> File not found InCD hkey= key= -> -> File not found IPHSend hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\AOL\IPHSend\IPHSend.exe -> [2006/02/17 12:59:46 | 00,124,520 | —- | M] (America Online, Inc.) iPlusAgent2 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\iriver\iriver plus 2\iAgent2.exe -> [2005/06/07 08:27:06 | 00,237,568 | —- | M] (Yurion, Inc.) iTunesHelper hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008/07/30 10:47:56 | 00,289,064 | —- | M] (Apple Inc.) NeroFilterCheck hkey= key= -> -> File not found PlaxoUpdate hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Plaxo\2.13.1.6\PlaxoHelper.exe -> [2008/04/14 17:36:46 | 00,227,914 | —- | M] (Plaxo, Inc.) PowerBar hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe -> [2004/04/21 11:26:28 | 00,086,016 | —- | M] (Cyberlink, Corp.) QuickTime Task hkey= key= -> -> File not found SFP hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\Verizon Online\SFP\vzSFPWin.exe -> [2003/09/05 16:30:18 | 00,561,152 | —- | M] (Verizon Internet Solutions) SoundMan hkey= key= -> -> File not found Steam hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Steam\steam.exe -> [2008/03/27 19:30:27 | 01,271,032 | —- | M] (Valve Corporation) SunJavaUpdateSched hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Java\jre1.5.0_10\bin\jusched.exe -> [2006/11/09 16:07:30 | 00,049,263 | —- | M] (Sun Microsystems, Inc.) updateMgr hkey= key= -> -> File not found VirRL2009 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\VirRL2009\VirRL2009.exe -> File not found < Disabled MSConfig State [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state -> "bootini" -> 0 -> "services" -> 0 -> "startup" -> 2 -> "system.ini" -> 0 -> "win.ini" -> 0 -> < File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .bat [@ = batfile] -> "%1" %* -> .chm [@ = chm.file] -> %SystemRoot%\hh.exe -> [2008/04/13 20:12:21 | 00,010,752 | —- | M] (Microsoft Corporation) .cmd [@ = cmdfile] -> "%1" %* -> .com [@ = ComFile] -> "%1" %* -> .exe [@ = exefile] -> "%1" %* -> .hlp [@ = hlpfile] -> %SystemRoot%\system32\winhlp32.exe -> [2004/08/04 08:00:00 | 00,008,192 | —- | M] (Microsoft Corporation) .hta [@ = htafile] -> %SystemRoot%\system32\mshta.exe -> [2008/04/13 20:12:27 | 00,029,184 | —- | M] (Microsoft Corporation) .html [@ = aol_htm] -> %ProgramFiles%\AOL\Explorer\1.2\AOLExplorer.exe -> [2005/11/02 23:01:14 | 00,050,792 | —- | M] (America Online, Inc.) .inf [@ = inffile] -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | —- | M] (Microsoft Corporation) .ini [@ = inifile] -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | —- | M] (Microsoft Corporation) .js [@ = JSFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .jse [@ = JSEFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .pif [@ = piffile] -> "%1" %* -> .reg [@ = regfile] -> %SystemRoot%\regedit.exe -> [2008/04/13 20:12:32 | 00,146,432 | —- | M] (Microsoft Corporation) .scr [@ = scrfile] -> "%1" /S -> .txt [@ = txtfile] -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | —- | M] (Microsoft Corporation) .vbe [@ = VBEFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .vbs [@ = VBSFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .wsf [@ = WSFFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) .wsh [@ = WSHFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | —- | M] (Microsoft Corporation) < EventViewer Logs - Last 10 Errors > -> Event Information -> Description Application [ Error ] 2/1/2008 4:36:48 PM Computer Name = WINXP-A88C7D920 | Source = crypt32 | ID = 131083 -> Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Application [ Error ] 2/1/2008 4:36:48 PM Computer Name = WINXP-A88C7D920 | Source = crypt32 | ID = 131083 -> Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Application [ Error ] 7/23/2008 1:41:27 PM Computer Name = WINXP-A88C7D920 | Source = SecurityCenter | ID = 1802 -> Description = The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus and Firewall. Application [ Error ] 8/26/2008 11:50:28 PM Computer Name = WINXP-A88C7D920 | Source = MsiInstaller | ID = 11905 -> Description = Product: ESScore – Error 1905.Module C:\Program Files\Kodak\Kodak EasyShare software\bin\vdt.dll failed to unregister. HRESULT -2147220472. Contact your support personnel. Application [ Error ] 8/26/2008 11:50:53 PM Computer Name = WINXP-A88C7D920 | Source = MsiInstaller | ID = 11905 -> Description = Product: ESSgui – Error 1905.Module C:\Program Files\Kodak\Kodak EasyShare software\bin\ESCom.dll failed to unregister. HRESULT -2147220472. Contact your support personnel. System [ Error ] 10/19/2008 6:34:57 PM Computer Name = WINXP-A88C7D920 | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7001 -> Description = The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: %%31 System [ Error ] 10/19/2008 6:35:29 PM Computer Name = WINXP-A88C7D920 | Source = Service Control Manager | ID = 7026 -> Description = The following boot-start or system-start driver(s) failed to load: AFD ASPI32 AvgLdx86 AvgMfx86 Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip System [ Error ] 10/19/2008 6:42:56 PM Computer Name = WINXP-A88C7D920 | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} System [ Error ] 10/19/2008 6:44:37 PM Computer Name = WINXP-A88C7D920 | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} [Files/Folders - Created Within 90 Days] 1 C:\*.tmp files -> C:\*.tmp -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2008/10/19 18:43:49 | 00,000,000 | —D | C] tmp.reg -> %SystemRoot%\System32\tmp.reg -> [2008/10/19 18:35:54 | 00,002,340 | —- | C] () VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe -> [2008/10/19 18:35:31 | 00,289,144 | —- | C] (S!Ri) SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe -> [2008/10/19 18:35:31 | 00,288,417 | —- | C] (S!Ri) swreg.exe -> %SystemRoot%\System32\swreg.exe -> [2008/10/19 18:35:31 | 00,135,168 | —- | C] (SteelWerX) AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe -> [2008/10/19 18:35:31 | 00,088,576 | —- | C] (S!Ri.URZ) VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> [2008/10/19 18:35:31 | 00,087,552 | —- | C] (S!Ri.URZ) o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe -> [2008/10/19 18:35:31 | 00,082,944 | —- | C] (S!Ri.URZ) IEDFix.exe -> %SystemRoot%\System32\IEDFix.exe -> [2008/10/19 18:35:31 | 00,082,944 | —- | C] (S!Ri.URZ) IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe -> [2008/10/19 18:35:31 | 00,082,944 | —- | C] (S!Ri.URZ) 404Fix.exe -> %SystemRoot%\System32\404Fix.exe -> [2008/10/19 18:35:31 | 00,082,432 | —- | C] (S!Ri.URZ) swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe -> [2008/10/19 18:35:31 | 00,079,360 | —- | C] (SteelWerX) Process.exe -> %SystemRoot%\System32\Process.exe -> [2008/10/19 18:35:31 | 00,053,248 | —- | C] (http://www.beyondlogic.org) dumphive.exe -> %SystemRoot%\System32\dumphive.exe -> [2008/10/19 18:35:31 | 00,051,200 | —- | C] () swsc.exe -> %SystemRoot%\System32\swsc.exe -> [2008/10/19 18:35:31 | 00,040,960 | —- | C] () WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe -> [2008/10/19 18:35:31 | 00,025,600 | —- | C] () SmitfraudFix -> %UserProfile%\Desktop\SmitfraudFix -> [2008/10/19 18:35:26 | 00,000,000 | —D | C] 123.doc -> %UserProfile%\My Documents\123.doc -> [2008/10/19 18:31:51 | 00,019,968 | —- | C] () OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/10/19 18:27:53 | 00,587,711 | —- | C] () SmitfraudFix.exe -> %UserProfile%\Desktop\SmitfraudFix.exe -> [2008/10/19 18:26:28 | 01,662,674 | —- | C] () tmp3.reg -> %SystemDrive%\tmp3.reg -> [2008/10/19 17:36:51 | 00,000,126 | —- | C] () 675873 -> %SystemRoot%\System32\675873 -> [2008/10/19 17:36:29 | 00,000,000 | —D | C] My Documents.url -> %UserProfile%\My Documents\My Documents.url -> [2008/10/19 17:36:24 | 00,000,133 | —- | C] () $AVG8.VAULT$ -> %SystemDrive%\$AVG8.VAULT$ -> [2008/10/19 17:35:28 | 00,000,000 | -H-D | C] srv.sys -> %SystemRoot%\System32\dllcache\srv.sys -> [2008/10/14 19:23:24 | 00,333,824 | —- | C] (Microsoft Corporation) win32k.sys -> %SystemRoot%\System32\dllcache\win32k.sys -> [2008/10/14 19:22:01 | 01,846,400 | —- | C] (Microsoft Corporation) ntkrnlmp.exe -> %SystemRoot%\System32\dllcache\ntkrnlmp.exe -> [2008/10/14 19:21:41 | 02,145,280 | —- | C] (Microsoft Corporation) ntoskrnl.exe -> %SystemRoot%\System32\dllcache\ntoskrnl.exe -> [2008/10/14 19:21:40 | 02,189,184 | —- | C] (Microsoft Corporation) ntkrpamp.exe -> %SystemRoot%\System32\dllcache\ntkrpamp.exe -> [2008/10/14 19:21:39 | 02,023,936 | —- | C] (Microsoft Corporation) ntkrnlpa.exe -> %SystemRoot%\System32\dllcache\ntkrnlpa.exe -> [2008/10/14 19:21:38 | 02,066,048 | —- | C] (Microsoft Corporation) ijji -> %SystemDrive%\ijji -> [2008/10/05 13:42:40 | 00,000,000 | —D | C] ChCfg.exe -> %SystemRoot%\System32\ChCfg.exe -> [2008/09/30 23:23:36 | 00,049,152 | —- | C] () Realtek AC97 -> %ProgramFiles%\Realtek AC97 -> [2008/09/30 23:22:24 | 00,000,000 | —D | C] alsndmgr.wav -> %SystemRoot%\System32\alsndmgr.wav -> [2008/09/30 23:22:17 | 00,141,016 | —- | C] () RtlCPAPI.dll -> %SystemRoot%\System32\RtlCPAPI.dll -> [2008/09/30 23:22:12 | 00,147,456 | —- | C] () RECYCLER -> %SystemDrive%\RECYCLER -> [2008/09/30 23:10:45 | 00,000,000 | -HSD | C] ComboFix -> %SystemDrive%\ComboFix -> [2008/09/30 21:38:44 | 00,000,000 | —D | C] temp -> %SystemRoot%\temp -> [2008/09/30 21:12:39 | 00,000,000 | —D | C] USetup.iss -> %SystemRoot%\USetup.iss -> [2008/09/30 16:41:44 | 00,000,553 | —- | C] () Realtek -> %ProgramFiles%\Realtek -> [2008/09/30 16:40:51 | 00,000,000 | —D | C] avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2008/09/30 15:14:02 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2008/09/30 15:14:01 | 00,076,040 | —- | C] (AVG Technologies CZ, s.r.o.) avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2008/09/30 15:13:58 | 00,097,928 | —- | C] (AVG Technologies CZ, s.r.o.) avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2008/09/30 15:13:57 | 00,026,824 | —- | C] (AVG Technologies CZ, s.r.o.) incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2008/09/30 15:13:50 | 29,045,884 | —- | C] () miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2008/09/30 15:13:50 | 00,307,238 | —- | C] () microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2008/09/30 15:13:50 | 00,043,628 | —- | C] () avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2008/09/30 15:13:49 | 06,061,540 | —- | C] () Avg -> %SystemRoot%\System32\drivers\Avg -> [2008/09/30 15:13:49 | 00,000,000 | —D | C] Malwarebytes -> %AppData%\Malwarebytes -> [2008/09/30 12:50:56 | 00,000,000 | —D | C] mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2008/09/30 12:50:29 | 00,017,200 | —- | C] (Malwarebytes Corporation) mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2008/09/30 12:50:27 | 00,038,528 | —- | C] (Malwarebytes Corporation) Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2008/09/30 12:50:25 | 00,000,000 | —D | C] Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2008/09/30 12:50:23 | 00,000,000 | —D | C] Download Manager -> %CommonProgramFiles%\Download Manager -> [2008/09/30 12:49:33 | 00,000,000 | —D | C] ERDNT -> %SystemRoot%\ERDNT -> [2008/09/30 12:21:21 | 00,000,000 | —D | C] ERUNT -> %ProgramFiles%\ERUNT -> [2008/09/30 12:20:01 | 00,000,000 | —D | C] Trend Micro -> %ProgramFiles%\Trend Micro -> [2008/09/29 20:51:14 | 00,000,000 | —D | C] Avg8 -> %AllUsersProfile%\Application Data\Avg8 -> [2008/09/28 13:41:56 | 00,000,000 | —D | C] udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll -> [2008/09/28 13:10:23 | 00,105,984 | —- | C] () Yahoo! -> %ProgramFiles%\Yahoo! -> [2008/09/27 21:35:35 | 00,000,000 | —D | C] AVG -> %ProgramFiles%\AVG -> [2008/09/27 21:29:28 | 00,000,000 | —D | C] Spybot - Search & Destroy -> %ProgramFiles%\Spybot - Search & Destroy -> [2008/09/27 21:17:47 | 00,000,000 | —D | C] Spybot - Search & Destroy -> %AllUsersProfile%\Application Data\Spybot - Search & Destroy -> [2008/09/27 21:17:47 | 00,000,000 | —D | C] PubPlugin.dll -> %SystemRoot%\System32\PubPlugin.dll -> [2008/09/20 22:52:02 | 00,157,152 | —- | C] (NHN Corporation) Robota.INI -> %SystemRoot%\Robota.INI -> [2008/09/17 23:27:20 | 00,000,028 | —- | C] () MAGIX -> %AppData%\MAGIX -> [2008/09/17 23:27:05 | 00,000,000 | —D | C] msxml4a.dll -> %SystemRoot%\System32\msxml4a.dll -> [2008/09/17 23:25:39 | 00,044,544 | —- | C] (Microsoft Corporation) DLLAV32.dll -> %SystemRoot%\System32\DLLAV32.dll -> [2008/09/17 23:25:36 | 00,487,424 | —- | C] (PoINT Software & Systems GmbH) MXRestore.exe -> %SystemRoot%\System32\MXRestore.exe -> [2008/09/17 23:25:36 | 00,430,080 | —- | C] (MAGIX AG) DLLRES32.dll -> %SystemRoot%\System32\DLLRES32.dll -> [2008/09/17 23:25:36 | 00,188,416 | —- | C] (PoINT Software & Systems GmbH) DLLDEV32.dll -> %SystemRoot%\System32\DLLDEV32.dll -> [2008/09/17 23:25:36 | 00,163,840 | —- | C] (PoINT Software & Systems GmbH) DLLDRV32.dll -> %SystemRoot%\System32\DLLDRV32.dll -> [2008/09/17 23:25:36 | 00,151,552 | —- | C] (PoINT Software & Systems GmbH) DLLCDA32.dll -> %SystemRoot%\System32\DLLCDA32.dll -> [2008/09/17 23:25:36 | 00,114,688 | —- | C] (PoINT Software & Systems GmbH) DLLCPY32.dll -> %SystemRoot%\System32\DLLCPY32.dll -> [2008/09/17 23:25:36 | 00,094,208 | —- | C] (PoINT Software & Systems GmbH) DLLPTL32.dll -> %SystemRoot%\System32\DLLPTL32.dll -> [2008/09/17 23:25:36 | 00,065,536 | —- | C] (PoINT Software & Systems GmbH) DLLCDF32.dll -> %SystemRoot%\System32\DLLCDF32.dll -> [2008/09/17 23:25:36 | 00,061,440 | —- | C] (PoINT Software & Systems GmbH) DLLTPO32.dll -> %SystemRoot%\System32\DLLTPO32.dll -> [2008/09/17 23:25:36 | 00,057,344 | —- | C] (PoINT Software & Systems GmbH) DLLPRJ32.dll -> %SystemRoot%\System32\DLLPRJ32.dll -> [2008/09/17 23:25:36 | 00,053,248 | —- | C] (PoINT Software & Systems GmbH) DLLIO32.dll -> %SystemRoot%\System32\DLLIO32.dll -> [2008/09/17 23:25:36 | 00,053,248 | —- | C] (PoINT Software & Systems GmbH) mgxasio2.dll -> %SystemRoot%\System32\mgxasio2.dll -> [2008/09/17 23:25:36 | 00,053,248 | —- | C] () DLLPRF32.dll -> %SystemRoot%\System32\DLLPRF32.dll -> [2008/09/17 23:25:36 | 00,049,152 | —- | C] (PoINT Software & Systems GmbH) DLLIMG32.dll -> %SystemRoot%\System32\DLLIMG32.dll -> [2008/09/17 23:25:36 | 00,045,056 | —- | C] (PoINT Software & Systems GmbH) DLLRD32.dll -> %SystemRoot%\System32\DLLRD32.dll -> [2008/09/17 23:25:36 | 00,040,960 | —- | C] (PoINT Software & Systems GmbH) DLLPNT32.dll -> %SystemRoot%\System32\DLLPNT32.dll -> [2008/09/17 23:25:36 | 00,036,864 | —- | C] (PoINT Software & Systems GmbH) STRING32.dll -> %SystemRoot%\System32\STRING32.dll -> [2008/09/17 23:25:36 | 00,032,768 | —- | C] (PoINT Software & Systems GmbH) DLLMSC32.dll -> %SystemRoot%\System32\DLLMSC32.dll -> [2008/09/17 23:25:36 | 00,032,768 | —- | C] (PoINT Software & Systems GmbH) DLLISO32.dll -> %SystemRoot%\System32\DLLISO32.dll -> [2008/09/17 23:25:36 | 00,032,768 | —- | C] (PoINT Software & Systems GmbH) DLLDIR32.dll -> %SystemRoot%\System32\DLLDIR32.dll -> [2008/09/17 23:25:36 | 00,032,768 | —- | C] (PoINT Software & Systems GmbH) TTIC32.dll -> %SystemRoot%\System32\TTIC32.dll -> [2008/09/17 23:25:36 | 00,024,576 | —- | C] (PoINT Software & Systems GmbH) TTI32.dll -> %SystemRoot%\System32\TTI32.dll -> [2008/09/17 23:25:36 | 00,024,576 | —- | C] (PoINT Software & Systems GmbH) DLLIX.dll -> %SystemRoot%\System32\DLLIX.dll -> [2008/09/17 23:25:36 | 00,024,576 | —- | C] (PoINT Software & Systems GmbH) DLLAV32.lib -> %SystemRoot%\System32\DLLAV32.lib -> [2008/09/17 23:25:36 | 00,014,182 | —- | C] () MAGIX -> %AllUsersProfile%\Application Data\MAGIX -> [2008/09/17 23:24:57 | 00,000,000 | —D | C] DLLDEV32i.dll -> %SystemRoot%\System32\DLLDEV32i.dll -> [2008/09/17 23:24:34 | 00,120,200 | —- | C] () MAGIX -> %ProgramFiles%\MAGIX -> [2008/09/17 23:24:34 | 00,000,000 | —D | C] mgxoschk.dll -> %SystemRoot%\System32\mgxoschk.dll -> [2008/09/17 23:24:02 | 00,700,416 | —- | C] (MAGIX AG) mgxoschk.ini -> %SystemRoot%\mgxoschk.ini -> [2008/09/17 23:24:02 | 00,005,937 | —- | C] () MAGIX -> %SystemRoot%\System32\MAGIX -> [2008/09/17 23:24:02 | 00,000,000 | —D | C] Aotoload.ocx -> %SystemRoot%\System32\Aotoload.ocx -> [2008/09/14 01:35:17 | 00,000,000 | —- | C] () U3 -> %AppData%\U3 -> [2008/09/14 00:42:59 | 00,000,000 | —D | C] MSECache -> %ProgramFiles%\MSECache -> [2008/09/03 21:31:33 | 00,000,000 | —D | C] Prefetch -> %SystemRoot%\Prefetch -> [2008/08/29 20:09:49 | 00,000,000 | —D | C] en-us -> %SystemRoot%\System32\en-us -> [2008/08/29 19:59:35 | 00,000,000 | —D | C] scripting -> %SystemRoot%\System32\scripting -> [2008/08/29 19:59:33 | 00,000,000 | —D | C] l2schemas -> %SystemRoot%\l2schemas -> [2008/08/29 19:59:31 | 00,000,000 | —D | C] en -> %SystemRoot%\System32\en -> [2008/08/29 19:59:30 | 00,000,000 | —D | C] bits -> %SystemRoot%\System32\bits -> [2008/08/29 19:59:29 | 00,000,000 | —D | C] ServicePackFiles -> %SystemRoot%\ServicePackFiles -> [2008/08/29 19:55:53 | 00,000,000 | —D | C] network diagnostic -> %SystemRoot%\network diagnostic -> [2008/08/29 19:53:09 | 00,000,000 | —D | C] $NtServicePackUninstall$ -> %SystemRoot%\$NtServicePackUninstall$ -> [2008/08/29 19:48:02 | 00,000,000 | -H-D | C] EHome -> %SystemRoot%\EHome -> [2008/08/29 19:47:59 | 00,000,000 | —D | C] xmllite.dll -> %SystemRoot%\System32\xmllite.dll -> [2008/08/29 13:54:52 | 00,121,856 | —- | C] (Microsoft Corporation) wmphoto.dll -> %SystemRoot%\System32\wmphoto.dll -> [2008/08/29 13:54:49 | 00,276,992 | —- | C] (Microsoft Corporation) wlanapi.dll -> %SystemRoot%\System32\wlanapi.dll -> [2008/08/29 13:54:47 | 00,069,120 | —- | C] (Microsoft Corporation) windowscodecsext.dll -> %SystemRoot%\System32\windowscodecsext.dll -> [2008/08/29 13:54:45 | 00,346,112 | —- | C] (Microsoft Corporation) windowscodecs.dll -> %SystemRoot%\System32\windowscodecs.dll -> [2008/08/29 13:54:44 | 00,712,704 | —- | C] (Microsoft Corporation) wacompen.sys -> %SystemRoot%\System32\drivers\wacompen.sys -> [2008/08/29 13:54:42 | 00,014,208 | —- | C] (Microsoft Corporation) viaagp.sys -> %SystemRoot%\System32\drivers\viaagp.sys -> [2008/08/29 13:54:41 | 00,042,240 | —- | C] (Microsoft Corporation) vidcap.ax -> %SystemRoot%\System32\vidcap.ax -> [2008/08/29 13:54:41 | 00,028,672 | —- | C] (Microsoft Corporation) usbvideo.sys -> %SystemRoot%\System32\drivers\usbvideo.sys -> [2008/08/29 13:54:39 | 00,121,984 | —- | C] (Microsoft Corporation) usb8023x.sys -> %SystemRoot%\System32\drivers\usb8023x.sys -> [2008/08/29 13:54:38 | 00,012,800 | —- | C] (Microsoft Corporation) uagp35.sys -> %SystemRoot%\System32\drivers\uagp35.sys -> [2008/08/29 13:54:36 | 00,044,672 | —- | C] (Microsoft Corporation) tsgqec.dll -> %SystemRoot%\System32\tsgqec.dll -> [2008/08/29 13:54:35 | 00,053,248 | —- | C] (Microsoft Corporation) tspkg.dll -> %SystemRoot%\System32\tspkg.dll -> [2008/08/29 13:54:35 | 00,050,688 | —- | C] (Microsoft Corporation) spupdwxp.exe -> %SystemRoot%\System32\spupdwxp.exe -> [2008/08/29 13:54:28 | 00,020,992 | —- | C] (Microsoft Corporation) spdwnwxp.exe -> %SystemRoot%\System32\spdwnwxp.exe -> [2008/08/29 13:54:27 | 00,007,680 | —- | C] (Microsoft Corporation) smbali.sys -> %SystemRoot%\System32\drivers\smbali.sys -> [2008/08/29 13:54:25 | 00,005,888 | —- | C] (Microsoft Corporation) setupn.exe -> %SystemRoot%\System32\setupn.exe -> [2008/08/29 13:54:21 | 00,032,768 | —- | C] (Microsoft Corporation) sffp_mmc.sys -> %SystemRoot%\System32\drivers\sffp_mmc.sys -> [2008/08/29 13:54:21 | 00,010,240 | —- | C] (Microsoft Corporation) rhttpaa.dll -> %SystemRoot%\System32\rhttpaa.dll -> [2008/08/29 13:54:17 | 00,290,304 | —- | C] (Microsoft Corporation) rfcomm.sys -> %SystemRoot%\System32\drivers\rfcomm.sys -> [2008/08/29 13:54:17 | 00,059,136 | —- | C] (Microsoft Corporation) rndismpx.sys -> %SystemRoot%\System32\drivers\rndismpx.sys -> [2008/08/29 13:54:17 | 00,030,592 | —- | C] (Microsoft Corporation) rasqec.dll -> %SystemRoot%\System32\rasqec.dll -> [2008/08/29 13:54:13 | 00,061,952 | —- | C] (Microsoft Corporation) qutil.dll -> %SystemRoot%\System32\qutil.dll -> [2008/08/29 13:54:11 | 00,076,800 | —- | C] (Microsoft Corporation) qagentrt.dll -> %SystemRoot%\System32\qagentrt.dll -> [2008/08/29 13:54:09 | 00,291,328 | —- | C] (Microsoft Corporation) qagent.dll -> %SystemRoot%\System32\qagent.dll -> [2008/08/29 13:54:09 | 00,150,528 | —- | C] (Microsoft Corporation) qcliprov.dll -> %SystemRoot%\System32\qcliprov.dll -> [2008/08/29 13:54:09 | 00,062,464 | —- | C] (Microsoft Corporation) photometadatahandler.dll -> %SystemRoot%\System32\photometadatahandler.dll -> [2008/08/29 13:54:07 | 00,412,160 | —- | C] (Microsoft Corporation) onex.dll -> %SystemRoot%\System32\onex.dll -> [2008/08/29 13:54:04 | 00,144,384 | —- | C] (Microsoft Corporation) netwlan5.img -> %SystemRoot%\System32\drivers\netwlan5.img -> [2008/08/29 13:53:52 | 00,067,866 | —- | C] () napmontr.dll -> %SystemRoot%\System32\napmontr.dll -> [2008/08/29 13:53:50 | 00,193,024 | —- | C] (Microsoft Corporation) napstat.exe -> %SystemRoot%\System32\napstat.exe -> [2008/08/29 13:53:50 | 00,176,640 | —- | C] (Microsoft Corporation) napipsec.dll -> %SystemRoot%\System32\napipsec.dll -> [2008/08/29 13:53:50 | 00,030,208 | —- | C] (Microsoft Corporation) mutohpen.sys -> %SystemRoot%\System32\drivers\mutohpen.sys -> [2008/08/29 13:53:50 | 00,012,672 | —- | C] (Microsoft Corporation) msxml6.dll -> %SystemRoot%\System32\msxml6.dll -> [2008/08/29 13:53:48 | 01,306,624 | —- | C] (Microsoft Corporation) msxml6.dll -> %SystemRoot%\System32\dllcache\msxml6.dll -> [2008/08/29 13:53:48 | 01,306,624 | —- | C] (Microsoft Corporation) msxml6r.dll -> %SystemRoot%\System32\msxml6r.dll -> [2008/08/29 13:53:48 | 00,079,872 | —- | C] (Microsoft Corporation) msxml6r.dll -> %SystemRoot%\System32\dllcache\msxml6r.dll -> [2008/08/29 13:53:48 | 00,079,872 | —- | C] (Microsoft Corporation) mssha.dll -> %SystemRoot%\System32\mssha.dll -> [2008/08/29 13:53:46 | 00,155,136 | —- | C] (Microsoft Corporation) msshavmsg.dll -> %SystemRoot%\System32\msshavmsg.dll -> [2008/08/29 13:53:46 | 00,076,800 | —- | C] (Microsoft Corporation) mmcex.dll -> %SystemRoot%\System32\mmcex.dll -> [2008/08/29 13:53:33 | 00,397,312 | —- | C] (Microsoft Corporation) microsoft.managementconsole.dll -> %SystemRoot%\System32\microsoft.managementconsole.dll -> [2008/08/29 13:53:33 | 00,184,320 | —- | C] (Microsoft Corporation) mmcfxcommon.dll -> %SystemRoot%\System32\mmcfxcommon.dll -> [2008/08/29 13:53:33 | 00,106,496 | —- | C] (Microsoft Corporation) mmcperf.exe -> %SystemRoot%\System32\mmcperf.exe -> [2008/08/29 13:53:33 | 00,033,792 | —- | C] (Microsoft Corporation) l2gpstore.dll -> %SystemRoot%\System32\l2gpstore.dll -> [2008/08/29 13:53:21 | 00,037,376 | —- | C] (Microsoft Corporation) kmsvc.dll -> %SystemRoot%\System32\kmsvc.dll -> [2008/08/29 13:53:20 | 00,061,440 | —- | C] (Microsoft Corporation) kbdpash.dll -> %SystemRoot%\System32\kbdpash.dll -> [2008/08/29 13:53:19 | 00,006,144 | —- | C] (Microsoft Corporation) kbdnepr.dll -> %SystemRoot%\System32\kbdnepr.dll -> [2008/08/29 13:53:19 | 00,006,144 | —- | C] (Microsoft Corporation) kbdiultn.dll -> %SystemRoot%\System32\kbdiultn.dll -> [2008/08/29 13:53:19 | 00,006,144 | —- | C] (Microsoft Corporation) kbdbhc.dll -> %SystemRoot%\System32\kbdbhc.dll -> [2008/08/29 13:53:18 | 00,006,144 | —- | C] (Microsoft Corporation) pid.inf -> %SystemRoot%\System32\pid.inf -> [2008/08/29 13:53:08 | 00,001,261 | —- | C] () hidbth.sys -> %SystemRoot%\System32\drivers\hidbth.sys -> [2008/08/29 13:53:04 | 00,025,600 | —- | C] (Microsoft Corporation) hidir.sys -> %SystemRoot%\System32\drivers\hidir.sys -> [2008/08/29 13:53:04 | 00,019,200 | —- | C] (Microsoft Corporation) gagp30kx.sys -> %SystemRoot%\System32\drivers\gagp30kx.sys -> [2008/08/29 13:53:02 | 00,046,464 | —- | C] (Microsoft Corporation) faxpatch.exe -> %SystemRoot%\System32\faxpatch.exe -> [2008/08/29 13:52:58 | 00,020,992 | —- | C] (Microsoft Corporation) eapp3hst.dll -> %SystemRoot%\System32\eapp3hst.dll -> [2008/08/29 13:52:55 | 00,184,832 | —- | C] (Microsoft Corporation) eapphost.dll -> %SystemRoot%\System32\eapphost.dll -> [2008/08/29 13:52:55 | 00,180,224 | —- | C] (Microsoft Corporation) eappcfg.dll -> %SystemRoot%\System32\eappcfg.dll -> [2008/08/29 13:52:55 | 00,126,976 | —- | C] (Microsoft Corporation) eappgnui.dll -> %SystemRoot%\System32\eappgnui.dll -> [2008/08/29 13:52:55 | 00,094,208 | —- | C] (Microsoft Corporation) eapqec.dll -> %SystemRoot%\System32\eapqec.dll -> [2008/08/29 13:52:55 | 00,059,392 | —- | C] (Microsoft Corporation) eappprxy.dll -> %SystemRoot%\System32\eappprxy.dll -> [2008/08/29 13:52:55 | 00,040,960 | —- | C] (Microsoft Corporation) eapsvc.dll -> %SystemRoot%\System32\eapsvc.dll -> [2008/08/29 13:52:55 | 00,033,792 | —- | C] (Microsoft Corporation) eapolqec.dll -> %SystemRoot%\System32\eapolqec.dll -> [2008/08/29 13:52:55 | 00,030,720 | —- | C] (Microsoft Corporation) dot3ui.dll -> %SystemRoot%\System32\dot3ui.dll -> [2008/08/29 13:52:52 | 00,650,752 | —- | C] (Microsoft Corporation) dot3svc.dll -> %SystemRoot%\System32\dot3svc.dll -> [2008/08/29 13:52:52 | 00,132,096 | —- | C] (Microsoft Corporation) dot3cfg.dll -> %SystemRoot%\System32\dot3cfg.dll -> [2008/08/29 13:52:52 | 00,057,856 | —- | C] (Microsoft Corporation) dot3msm.dll -> %SystemRoot%\System32\dot3msm.dll -> [2008/08/29 13:52:52 | 00,056,320 | —- | C] (Microsoft Corporation) dot3gpclnt.dll -> %SystemRoot%\System32\dot3gpclnt.dll -> [2008/08/29 13:52:52 | 00,039,936 | —- | C] (Microsoft Corporation) dot3api.dll -> %SystemRoot%\System32\dot3api.dll -> [2008/08/29 13:52:52 | 00,026,112 | —- | C] (Microsoft Corporation) dot3dlg.dll -> %SystemRoot%\System32\dot3dlg.dll -> [2008/08/29 13:52:52 | 00,009,216 | —- | C] (Microsoft Corporation) dimsroam.dll -> %SystemRoot%\System32\dimsroam.dll -> [2008/08/29 13:52:49 | 00,039,936 | —- | C] (Microsoft Corporation) dimsntfy.dll -> %SystemRoot%\System32\dimsntfy.dll -> [2008/08/29 13:52:49 | 00,019,456 | —- | C] (Microsoft Corporation) dhcpqec.dll -> %SystemRoot%\System32\dhcpqec.dll -> [2008/08/29 13:52:48 | 00,048,640 | —- | C] (Microsoft Corporation) cxthsfs2.cty -> %SystemRoot%\System32\drivers\cxthsfs2.cty -> [2008/08/29 13:52:46 | 00,129,045 | —- | C] () credssp.dll -> %SystemRoot%\System32\credssp.dll -> [2008/08/29 13:52:45 | 00,012,800 | —- | C] (Microsoft Corporation) bthpan.sys -> %SystemRoot%\System32\drivers\bthpan.sys -> [2008/08/29 13:52:40 | 00,101,120 | —- | C] (Microsoft Corporation) bthprint.sys -> %SystemRoot%\System32\drivers\bthprint.sys -> [2008/08/29 13:52:40 | 00,036,480 | —- | C] (Microsoft Corporation) bthusb.sys -> %SystemRoot%\System32\drivers\bthusb.sys -> [2008/08/29 13:52:40 | 00,018,944 | —- | C] (Microsoft Corporation) bthmodem.sys -> %SystemRoot%\System32\drivers\bthmodem.sys -> [2008/08/29 13:52:39 | 00,037,888 | —- | C] (Microsoft Corporation) bthenum.sys -> %SystemRoot%\System32\drivers\bthenum.sys -> [2008/08/29 13:52:39 | 00,017,024 | —- | C] (Microsoft Corporation) bitsprx4.dll -> %SystemRoot%\System32\bitsprx4.dll -> [2008/08/29 13:52:39 | 00,007,168 | —- | C] (Microsoft Corporation) azroles.dll -> %SystemRoot%\System32\azroles.dll -> [2008/08/29 13:52:38 | 00,233,472 | —- | C] (Microsoft Corporation) ativmc20.cod -> %SystemRoot%\System32\drivers\ativmc20.cod -> [2008/08/29 13:52:36 | 00,064,352 | —- | C] () alim1541.sys -> %SystemRoot%\System32\drivers\alim1541.sys -> [2008/08/29 13:52:32 | 00,042,752 | —- | C] (Microsoft Corporation) agpcpq.sys -> %SystemRoot%\System32\drivers\agpcpq.sys -> [2008/08/29 13:52:29 | 00,044,928 | —- | C] (Microsoft Corporation) agp440.sys -> %SystemRoot%\System32\drivers\agp440.sys -> [2008/08/29 13:52:29 | 00,042,368 | —- | C] (Microsoft Corporation) aaclient.dll -> %SystemRoot%\System32\aaclient.dll -> [2008/08/29 13:52:27 | 00,136,192 | —- | C] (Microsoft Corporation) inetcomm.dll -> %SystemRoot%\System32\dllcache\inetcomm.dll -> [2008/08/29 13:21:36 | 00,691,712 | —- | C] (Microsoft Corporation) AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [2008/08/10 23:27:08 | 00,000,284 | —- | C] () iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2008/08/10 23:21:23 | 00,002,137 | —- | C] () iPod -> %ProgramFiles%\iPod -> [2008/08/10 23:19:17 | 00,000,000 | —D | C] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [2008/08/09 09:59:04 | 00,054,156 | -H– | C] () QTFont.for -> %SystemRoot%\QTFont.for -> [2008/08/09 09:59:04 | 00,001,409 | —- | C] () [Files/Folders - Modified Within 90 Days] 1 C:\*.tmp files -> C:\*.tmp -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 1 C:\Documents and Settings\winxp\My Documents\*.tmp files -> C:\Documents and Settings\winxp\My Documents\*.tmp -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [2006/01/26 16:50:18 | 00,000,000 | —D | M] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2008/10/14 19:23:55 | 00,004,232 | —- | M] () qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2008/10/14 19:23:55 | 00,004,646 | —- | M] () C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA -> [2006/02/28 21:14:06 | 00,000,000 | —D | M] opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [2006/02/28 21:14:22 | 00,011,108 | —- | M] () C:\WINDOWS\Temp\ -> C:\WINDOWS\temp -> [2008/10/19 18:32:08 | 00,000,000 | —D | M] alcrmv.exe -> C:\WINDOWS\temp\alcrmv.exe -> [2006/07/31 11:27:30 | 00,217,088 | —- | M] (Realtek Semiconductor Corp.) alcupd.exe -> C:\WINDOWS\temp\alcupd.exe -> [2006/07/31 11:19:00 | 00,315,392 | —- | M] (Realtek Semiconductor Corp.) ChCfg.exe -> C:\WINDOWS\temp\ChCfg.exe -> [2006/08/01 15:02:00 | 00,049,152 | —- | M] () RTLCPL.exe -> C:\WINDOWS\temp\RTLCPL.exe -> [2006/12/08 15:20:14 | 10,528,768 | —- | M] (Realtek Semiconductor Corp.) soundman.exe -> C:\WINDOWS\temp\soundman.exe -> [2007/04/16 15:28:22 | 00,577,536 | —- | M] (Realtek Semiconductor Corp.) C:\WINDOWS\Temp\ -> C:\WINDOWS\temp -> [2008/10/19 18:32:08 | 00,000,000 | —D | M] newdev.dll -> C:\WINDOWS\temp\newdev.dll -> [2008/04/13 20:12:02 | 00,247,808 | —- | M] (Microsoft Corporation) RtlCPAPI.dll -> C:\WINDOWS\temp\RtlCPAPI.dll -> [2006/10/18 02:53:26 | 00,147,456 | —- | M] () tmp.reg -> %SystemRoot%\System32\tmp.reg -> [2008/10/19 18:35:54 | 00,002,340 | —- | M] () hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [2008/10/19 18:35:50 | 00,000,027 | —- | M] () bootstat.dat -> %SystemRoot%\bootstat.dat -> [2008/10/19 18:34:08 | 00,002,048 | –S- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/10/19 18:32:05 | 00,000,006 | -H– | M] () 123.doc -> %UserProfile%\My Documents\123.doc -> [2008/10/19 18:31:52 | 00,019,968 | —- | M] () OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/10/19 18:27:56 | 00,587,711 | —- | M] () SmitfraudFix.exe -> %UserProfile%\Desktop\SmitfraudFix.exe -> [2008/10/19 18:26:41 | 01,662,674 | —- | M] () Microsoft Office Word 2003.lnk -> %UserProfile%\Desktop\Microsoft Office Word 2003.lnk -> [2008/10/19 18:24:31 | 00,002,497 | —- | M] () wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2008/10/19 17:54:03 | 00,012,598 | —- | M] () win.ini -> %SystemRoot%\win.ini -> [2008/10/19 17:52:13 | 00,000,624 | —- | M] () system.ini -> %SystemRoot%\system.ini -> [2008/10/19 17:52:13 | 00,000,227 | —- | M] () boot.ini -> %SystemDrive%\boot.ini -> [2008/10/19 17:52:13 | 00,000,210 | -HS- | M] () incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2008/10/19 17:44:53 | 29,045,884 | —- | M] () tmp3.reg -> %SystemDrive%\tmp3.reg -> [2008/10/19 17:36:53 | 00,000,126 | —- | M] () My Documents.url -> %UserProfile%\My Documents\My Documents.url -> [2008/10/19 17:36:24 | 00,000,133 | —- | M] () iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2008/10/18 20:39:25 | 00,002,137 | —- | M] () winamp.ini -> %SystemRoot%\winamp.ini -> [2008/10/16 23:20:14 | 00,001,125 | —- | M] () microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2008/10/15 20:07:24 | 00,043,628 | —- | M] () FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2008/10/15 12:32:18 | 00,246,312 | —- | M] () imsins.BAK -> %SystemRoot%\imsins.BAK -> [2008/10/14 23:18:26 | 00,001,393 | —- | M] () PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2008/10/14 23:05:39 | 00,478,288 | —- | M] () perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [2008/10/14 23:05:39 | 00,409,232 | —- | M] () perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [2008/10/14 23:05:39 | 00,064,372 | —- | M] () o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe -> [2008/10/10 08:58:08 | 00,082,944 | —- | M] (S!Ri.URZ) IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe -> [2008/10/10 08:58:08 | 00,082,944 | —- | M] (S!Ri.URZ) miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2008/10/09 21:10:22 | 00,307,238 | —- | M] () MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2008/10/07 15:19:40 | 16,721,856 | —- | M] (Microsoft Corporation) IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/10/05 22:26:14 | 01,577,134 | -H– | M] () VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> [2008/10/01 15:51:40 | 00,087,552 | —- | M] (S!Ri.URZ) PDBOXGame.html -> %SystemRoot%\System32\PDBOXGame.html -> [2008/09/30 15:23:23 | 00,000,000 | —- | M] () avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2008/09/30 15:14:02 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2008/09/30 15:14:01 | 00,076,040 | —- | M] (AVG Technologies CZ, s.r.o.) avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2008/09/30 15:13:58 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.) avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2008/09/30 15:13:57 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.) avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2008/09/30 15:13:50 | 06,061,540 | —- | M] () udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll -> [2008/09/28 13:10:24 | 00,105,984 | —- | M] () WININIT.INI -> %SystemRoot%\WININIT.INI -> [2008/09/28 13:08:41 | 00,000,810 | —- | M] () GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2008/09/18 15:50:51 | 00,067,616 | —- | M] () Robota.INI -> %SystemRoot%\Robota.INI -> [2008/09/17 23:27:20 | 00,000,028 | —- | M] () mgxoschk.ini -> %SystemRoot%\mgxoschk.ini -> [2008/09/17 23:25:59 | 00,005,937 | —- | M] () win32k.sys -> %SystemRoot%\System32\win32k.sys -> [2008/09/15 08:12:56 | 01,846,400 | —- | M] (Microsoft Corporation) win32k.sys -> %SystemRoot%\System32\dllcache\win32k.sys -> [2008/09/15 08:12:56 | 01,846,400 | —- | M] (Microsoft Corporation) Aotoload.ocx -> %SystemRoot%\System32\Aotoload.ocx -> [2008/09/14 01:35:17 | 00,000,000 | —- | M] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2008/09/10 00:04:02 | 00,038,528 | —- | M] (Malwarebytes Corporation) mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2008/09/10 00:03:56 | 00,017,200 | —- | M] (Malwarebytes Corporation) AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe -> [2008/09/08 23:38:55 | 00,088,576 | —- | M] (S!Ri.URZ) srv.sys -> %SystemRoot%\System32\drivers\srv.sys -> [2008/09/08 06:41:42 | 00,333,824 | —- | M] (Microsoft Corporation) srv.sys -> %SystemRoot%\System32\dllcache\srv.sys -> [2008/09/08 06:41:42 | 00,333,824 | —- | M] (Microsoft Corporation) DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2008/08/31 20:56:43 | 00,036,352 | —- | M] () desktop.ini -> %UserProfile%\My Documents\desktop.ini -> [2008/08/29 20:12:27 | 00,000,076 | -HS- | M] () ntldr -> %SystemDrive%\ntldr -> [2008/08/29 19:52:30 | 00,250,048 | RHS- | M] () AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [2008/08/29 14:28:10 | 00,000,284 | —- | M] () logfile -> %SystemDrive%\logfile -> [2008/08/26 23:44:40 | 00,035,052 | —- | M] () fscagent.ini -> %SystemRoot%\System32\fscagent.ini -> [2008/08/23 21:18:44 | 00,000,080 | —- | M] () mshtml.dll -> %SystemRoot%\System32\mshtml.dll -> [2008/08/20 01:30:53 | 03,067,904 | —- | M] (Microsoft Corporation) mshtml.dll -> %SystemRoot%\System32\dllcache\mshtml.dll -> [2008/08/20 01:30:53 | 03,067,904 | —- | M] (Microsoft Corporation) urlmon.dll -> %SystemRoot%\System32\urlmon.dll -> [2008/08/20 01:30:52 | 00,619,520 | —- | M] (Microsoft Corporation) urlmon.dll -> %SystemRoot%\System32\dllcache\urlmon.dll -> [2008/08/20 01:30:52 | 00,619,520 | —- | M] (Microsoft Corporation) shdocvw.dll -> %SystemRoot%\System32\shdocvw.dll -> [2008/08/20 01:30:51 | 01,499,136 | —- | M] (Microsoft Corporation) shdocvw.dll -> %SystemRoot%\System32\dllcache\shdocvw.dll -> [2008/08/20 01:30:51 | 01,499,136 | —- | M] (Microsoft Corporation) wininet.dll -> %SystemRoot%\System32\wininet.dll -> [2008/08/20 01:30:51 | 00,666,112 | —- | M] (Microsoft Corporation) wininet.dll -> %SystemRoot%\System32\dllcache\wininet.dll -> [2008/08/20 01:30:51 | 00,666,112 | —- | M] (Microsoft Corporation) 404Fix.exe -> %SystemRoot%\System32\404Fix.exe -> [2008/08/18 12:19:03 | 00,082,432 | —- | M] (S!Ri.URZ) ntoskrnl.exe -> %SystemRoot%\System32\dllcache\ntoskrnl.exe -> [2008/08/14 06:11:02 | 02,189,184 | —- | M] (Microsoft Corporation) ntoskrnl.exe -> %SystemRoot%\System32\ntoskrnl.exe -> [2008/08/14 06:09:26 | 02,145,280 | —- | M] (Microsoft Corporation) ntkrnlmp.exe -> %SystemRoot%\System32\dllcache\ntkrnlmp.exe -> [2008/08/14 06:09:26 | 02,145,280 | —- | M] (Microsoft Corporation) afd.sys -> %SystemRoot%\System32\drivers\afd.sys -> [2008/08/14 06:04:36 | 00,138,496 | —- | M] (Microsoft Corporation) afd.sys -> %SystemRoot%\System32\dllcache\afd.sys -> [2008/08/14 06:04:36 | 00,138,496 | —- | M] (Microsoft Corporation) ntkrnlpa.exe -> %SystemRoot%\System32\dllcache\ntkrnlpa.exe -> [2008/08/14 05:33:16 | 02,066,048 | —- | M] (Microsoft Corporation) ntkrpamp.exe -> %SystemRoot%\System32\dllcache\ntkrpamp.exe -> [2008/08/14 05:33:16 | 02,023,936 | —- | M] (Microsoft Corporation) ntkrnlpa.exe -> %SystemRoot%\System32\ntkrnlpa.exe -> [2008/08/14 05:33:16 | 02,023,936 | —- | M] (Microsoft Corporation) QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [2008/08/10 16:08:17 | 00,054,156 | -H– | M] () QTFont.for -> %SystemRoot%\QTFont.for -> [2008/08/09 09:59:04 | 00,001,409 | —- | M] () cmiset.inf -> %SystemRoot%\cmiset.inf -> [2008/08/04 22:25:36 | 00,000,093 | —- | M] () [File - Lop Check] Application Data -> C:\Documents and Settings\All Users\Application Data -> [2008/09/30 15:12:15 | 00,000,000 | RH-D | M] Adobe -> C:\Documents and Settings\All Users\Application Data\Adobe -> [2006/08/21 20:31:11 | 00,000,000 | —D | M] AOL -> C:\Documents and Settings\All Users\Application Data\AOL -> [2006/02/16 18:22:27 | 00,000,000 | —D | M] AOL Downloads -> C:\Documents and Settings\All Users\Application Data\AOL Downloads -> [2008/02/19 14:12:41 | 00,000,000 | —D | M] AOL OCP -> C:\Documents and Settings\All Users\Application Data\AOL OCP -> [2007/06/07 20:25:06 | 00,000,000 | —D | M] Apple -> C:\Documents and Settings\All Users\Application Data\Apple -> [2008/03/04 22:33:25 | 00,000,000 | —D | M] Apple Computer -> C:\Documents and Settings\All Users\Application Data\Apple Computer -> [2008/03/04 22:38:04 | 00,000,000 | —D | M] ATI -> C:\Documents and Settings\All Users\Application Data\ATI -> [2007/09/14 00:10:24 | 00,000,000 | —D | M] Avg8 -> C:\Documents and Settings\All Users\Application Data\Avg8 -> [2008/09/30 15:13:39 | 00,000,000 | —D | M] Kodak -> C:\Documents and Settings\All Users\Application Data\Kodak -> [2008/08/27 00:08:55 | 00,000,000 | —D | M] MAGIX -> C:\Documents and Settings\All Users\Application Data\MAGIX -> [2008/09/17 23:26:20 | 00,000,000 | —D | M] Malwarebytes -> C:\Documents and Settings\All Users\Application Data\Malwarebytes -> [2008/09/30 12:50:25 | 00,000,000 | —D | M] Microsoft -> C:\Documents and Settings\All Users\Application Data\Microsoft -> [2007/10/28 19:39:17 | 00,000,000 | –SD | M] Motive -> C:\Documents and Settings\All Users\Application Data\Motive -> [2006/06/29 14:09:35 | 00,000,000 | —D | M] MSN Messenger 6.1.0155 -> C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.1.0155 -> [2006/02/14 22:45:39 | 00,000,000 | —D | M] MSN6 -> C:\Documents and Settings\All Users\Application Data\MSN6 -> [2006/02/14 22:45:46 | 00,000,000 | —D | M] Musicnotes -> C:\Documents and Settings\All Users\Application Data\Musicnotes -> [2008/06/28 10:49:10 | 00,000,000 | —D | M] Office Genuine Advantage -> C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage -> [2008/01/24 21:21:03 | 00,000,000 | —D | M] Real -> C:\Documents and Settings\All Users\Application Data\Real -> [2006/05/21 21:43:41 | 00,000,000 | —D | M] Skype -> C:\Documents and Settings\All Users\Application Data\Skype -> [2007/08/25 20:11:31 | 00,000,000 | —D | M] Spybot - Search & Destroy -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy -> [2008/09/28 13:37:20 | 00,000,000 | —D | M] Viewpoint -> C:\Documents and Settings\All Users\Application Data\Viewpoint -> [2008/09/30 16:07:09 | 00,000,000 | —D | M] Windows Genuine Advantage -> C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage -> [2006/01/26 16:52:43 | 00,000,000 | —D | M] Application Data -> C:\Documents and Settings\winxp\Application Data -> [2008/10/19 18:35:55 | 00,000,000 | RH-D | M] acccore -> C:\Documents and Settings\winxp\Application Data\acccore -> [2006/02/16 18:23:13 | 00,000,000 | —D | M] Adobe -> C:\Documents and Settings\winxp\Application Data\Adobe -> [2008/02/13 16:04:07 | 00,000,000 | —D | M] AdobeUM -> C:\Documents and Settings\winxp\Application Data\AdobeUM -> [2007/05/01 20:56:39 | 00,000,000 | —D | M] Aim -> C:\Documents and Settings\winxp\Application Data\Aim -> [2006/08/18 20:01:07 | 00,000,000 | —D | M] Apple Computer -> C:\Documents and Settings\winxp\Application Data\Apple Computer -> [2008/03/04 22:43:57 | 00,000,000 | —D | M] ATI -> C:\Documents and Settings\winxp\Application Data\ATI -> [2007/09/14 00:10:23 | 00,000,000 | —D | M] BSplayer -> C:\Documents and Settings\winxp\Application Data\BSplayer -> [2006/06/29 15:43:21 | 00,000,000 | —D | M] CyberLink -> C:\Documents and Settings\winxp\Application Data\CyberLink -> [2006/08/18 16:40:58 | 00,000,000 | —D | M] gtk-2.0 -> C:\Documents and Settings\winxp\Application Data\gtk-2.0 -> [2008/05/23 00:08:58 | 00,000,000 | —D | M] Help -> C:\Documents and Settings\winxp\Application Data\Help -> [2008/05/02 19:04:47 | 00,000,000 | —D | M] Identities -> C:\Documents and Settings\winxp\Application Data\Identities -> [2006/01/26 16:48:55 | 00,000,000 | —D | M] ijjigame -> C:\Documents and Settings\winxp\Application Data\ijjigame -> [2008/05/01 21:33:24 | 00,000,000 | -H-D | M] Leadertech -> C:\Documents and Settings\winxp\Application Data\Leadertech -> [2006/04/14 18:09:53 | 00,000,000 | —D | M] LimeWire -> C:\Documents and Settings\winxp\Application Data\LimeWire -> [2008/04/13 17:49:15 | 00,000,000 | —D | M] Macromedia -> C:\Documents and Settings\winxp\Application Data\Macromedia -> [2006/04/05 21:18:09 | 00,000,000 | —D | M] MAGIX -> C:\Documents and Settings\winxp\Application Data\MAGIX -> [2008/09/17 23:27:05 | 00,000,000 | —D | M] Malwarebytes -> C:\Documents and Settings\winxp\Application Data\Malwarebytes -> [2008/09/30 12:50:56 | 00,000,000 | —D | M] Microsoft -> C:\Documents and Settings\winxp\Application Data\Microsoft -> [2008/09/30 15:19:57 | 00,000,000 | –SD | M] Move Networks -> C:\Documents and Settings\winxp\Application Data\Move Networks -> [2007/10/22 16:40:37 | 00,000,000 | —D | M] Mozilla -> C:\Documents and Settings\winxp\Application Data\Mozilla -> [2006/10/29 00:10:43 | 00,000,000 | —D | M] MSN6 -> C:\Documents and Settings\winxp\Application Data\MSN6 -> [2006/09/08 10:48:36 | 00,000,000 | —D | M] MSNInstaller -> C:\Documents and Settings\winxp\Application Data\MSNInstaller -> [2006/07/29 09:24:04 | 00,000,000 | —D | M] Real -> C:\Documents and Settings\winxp\Application Data\Real -> [2006/10/29 00:14:42 | 00,000,000 | —D | M] Registry Booster -> C:\Documents and Settings\winxp\Application Data\Registry Booster -> [2006/10/22 12:34:58 | 00,000,000 | —D | M] Seven Zip -> C:\Documents and Settings\winxp\Application Data\Seven Zip -> [2006/06/04 23:23:07 | 00,000,000 | —D | M] Skype -> C:\Documents and Settings\winxp\Application Data\Skype -> [2007/08/25 20:11:31 | 00,000,000 | —D | M] Sun -> C:\Documents and Settings\winxp\Application Data\Sun -> [2006/05/14 19:07:19 | 00,000,000 | —D | M] Talkback -> C:\Documents and Settings\winxp\Application Data\Talkback -> [2006/10/29 00:10:53 | 00,000,000 | —D | M] U3 -> C:\Documents and Settings\winxp\Application Data\U3 -> [2008/09/14 01:30:25 | 00,000,000 | —D | M] Uniblue -> C:\Documents and Settings\winxp\Application Data\Uniblue -> [2007/04/15 21:15:40 | 00,000,000 | —D | M] Ventrilo -> C:\Documents and Settings\winxp\Application Data\Ventrilo -> [2006/04/07 20:37:58 | 00,000,000 | —D | M] Viewpoint -> C:\Documents and Settings\winxp\Application Data\Viewpoint -> [2006/07/25 14:08:43 | 00,000,000 | —D | M] vlc -> C:\Documents and Settings\winxp\Application Data\vlc -> [2007/12/06 19:06:02 | 00,000,000 | —D | M] Vso -> C:\Documents and Settings\winxp\Application Data\Vso -> [2006/06/04 22:08:52 | 00,000,000 | —D | M] C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2008/08/10 23:27:08 | 00,000,000 | –SD | M] AppleSoftwareUpdate.job -> C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -> [2008/08/29 14:28:10 | 00,000,284 | —- | M] () desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/04 08:00:00 | 00,000,065 | RH– | M] () SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2008/10/19 18:32:05 | 00,000,006 | -H– | M] () [File - Purity Scan] [CatchMe Rootkit Scan by GMER] < Windows folder & sub-folders > scanning hidden processes … scanning hidden services & system hive … scanning hidden registry entries … scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 6 < Document and Settings folder & sub folders > scanning hidden files … C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\Sharing Folders\[removed]\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\01\10-{44B5AFD8-2E05-5F03-028F-DE5DADF03011}-v1-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\12\12-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v12-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7032 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\12\12-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v12-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\13\13-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v13-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8346 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\13\13-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v13-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\14\14-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v14-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9354 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\14\14-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v14-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\15\15-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v15-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7158 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\15\15-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v15-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\16\16-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v16-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8184 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\16\16-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v16-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 912 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\17\17-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v17-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8904 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\17\17-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v17-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1008 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\18\18-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v18-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8670 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\18\18-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v18-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1000 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\19\19-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v19-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8058 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\19\19-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v19-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 896 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\20\20-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v20-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7410 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\20\20-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v20-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 840 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\21\21-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v21-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7590 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\21\21-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v21-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 864 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\22\22-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v22-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7374 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\22\22-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v22-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\23\23-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v23-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8364 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\23\23-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v23-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\24\24-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v24-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7536 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\24\24-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v24-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\25\25-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v25-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7140 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\25\25-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v25-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\26\26-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v26-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6942 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\26\26-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v26-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 784 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\27\27-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v27-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7410 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\27\27-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v27-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\28\28-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v28-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8166 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\28\28-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v28-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 936 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\29\29-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v29-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6654 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\29\29-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v29-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 744 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\30\30-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v30-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8346 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\30\30-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v30-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\31\31-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v31-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7086 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\31\31-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v31-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\32\32-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v32-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8094 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\32\32-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v32-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 880 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\33\33-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v33-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7140 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\33\33-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v33-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\34\34-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v34-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6654 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\34\34-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v34-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 744 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\35\35-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v35-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7320 bytes hidden from API C:\Documents and Settings\winxp\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{44B5AFD8-2E05-5F03-028F-DE5DADF03011}\35\35-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v35-{4362E3E7-4406-4B9D-B21F-B8F115DFBFF2}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API C:\Documents and Settings\winxp\My Documents\Memory Card\my_pix\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\Memory Card\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Downloads\LimeWire PRO 4.10.7\AC#ACM\AC3ACM\ReadMe\New Folder (3)\New Folder (3)\New Folder (3)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Downloads\LimeWire PRO 4.10.7\AC#ACM\AC3ACM\ReadMe\New Folder (3)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Downloads\LimeWire PRO 4.10.7\AC#ACM\AC3ACM\ReadMe\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\3-3-08\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Albums\BoA\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Albums\KARA (Fin.K.L 2) - The First Blooming\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Albums\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\Praise\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\Review\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\SS\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\TKD\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\ C:\Documents and Settings\winxp\My Documents\My Music\Sancho\ C:\Documents and Settings\winxp\My Documents\My Music\Sancho\ C:\Documents and Settings\winxp\My Documents\My Music\Sancho\ C:\Documents and Settings\winxp\My Documents\My Music\Sancho\English\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\Japanese\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Dance\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Sg wanna be+ & SeeYa\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Sonx\Se7en\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Sonx\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Sancho\N's music\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Favorites\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\iTunes\Album Artwork\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\iTunes\iTunes Music\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\iTunes\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Luis Miguel\Segundo Romance\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Music\Luis Miguel\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\Ssantz\School\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\Ssantz\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\Canon\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\Cell Phone\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\CIA\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\Lobster\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\MOMA\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\NY\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\SM Audition\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\TKD\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Pictures\MISC\ C:\Documents and Settings\winxp\My Documents\My Received Files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Movies\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Music Videos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Performances\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Veoh\thumbs\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\Veoh\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\My Videos\ C:\Documents and Settings\winxp\My Documents\My Videos\ C:\Documents and Settings\winxp\My Documents\My Videos\ C:\Documents and Settings\winxp\My Documents\School Work\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\winxp\My Documents\V3 2007 Ç÷¡Æ¼´½-Æò»ý¾÷µ¥ÀÌÆ®\V3 2007 Platinum(v3 2007 ÀÚµ¿¾÷µ¥ÀÌÆ® )\_Setup\AutoRun\Thumbs.db:encryptable 0 bytes scan completed successfully hidden files: 517 < End of report >
Perfect

You shouldn't have run ComboFix by yourself

Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {030A0F33-5B99-482E-83F5-2EEB8457878B} [HKLM] -> %SystemRoot%\system32\675873\675873.dll [675873 Class]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{144A6B24-0EBC-4D89-BF09-A06A718E57B5}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{867AB302-E62F-4e8e-B297-6444A9C81D09}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{9034A523-D068-4BE8-A284-9DF278BE776E}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List
YN -> "C:\Program Files\AIM\aim.exe" -> C:\Program Files\AIM\aim.exe [C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YY -> "C:\WINDOWS\system32\BugsSvr.exe" -> C:\WINDOWS\system32\BugsSvr.exe [C:\WINDOWS\system32\BugsSvr.exe:*:Enabled:Bugs Music Player Control]
YY -> "C:\WINDOWS\system32\cjmvsvr.exe" -> C:\WINDOWS\system32\cjmvsvr.exe [C:\WINDOWS\system32\cjmvsvr.exe:*:Enabled:CJMUSIC VoD Control]
YY -> "C:\WINDOWS\system32\p3bvsvr.exe" -> C:\WINDOWS\system32\p3bvsvr.exe [C:\WINDOWS\system32\p3bvsvr.exe:*:Enabled:Bugs Music VoD Control]
YY -> "C:\WINDOWS\system32\P3MxSvr.exe" -> C:\WINDOWS\system32\P3MxSvr.exe [C:\WINDOWS\system32\P3MxSvr.exe:*:Enabled:Maxmp3 AoD Control]
YY -> "C:\WINDOWS\system32\p3mxvsvr.exe" -> C:\WINDOWS\system32\p3mxvsvr.exe [C:\WINDOWS\system32\p3mxvsvr.exe:*:Enabled:MAXMP3 VOD Control]
YY -> "C:\WINDOWS\system32\skcbgm.exe" -> C:\WINDOWS\system32\skcbgm.exe [C:\WINDOWS\system32\skcbgm.exe:*:Enabled:SK Communications Cyworld BGM Player]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> \I\Shell\AutoRun\command\\"" -> I:\LaunchU3.exe [I:\LaunchU3.exe -a]
[Registry - Additional Scans - Safe List]
< Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\
YN -> HotKeysCmds hkey= key= ->
YN -> IgfxTray hkey= key= ->
YN -> InCD hkey= key= ->
YN -> NeroFilterCheck hkey= key= ->
YN -> QuickTime Task hkey= key= ->
YN -> SoundMan hkey= key= ->
YN -> updateMgr hkey= key= ->
YN -> VirRL2009 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\VirRL2009\VirRL2009.exe
[Files/Folders - Created Within 90 Days]
NY -> 1 C:\*.tmp files -> C:\*.tmp
NY -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> tmp.reg -> %SystemRoot%\System32\tmp.reg
NY -> VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe
NY -> SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe
NY -> swreg.exe -> %SystemRoot%\System32\swreg.exe
NY -> AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe
NY -> VACFix.exe -> %SystemRoot%\System32\VACFix.exe
NY -> o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe
NY -> IEDFix.exe -> %SystemRoot%\System32\IEDFix.exe
NY -> IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe
NY -> 404Fix.exe -> %SystemRoot%\System32\404Fix.exe
NY -> swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe
NY -> Process.exe -> %SystemRoot%\System32\Process.exe
NY -> dumphive.exe -> %SystemRoot%\System32\dumphive.exe
NY -> swsc.exe -> %SystemRoot%\System32\swsc.exe
NY -> WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe
NY -> SmitfraudFix -> %UserProfile%\Desktop\SmitfraudFix
NY -> SmitfraudFix.exe -> %UserProfile%\Desktop\SmitfraudFix.exe
NY -> tmp3.reg -> %SystemDrive%\tmp3.reg
NY -> 675873 -> %SystemRoot%\System32\675873
NY -> ComboFix -> %SystemDrive%\ComboFix
NY -> udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll
[Files/Folders - Modified Within 90 Days]
NY -> udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll
NY -> mgxoschk.ini -> %SystemRoot%\mgxoschk.ini
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.




Also post a new HJT log
OTScanIt2 logfile created on: 10/19/2008 7:22:37 PM - Run 2
OTScanIt2 by OldTimer - Version 1.0.0.17b	 Folder = C:\Documents and Settings\winxp\Desktop\OTScanIt2
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
511.29 Mb Total Physical Memory | 167.68 Mb Available Physical Memory | 32.80% Memory free
1.22 Gb Paging File | 0.81 Gb Available in Paging File | 66.86% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 92.81 Gb Free Space | 62.27% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: WINXP-A88C7D920
Current User Name: winxp
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
 
[Processes - Safe List]
ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> [2007/08/21 21:57:14 | 00,487,424 | —- | M] (ATI Technologies Inc.)
incdsrv.exe -> %ProgramFiles%\Ahead\InCD\InCDsrv.exe -> [2005/06/10 18:19:38 | 00,869,888 | —- | M] (Nero AG)
ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> [2007/08/21 21:57:14 | 00,487,424 | —- | M] (ATI Technologies Inc.)
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/07/22 20:42:12 | 00,116,040 | —- | M] (Apple Inc.)
avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/09/30 15:13:41 | 00,231,704 | —- | M] (AVG Technologies CZ, s.r.o.)
mdm.exe -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 00:25:00 | 00,322,120 | —- | M] (Microsoft Corporation)
pnkbstra.exe -> %SystemRoot%\system32\PnkBstrA.exe -> [2008/01/05 22:24:53 | 00,066,872 | —- | M] ()
avgtray.exe -> %ProgramFiles%\AVG\AVG8\avgtray.exe -> [2008/10/01 09:38:16 | 01,234,712 | —- | M] (AVG Technologies CZ, s.r.o.)
mom.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\MOM.exe -> [2007/07/17 11:13:56 | 00,049,152 | —- | M] (Advanced Micro Devices Inc.)
soundman.exe -> %SystemRoot%\soundman.exe -> [2007/04/16 15:28:22 | 00,577,536 | —- | M] (Realtek Semiconductor Corp.)
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008/07/30 10:47:56 | 00,289,064 | —- | M] (Apple Inc.)
ccc.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\CCC.exe -> [2007/07/17 11:13:34 | 00,049,152 | —- | M] (ATI Technologies Inc.)
avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> [2008/09/30 15:13:47 | 00,287,000 | —- | M] (AVG Technologies CZ, s.r.o.)
avgemc.exe -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2008/09/30 15:13:43 | 00,875,288 | —- | M] (AVG Technologies CZ, s.r.o.)
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/07/30 10:47:48 | 00,532,264 | —- | M] (Apple Inc.)
iexplore.exe -> %ProgramFiles%\Internet Explorer\iexplore.exe -> [2008/04/13 20:12:22 | 00,093,184 | —- | M] (Microsoft Corporation)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/10/18 12:23:46 | 00,417,280 | —- | M] (OldTimer Tools)
 
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/07/22 20:42:12 | 00,116,040 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation)
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ati2evxx.exe -> [2007/08/21 21:57:14 | 00,487,424 | —- | M] (ATI Technologies Inc.)
(ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2sgag.exe -> [2007/08/21 21:05:00 | 00,593,920 | —- | M] ()
(avg8emc) AVG Free8 E-mail Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2008/09/30 15:13:43 | 00,875,288 | —- | M] (AVG Technologies CZ, s.r.o.)
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/09/30 15:13:41 | 00,231,704 | —- | M] (AVG Technologies CZ, s.r.o.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Stopped] ->  -> File not found
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation)
(InCDsrv) InCD Helper [Win32_Own | Auto | Running] -> %ProgramFiles%\Ahead\InCD\InCDsrv.exe -> [2005/06/10 18:19:38 | 00,869,888 | —- | M] (Nero AG)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/07/30 10:47:48 | 00,532,264 | —- | M] (Apple Inc.)
(MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 00:25:00 | 00,322,120 | —- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 13:28:22 | 00,089,136 | —- | M] (Microsoft Corporation)
(PnkBstrA) PnkBstrA [Win32_Own | Auto | Running] -> %SystemRoot%\system32\PnkBstrA.exe -> [2008/01/05 22:24:53 | 00,066,872 | —- | M] ()
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\MSN Messenger\usnsvc.exe -> [2007/01/19 12:54:14 | 00,097,136 | —- | M] (Microsoft Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\alcxwdm.sys -> [2008/01/24 16:36:16 | 04,127,488 | R— | M] (Realtek Semiconductor Corp.)
(ASPI) Advanced SCSI Programming Interface Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ASPI32.SYS -> [2002/07/17 10:05:10 | 00,016,512 | —- | M] (Adaptec)
(ASPI32) ASPI32 [Kernel | System | Running] -> %SystemRoot%\System32\drivers\ASPI32.SYS -> [2002/07/17 10:05:10 | 00,016,512 | —- | M] (Adaptec)
(ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ati2mtag.sys -> [2007/08/21 22:07:39 | 02,417,664 | —- | M] (ATI Technologies Inc.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\system32\drivers\avgldx86.sys -> [2008/09/30 15:13:58 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\system32\drivers\avgmfx86.sys -> [2008/09/30 15:13:57 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgTdiX) AVG Free8 Network Redirector [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\avgtdix.sys -> [2008/09/30 15:14:01 | 00,076,040 | —- | M] (AVG Technologies CZ, s.r.o.)
(FsVga) FsVga [Kernel | System | Running] -> %SystemRoot%\system32\drivers\fsvga.sys -> [2004/08/04 08:00:00 | 00,012,160 | —- | M] (Microsoft Corporation)
(GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> [2008/01/29 12:01:28 | 00,016,168 | —- | M] (GEAR Software Inc.)
(ialm) ialm [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ialmnt5.sys -> [2004/11/01 21:27:20 | 00,773,565 | R— | M] (Intel Corporation)
(InCDfs) InCD File System [File_System | Disabled | Running] -> %SystemRoot%\System32\drivers\InCDfs.sys -> [2005/06/10 18:12:12 | 00,099,584 | —- | M] (Nero AG)
(InCDPass) InCDPass [Kernel | System | Running] -> %SystemRoot%\system32\drivers\InCDpass.sys -> [2005/06/10 18:11:50 | 00,029,696 | —- | M] (Nero AG)
(incdrm) InCD Reader [Kernel | System | Running] -> %SystemRoot%\System32\drivers\InCDrm.sys -> [2005/06/10 10:11:44 | 00,028,160 | —- | M] (Nero AG)
(pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pfc.sys -> [2003/12/05 05:46:36 | 00,010,368 | —- | M] (Padus, Inc.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2004/08/04 08:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> [2007/03/29 03:00:00 | 00,043,528 | —- | M] (Sonic Solutions)
(RTL8023xp) Realtek 10/100/1000 NIC Family all in one NDIS XP Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Rtlnicxp.sys -> [2005/03/03 23:10:26 | 00,074,496 | R— | M] (Realtek Semiconductor Corporation						   )
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\RTL8139.sys -> [2004/08/03 18:31:34 | 00,020,992 | —- | M] (Realtek Semiconductor Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(STEC3) STEC3 [Kernel | Auto | Running] -> %SystemRoot%\system32\STEC3.sys -> [2007/11/27 17:38:48 | 00,002,368 | —- | M] (AntiCracking)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usbaapl.sys -> [2008/07/22 20:32:44 | 00,032,000 | —- | M] (Apple, Inc.)
(USB_RNDIS_XP) Westell WireSpeed Dual Connect Modem [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\usb8023.sys -> [2008/04/13 14:56:49 | 00,012,800 | —- | M] (Microsoft Corporation)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\windows\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> 
HKEY_LOCAL_MACHINE\: Search\\"" ->  -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
HKEY_LOCAL_MACHINE\: SearchURL\\"" ->  -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\windows\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.google.com/ -> 
HKEY_CURRENT_USER\: SearchURL\\"" -> http://home.microsoft.com/access/autosearch.asp?p=%s -> 
HKEY_CURRENT_USER\: SearchURL\\"provider" ->  -> 
HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> 
HKEY_CURRENT_USER\: "ProxyOverride" -> 127.0.0.1;*.local -> 
< HOSTS File > (27 bytes and 1 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
127.0.0.1	   localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{030A0F33-5B99-482E-83F5-2EEB8457878B} [HKLM] -> %SystemRoot%\system32\675873\675873.dll [675873 Class] -> File not found
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2008/09/30 15:13:47 | 00,455,960 | —- | M] (AVG Technologies CZ, s.r.o.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_10\bin\ssv.dll [SSVHelper Class] -> [2006/11/09 16:21:52 | 00,440,056 | —- | M] (Sun Microsystems, Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{D0943516-5076-4020-A3B5-AEFAF26AB263}" [HKLM] -> %ProgramFiles%\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [Veoh Browser Plug-in] -> [2008/02/22 21:31:18 | 00,352,256 | —- | M] (Veoh Networks Inc)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{144A6B24-0EBC-4D89-BF09-A06A718E57B5}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2008/10/01 09:38:16 | 01,234,712 | —- | M] (AVG Technologies CZ, s.r.o.)
"IMJPMIG8.1" -> %SystemRoot%\ime\imjp8_1\imjpmig.exe ["C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] -> [2004/08/04 08:00:00 | 00,208,952 | —- | M] (Microsoft Corporation)
"iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/07/30 10:47:56 | 00,289,064 | —- | M] (Apple Inc.)
"MSConfig" -> %SystemRoot%\pchealth\helpctr\binaries\msconfig.exe [C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto] -> [2008/04/13 20:12:27 | 00,169,984 | —- | M] (Microsoft Corporation)
"MSPY2002" -> %SystemRoot%\system32\IME\PINTLGNT\IMSCINST.EXE [C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC] -> [2004/08/04 08:00:00 | 00,059,392 | —- | M] ()
"PHIME2002A" -> %SystemRoot%\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2004/08/04 08:00:00 | 00,455,168 | —- | M] (Microsoft Corporation)
"PHIME2002ASync" -> %SystemRoot%\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> [2004/08/04 08:00:00 | 00,455,168 | —- | M] (Microsoft Corporation)
"SoundMan" -> %SystemRoot%\soundman.exe [SOUNDMAN.EXE] -> [2007/04/16 15:28:22 | 00,577,536 | —- | M] (Realtek Semiconductor Corp.)
"StartCCC" -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ["C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"] -> [2006/11/10 12:35:24 | 00,090,112 | —- | M] ()
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
< winxp Startup Folder > -> C:\Documents and Settings\winxp\Start Menu\Programs\Startup -> 
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer -> 
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [227] -> File not found
\\"NoDrives" ->  [0] -> File not found
\\"NoDriveAutoRun" ->  [67108863] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"HideLegacyLogonScripts" ->  [0] -> File not found
\\"HideLogoffScripts" ->  [0] -> File not found
\\"RunLogonScriptSync" ->  [1] -> File not found
\\"RunStartupScriptSync" ->  [0] -> File not found
\\"HideStartupScripts" ->  [0] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"HideLegacyLogonScripts" ->  [0] -> File not found
\\"HideLogoffScripts" ->  [0] -> File not found
\\"HideStartupScripts" ->  [0] -> File not found
\\"RunLogonScriptSync" ->  [1] -> File not found
\\"RunStartupScriptSync" ->  [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&D&ownload &with BitComet -> %ProgramFiles%\BitComet\BitComet.exe [res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com)
&D&ownload all video with BitComet -> %ProgramFiles%\BitComet\BitComet.exe [res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com)
&D&ownload all with BitComet -> %ProgramFiles%\BitComet\BitComet.exe [res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm] -> [2007/02/08 04:49:42 | 04,526,144 | —- | M] (www.BitComet.com)
E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2008/08/04 16:12:50 | 10,354,176 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_10\bin\NPJPI150_10.dll [Menu: Sun Java Console] -> [2006/11/09 16:21:53 | 00,075,528 | —- | M] (Sun Microsystems, Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2007/04/19 14:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 19:26:26 | 00,947,472 | —- | M] (Microsoft Corporation)
CmdMapping\\"{867AB302-E62F-4e8e-B297-6444A9C81D09}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{9034A523-D068-4BE8-A284-9DF278BE776E}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 14:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4836 domain(s) found. -> 
46 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4880 domain(s) found. -> 
download.com .[*] -> Trusted sites -> 
www_google.com [https] -> Trusted sites -> 
48 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 37 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=67633[Office Genuine Advantage Validation Tool] -> 
{0B96BF84-DA5C-46F4-A7FC-5319CFF74163} [HKLM] -> http://player.mnet.com/package/cjmuset.cab[MnetLauncher Control] -> 
{0CCA191D-13A6-4E29-B746-314DEE697D83} [HKLM] -> http://upload.facebook.com/controls/FacebookPhotoUploader5.cab[Facebook Photo Uploader 5] -> 
{1239CC52-59EF-4DFA-8C61-90FFA846DF7E} [HKLM] -> http://www.musicnotes.com/download/mnviewer.cab[Musicnotes Viewer] -> 
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab[Shockwave ActiveX Control] -> 
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=39204[Windows Genuine Advantage Validation Tool] -> 
{1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} [HKLM] -> http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB[Tpwin Control] -> 
{20A60F0D-9AFA-4515-A0FD-83BD84642501} [HKLM] -> http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab[Checkers Class] -> 
{5C051655-FCD5-4969-9182-770EA5AA5565} [HKLM] -> http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab[Solitaire Showdown Class] -> 
{6A2E758A-028B-46BB-A11D-0608AB5A4ED3} [HKLM] -> http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab[DaumBGMCtrl Class] -> 
{7FC1B346-83E6-4774-8D20-1A6B09B0E737} [HKLM] -> http://cid-2062e4c29cecd973.spaces.live.com/PhotoUpload/MsnPUpld.cab[Windows Live Photo Upload Control] -> 
{882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} [HKLM] -> http://www.maxmp3.co.kr/Ver2/App/totalApp/maxhelper/maxhelper.cab[Reg Error: Key does not exist or could not be opened.] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> 
{938527D1-CDB7-4147-998A-B20FCA5CC976} [HKLM] -> http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10[Cdmcco Class] -> 
{B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} [HKLM] -> http://cafeimg.hanmail.net/cto/1_2_3_5/xman.cab?ver=1,2,3,5[Daum ActiveX manager Class] -> 
{BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} [HKLM] -> http://install.bugs.co.kr/install/BugsInstallerEx.cab[BugsInstallEx Control] -> 
{BFB6D72C-1030-47E4-88A2-614ACCC92467} [HKLM] -> http://www.maxmp3.co.kr/MaxMP3/Html/MPlayer/Movie/__P2P__/Package/p3mxvset.cab[MaxMp3VSet Class] -> 
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab[MessengerStatsClient Class] -> 
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab[Java Plug-in 1.5.0_06] -> 
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> 
{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} [HKLM] -> http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab[Minesweeper Flags Class] -> 
{F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} [HKLM] -> http://www.clubbox.co.kr/neo.fld/MultiUpload.cab[MultiUpload Control] -> 
Microsoft XML Parser for Java [HKLM] -> file://C:\WINDOWS\Java\classes\xmldso.cab[Reg Error: Key does not exist or could not be opened.] -> 
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{071D6C45-70FF-4BAF-A962-2492D96B0B6F} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{0A2B9F81-D36A-46CE-8E0B-4700F7709A2B} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{200DD75C-B1D1-49D6-BB6E-79C452CFD4BC} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{286AF6EB-159D-4E76-8AA6-289F273CDF40} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{3075C271-0468-46ED-8465-57D461DCA6CA} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{31542321-274D-4BE1-87C2-6D900C548D20} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{360F233C-3A83-43D1-83A9-A990E66E7007} ->	() -> 
{3839BC48-2BD9-4C36-90C3-BD799DC43DAF} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{38DC29AB-CDDA-4FD0-BCF9-E57929BD9148} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{3B26581C-74C6-4FDA-861E-A40A8FD76B85} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{41999A77-3DE0-44A6-95F5-2A146BA5752A} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{48EDF500-2504-4497-8C0F-5AC6D497B85F} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{4A0ADBC5-EF89-49BC-9246-AA7FE6FE99C0} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{522D2FCE-D13F-41A8-9D27-4630B0EDB16A} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{6BFECF85-09E9-4B7C-BE38-41DC51E48595} ->	(1394 Net Adapter) -> 
{6DE86882-D361-4474-B718-9A7D03892B04} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{75BDDF19-2423-46A9-BF6A-3DEC91CE8F32} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{786699C2-7332-4173-847E-72D757B4FFFF} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{903A496C-52C8-4FB0-9F77-92886AD6F864} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{999D8D0E-013B-4045-B84E-DCE6010AABE2} ->	(Westell WireSpeed Dual Connect Modem) -> 
{9F1B87A7-4840-4940-A317-20636963E260} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{A0B94B5F-1FAA-4CFE-A670-0690221E447F} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{A5A49757-DF49-47F9-972A-A104F92F3FB0} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{A5F8252B-7A53-4B3E-A4F2-3F9E011D2EB8} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{B187D059-C994-477B-B0D0-AF4A61FD0B57} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{B2802976-A05F-427D-8524-274EB9C17B5E} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{B2EE89A9-69F3-4CF7-AD6F-BD5FBF32405C} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{B631C3C0-4499-4E2F-8527-8D865C0D4C50} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{BA012AB4-72DF-4939-86C5-93CE8FEBF682} ->	(1394 Net Adapter) -> 
{C0BC3CD5-5184-42FB-88F7-D860D88D20E2} ->	() -> 
{DBDA3452-D2F5-40F8-A387-9C470D6E2D1C} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{F3F10CFF-2B61-42F1-96F9-D9D3091566FC} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{F7BDF2D4-8AEC-43F3-A8D5-A50E69C69EED} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{F8D71487-3173-478F-B0E6-8BFD0911B767} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll -> [2007/08/21 21:58:42 | 00,122,880 | —- | M] (ATI Technologies Inc.)
igfxcui -> %SystemRoot%\system32\igfxsrvc.dll -> [2004/11/01 20:59:20 | 00,348,160 | R— | M] (Intel Corporation)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Program Files\AIM\aim.exe" -> C:\Program Files\AIM\aim.exe [C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger] -> File not found
"C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe [C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe:*:Enabled:AOL Services] -> [2005/08/02 15:33:02 | 00,151,640 | —- | M] (America Online, Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 03:17:27 | 00,010,800 | —- | M] (AOL LLC)
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme" -> C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme [C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme:*:Enabled:GunBound] -> [2008/05/16 16:08:10 | 01,359,872 | —- | M] (Softnyx)
"C:\ijji\ENGLISH\u_gbound.exe" -> C:\ijji\ENGLISH\u_gbound.exe [C:\ijji\ENGLISH\u_gbound.exe:*:Enabled:] -> [2008/05/19 22:06:06 | 00,868,352 | —- | M] (NHN USA inc.)
"C:\Program Files\AIM6\aim6.exe" -> C:\Program Files\AIM6\aim6.exe [C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM] -> [2008/01/03 12:15:06 | 00,050,528 | —- | M] (AOL LLC)
"C:\Program Files\AVG\AVG8\avgemc.exe" -> C:\Program Files\AVG\AVG8\avgemc.exe [C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe] -> [2008/09/30 15:13:43 | 00,875,288 | —- | M] (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> [2008/09/30 15:13:44 | 00,641,304 | —- | M] (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe [C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe:*:Enabled:AIM] -> [2006/08/28 16:22:24 | 00,050,768 | —- | M] (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe [C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe:*:Enabled:AOL Services] -> [2005/08/02 15:33:02 | 00,151,640 | —- | M] (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe" -> C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe [C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe:*:Enabled:AOL Services] -> [2006/05/09 20:24:16 | 00,050,760 | —- | M] (America Online, Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 03:17:27 | 00,010,800 | —- | M] (AOL LLC)
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe" -> C:\Program Files\EA GAMES\Battlefield 2\BF2.exe [C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2] -> [2006/09/26 18:53:22 | 07,574,463 | —- | M] ()
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/07/30 10:47:50 | 20,252,968 | —- | M] (Apple Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> [2006/02/10 19:14:27 | 00,081,920 | —- | M] (Lime Wire, LLC)
"C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\BugsSvr.exe" -> C:\WINDOWS\system32\BugsSvr.exe [C:\WINDOWS\system32\BugsSvr.exe:*:Enabled:Bugs Music Player Control] -> [2005/12/23 17:03:32 | 00,167,936 | —- | M] ()
"C:\WINDOWS\system32\cjmvsvr.exe" -> C:\WINDOWS\system32\cjmvsvr.exe [C:\WINDOWS\system32\cjmvsvr.exe:*:Enabled:CJMUSIC VoD Control] -> [2007/05/03 18:50:05 | 00,176,128 | —- | M] ((c) CJ MUSIC)
"C:\WINDOWS\system32\clubbox.exe" -> C:\WINDOWS\system32\clubbox.exe [C:\WINDOWS\system32\clubbox.exe:*:Enabled:CLUBBOX File Transfer Manager] -> [2008/02/28 06:58:00 | 01,536,000 | R— | M] (Nowcom, Co. LTD.)
"C:\WINDOWS\system32\fscagent.exe" -> C:\WINDOWS\system32\fscagent.exe [C:\WINDOWS\system32\fscagent.exe:*:Enabled:???? ???? ??] -> [2008/02/25 12:24:40 | 00,159,744 | R— | M] (Nowcom Co., Ltd.)
"C:\WINDOWS\system32\p3bvsvr.exe" -> C:\WINDOWS\system32\p3bvsvr.exe [C:\WINDOWS\system32\p3bvsvr.exe:*:Enabled:Bugs Music VoD Control] -> [2006/02/18 11:38:09 | 00,167,936 | —- | M] ((c) PeeringPortal)
"C:\WINDOWS\system32\P3MxSvr.exe" -> C:\WINDOWS\system32\P3MxSvr.exe [C:\WINDOWS\system32\P3MxSvr.exe:*:Enabled:Maxmp3 AoD Control] -> [2007/06/20 12:17:54 | 00,159,744 | —- | M] ()
"C:\WINDOWS\system32\p3mxvsvr.exe" -> C:\WINDOWS\system32\p3mxvsvr.exe [C:\WINDOWS\system32\p3mxvsvr.exe:*:Enabled:MAXMP3 VOD Control] -> [2007/02/12 11:12:48 | 00,202,520 | —- | M] (Maxmp3)
"C:\WINDOWS\system32\skcbgm.exe" -> C:\WINDOWS\system32\skcbgm.exe [C:\WINDOWS\system32\skcbgm.exe:*:Enabled:SK Communications Cyworld BGM Player] -> [2007/01/09 18:15:26 | 00,163,840 | —- | M] ((c) SK Communications)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 14:40:46 | 00,062,976 | —- | M] (Microsoft Corporation)
< Drives with AutoRun files > ->  -> 
C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2006/01/26 16:44:23 | 00,000,000 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell
\I\Shell\\"" ->  [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell\AutoRun
\I\Shell\AutoRun\\"" ->  [Auto&Play] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell\AutoRun\command
\I\Shell\AutoRun\command\\"" -> I:\LaunchU3.exe [I:\LaunchU3.exe -a] -> File not found
 
 
[Files/Folders - Created Within 30 Days]
1 C:\*.tmp files -> C:\*.tmp -> 
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2008/10/19 18:43:49 | 00,000,000 | —D | C]
tmp.reg -> %SystemRoot%\System32\tmp.reg -> [2008/10/19 18:35:54 | 00,002,340 | —- | C] ()
VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe -> [2008/10/19 18:35:31 | 00,289,144 | —- | C] (S!Ri)
SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe -> [2008/10/19 18:35:31 | 00,288,417 | —- | C] (S!Ri)
swreg.exe -> %SystemRoot%\System32\swreg.exe -> [2008/10/19 18:35:31 | 00,135,168 | —- | C] (SteelWerX)
AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe -> [2008/10/19 18:35:31 | 00,088,576 | —- | C] (S!Ri.URZ)
VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> [2008/10/19 18:35:31 | 00,087,552 | —- | C] (S!Ri.URZ)
o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe -> [2008/10/19 18:35:31 | 00,082,944 | —- | C] (S!Ri.URZ)
IEDFix.exe -> %SystemRoot%\System32\IEDFix.exe -> [2008/10/19 18:35:31 | 00,082,944 | —- | C] (S!Ri.URZ)
IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe -> [2008/10/19 18:35:31 | 00,082,944 | —- | C] (S!Ri.URZ)
404Fix.exe -> %SystemRoot%\System32\404Fix.exe -> [2008/10/19 18:35:31 | 00,082,432 | —- | C] (S!Ri.URZ)
swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe -> [2008/10/19 18:35:31 | 00,079,360 | —- | C] (SteelWerX)
Process.exe -> %SystemRoot%\System32\Process.exe -> [2008/10/19 18:35:31 | 00,053,248 | —- | C] (http://www.beyondlogic.org)
dumphive.exe -> %SystemRoot%\System32\dumphive.exe -> [2008/10/19 18:35:31 | 00,051,200 | —- | C] ()
swsc.exe -> %SystemRoot%\System32\swsc.exe -> [2008/10/19 18:35:31 | 00,040,960 | —- | C] ()
WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe -> [2008/10/19 18:35:31 | 00,025,600 | —- | C] ()
SmitfraudFix -> %UserProfile%\Desktop\SmitfraudFix -> [2008/10/19 18:35:26 | 00,000,000 | —D | C]
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/10/19 18:27:53 | 00,587,711 | —- | C] ()
SmitfraudFix.exe -> %UserProfile%\Desktop\SmitfraudFix.exe -> [2008/10/19 18:26:28 | 01,662,674 | —- | C] ()
tmp3.reg -> %SystemDrive%\tmp3.reg -> [2008/10/19 17:36:51 | 00,000,126 | —- | C] ()
675873 -> %SystemRoot%\System32\675873 -> [2008/10/19 17:36:29 | 00,000,000 | —D | C]
My Documents.url -> %UserProfile%\My Documents\My Documents.url -> [2008/10/19 17:36:24 | 00,000,133 | —- | C] ()
$AVG8.VAULT$ -> %SystemDrive%\$AVG8.VAULT$ -> [2008/10/19 17:35:28 | 00,000,000 | -H-D | C]
srv.sys -> %SystemRoot%\System32\dllcache\srv.sys -> [2008/10/14 19:23:24 | 00,333,824 | —- | C] (Microsoft Corporation)
win32k.sys -> %SystemRoot%\System32\dllcache\win32k.sys -> [2008/10/14 19:22:01 | 01,846,400 | —- | C] (Microsoft Corporation)
ntkrnlmp.exe -> %SystemRoot%\System32\dllcache\ntkrnlmp.exe -> [2008/10/14 19:21:41 | 02,145,280 | —- | C] (Microsoft Corporation)
ntoskrnl.exe -> %SystemRoot%\System32\dllcache\ntoskrnl.exe -> [2008/10/14 19:21:40 | 02,189,184 | —- | C] (Microsoft Corporation)
ntkrpamp.exe -> %SystemRoot%\System32\dllcache\ntkrpamp.exe -> [2008/10/14 19:21:39 | 02,023,936 | —- | C] (Microsoft Corporation)
ntkrnlpa.exe -> %SystemRoot%\System32\dllcache\ntkrnlpa.exe -> [2008/10/14 19:21:38 | 02,066,048 | —- | C] (Microsoft Corporation)
ijji -> %SystemDrive%\ijji -> [2008/10/05 13:42:40 | 00,000,000 | —D | C]
ChCfg.exe -> %SystemRoot%\System32\ChCfg.exe -> [2008/09/30 23:23:36 | 00,049,152 | —- | C] ()
Realtek AC97 -> %ProgramFiles%\Realtek AC97 -> [2008/09/30 23:22:24 | 00,000,000 | —D | C]
alsndmgr.wav -> %SystemRoot%\System32\alsndmgr.wav -> [2008/09/30 23:22:17 | 00,141,016 | —- | C] ()
RtlCPAPI.dll -> %SystemRoot%\System32\RtlCPAPI.dll -> [2008/09/30 23:22:12 | 00,147,456 | —- | C] ()
RECYCLER -> %SystemDrive%\RECYCLER -> [2008/09/30 23:10:45 | 00,000,000 | -HSD | C]
ComboFix -> %SystemDrive%\ComboFix -> [2008/09/30 21:38:44 | 00,000,000 | —D | C]
temp -> %SystemRoot%\temp -> [2008/09/30 21:12:39 | 00,000,000 | —D | C]
USetup.iss -> %SystemRoot%\USetup.iss -> [2008/09/30 16:41:44 | 00,000,553 | —- | C] ()
Realtek -> %ProgramFiles%\Realtek -> [2008/09/30 16:40:51 | 00,000,000 | —D | C]
avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2008/09/30 15:14:02 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.)
avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2008/09/30 15:14:01 | 00,076,040 | —- | C] (AVG Technologies CZ, s.r.o.)
avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2008/09/30 15:13:58 | 00,097,928 | —- | C] (AVG Technologies CZ, s.r.o.)
avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2008/09/30 15:13:57 | 00,026,824 | —- | C] (AVG Technologies CZ, s.r.o.)
incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2008/09/30 15:13:50 | 29,045,884 | —- | C] ()
miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2008/09/30 15:13:50 | 00,307,238 | —- | C] ()
microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2008/09/30 15:13:50 | 00,043,628 | —- | C] ()
avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2008/09/30 15:13:49 | 06,061,540 | —- | C] ()
Avg -> %SystemRoot%\System32\drivers\Avg -> [2008/09/30 15:13:49 | 00,000,000 | —D | C]
Malwarebytes -> %AppData%\Malwarebytes -> [2008/09/30 12:50:56 | 00,000,000 | —D | C]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2008/09/30 12:50:29 | 00,017,200 | —- | C] (Malwarebytes Corporation)
mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2008/09/30 12:50:27 | 00,038,528 | —- | C] (Malwarebytes Corporation)
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2008/09/30 12:50:25 | 00,000,000 | —D | C]
Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2008/09/30 12:50:23 | 00,000,000 | —D | C]
Download Manager -> %CommonProgramFiles%\Download Manager -> [2008/09/30 12:49:33 | 00,000,000 | —D | C]
ERDNT -> %SystemRoot%\ERDNT -> [2008/09/30 12:21:21 | 00,000,000 | —D | C]
ERUNT -> %ProgramFiles%\ERUNT -> [2008/09/30 12:20:01 | 00,000,000 | —D | C]
Trend Micro -> %ProgramFiles%\Trend Micro -> [2008/09/29 20:51:14 | 00,000,000 | —D | C]
Avg8 -> %AllUsersProfile%\Application Data\Avg8 -> [2008/09/28 13:41:56 | 00,000,000 | —D | C]
udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll -> [2008/09/28 13:10:23 | 00,105,984 | —- | C] ()
Yahoo! -> %ProgramFiles%\Yahoo! -> [2008/09/27 21:35:35 | 00,000,000 | —D | C]
AVG -> %ProgramFiles%\AVG -> [2008/09/27 21:29:28 | 00,000,000 | —D | C]
Spybot - Search & Destroy -> %ProgramFiles%\Spybot - Search & Destroy -> [2008/09/27 21:17:47 | 00,000,000 | —D | C]
Spybot - Search & Destroy -> %AllUsersProfile%\Application Data\Spybot - Search & Destroy -> [2008/09/27 21:17:47 | 00,000,000 | —D | C]
PubPlugin.dll -> %SystemRoot%\System32\PubPlugin.dll -> [2008/09/20 22:52:02 | 00,157,152 | —- | C] (NHN Corporation)
 
[Files/Folders - Modified Within 30 Days]
1 C:\*.tmp files -> C:\*.tmp -> 
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
1 C:\Documents and Settings\winxp\My Documents\*.tmp files -> C:\Documents and Settings\winxp\My Documents\*.tmp -> 
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [2006/01/26 16:50:18 | 00,000,000 | —D | M]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2008/10/14 19:23:55 | 00,004,232 | —- | M] ()
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2008/10/14 19:23:55 | 00,004,646 | —- | M] ()
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA -> [2006/02/28 21:14:06 | 00,000,000 | —D | M]
opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [2006/02/28 21:14:22 | 00,011,108 | —- | M] ()
C:\WINDOWS\Temp\ -> C:\WINDOWS\temp -> [2008/10/19 19:23:29 | 00,000,000 | —D | M]
alcrmv.exe -> C:\WINDOWS\temp\alcrmv.exe -> [2006/07/31 11:27:30 | 00,217,088 | —- | M] (Realtek Semiconductor Corp.)
alcupd.exe -> C:\WINDOWS\temp\alcupd.exe -> [2006/07/31 11:19:00 | 00,315,392 | —- | M] (Realtek Semiconductor Corp.)
ChCfg.exe -> C:\WINDOWS\temp\ChCfg.exe -> [2006/08/01 15:02:00 | 00,049,152 | —- | M] ()
RTLCPL.exe -> C:\WINDOWS\temp\RTLCPL.exe -> [2006/12/08 15:20:14 | 10,528,768 | —- | M] (Realtek Semiconductor Corp.)
soundman.exe -> C:\WINDOWS\temp\soundman.exe -> [2007/04/16 15:28:22 | 00,577,536 | —- | M] (Realtek Semiconductor Corp.)
C:\WINDOWS\Temp\ -> C:\WINDOWS\temp -> [2008/10/19 19:23:31 | 00,000,000 | —D | M]
newdev.dll -> C:\WINDOWS\temp\newdev.dll -> [2008/04/13 20:12:02 | 00,247,808 | —- | M] (Microsoft Corporation)
RtlCPAPI.dll -> C:\WINDOWS\temp\RtlCPAPI.dll -> [2006/10/18 02:53:26 | 00,147,456 | —- | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2008/10/19 18:55:12 | 00,012,598 | —- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/10/19 18:54:34 | 00,000,006 | -H– | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2008/10/19 18:54:31 | 00,002,048 | –S- | M] ()
tmp.reg -> %SystemRoot%\System32\tmp.reg -> [2008/10/19 18:35:54 | 00,002,340 | —- | M] ()
hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [2008/10/19 18:35:50 | 00,000,027 | —- | M] ()
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/10/19 18:27:56 | 00,587,711 | —- | M] ()
SmitfraudFix.exe -> %UserProfile%\Desktop\SmitfraudFix.exe -> [2008/10/19 18:26:41 | 01,662,674 | —- | M] ()
Microsoft Office Word 2003.lnk -> %UserProfile%\Desktop\Microsoft Office Word 2003.lnk -> [2008/10/19 18:24:31 | 00,002,497 | —- | M] ()
win.ini -> %SystemRoot%\win.ini -> [2008/10/19 17:52:13 | 00,000,624 | —- | M] ()
system.ini -> %SystemRoot%\system.ini -> [2008/10/19 17:52:13 | 00,000,227 | —- | M] ()
boot.ini -> %SystemDrive%\boot.ini -> [2008/10/19 17:52:13 | 00,000,210 | -HS- | M] ()
incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2008/10/19 17:44:53 | 29,045,884 | —- | M] ()
tmp3.reg -> %SystemDrive%\tmp3.reg -> [2008/10/19 17:36:53 | 00,000,126 | —- | M] ()
My Documents.url -> %UserProfile%\My Documents\My Documents.url -> [2008/10/19 17:36:24 | 00,000,133 | —- | M] ()
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2008/10/18 20:39:25 | 00,002,137 | —- | M] ()
winamp.ini -> %SystemRoot%\winamp.ini -> [2008/10/16 23:20:14 | 00,001,125 | —- | M] ()
microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2008/10/15 20:07:24 | 00,043,628 | —- | M] ()
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2008/10/15 12:32:18 | 00,246,312 | —- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2008/10/14 23:18:26 | 00,001,393 | —- | M] ()
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2008/10/14 23:05:39 | 00,478,288 | —- | M] ()
perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [2008/10/14 23:05:39 | 00,409,232 | —- | M] ()
perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [2008/10/14 23:05:39 | 00,064,372 | —- | M] ()
o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe -> [2008/10/10 08:58:08 | 00,082,944 | —- | M] (S!Ri.URZ)
IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe -> [2008/10/10 08:58:08 | 00,082,944 | —- | M] (S!Ri.URZ)
miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2008/10/09 21:10:22 | 00,307,238 | —- | M] ()
MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2008/10/07 15:19:40 | 16,721,856 | —- | M] (Microsoft Corporation)
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/10/05 22:26:14 | 01,577,134 | -H– | M] ()
VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> [2008/10/01 15:51:40 | 00,087,552 | —- | M] (S!Ri.URZ)
PDBOXGame.html -> %SystemRoot%\System32\PDBOXGame.html -> [2008/09/30 15:23:23 | 00,000,000 | —- | M] ()
avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2008/09/30 15:14:02 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.)
avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2008/09/30 15:14:01 | 00,076,040 | —- | M] (AVG Technologies CZ, s.r.o.)
avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2008/09/30 15:13:58 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.)
avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2008/09/30 15:13:57 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.)
avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2008/09/30 15:13:50 | 06,061,540 | —- | M] ()
udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll -> [2008/09/28 13:10:24 | 00,105,984 | —- | M] ()
WININIT.INI -> %SystemRoot%\WININIT.INI -> [2008/09/28 13:08:41 | 00,000,810 | —- | M] ()
< End of report >








Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:24:12, on 10/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: 675873 helper - {030A0F33-5B99-482E-83F5-2EEB8457878B} - C:\WINDOWS\system32\675873\675873.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.download.com
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {0B96BF84-DA5C-46F4-A7FC-5319CFF74163} (MnetLauncher Control) - http://player.mnet.com/package/cjmuset.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} (DaumBGMCtrl Class) - http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-2062e4c29cecd973.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} - http://www.maxmp3.co.kr/Ver2/App/totalApp/…r/maxhelper.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://cafeimg.hanmail.net/cto/1_2_3_5/xman.cab?ver=1,2,3,5
O16 - DPF: {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} (BugsInstallEx Control) - http://install.bugs.co.kr/install/BugsInstallerEx.cab
O16 - DPF: {BFB6D72C-1030-47E4-88A2-614ACCC92467} (MaxMp3VSet Class) - http://www.maxmp3.co.kr/MaxMP3/Html/MPlaye…ge/p3mxvset.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} (MultiUpload Control) - http://www.clubbox.co.kr/neo.fld/MultiUpload.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 7747 bytes
Hello

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-19 19:26:59
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 95 GB (62%) free of 153 GB
Total RAM: 511 MB (29% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:27:09, on 10/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\winxp\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\winxp.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: 675873 helper - {030A0F33-5B99-482E-83F5-2EEB8457878B} - C:\WINDOWS\system32\675873\675873.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D;&ownload; &with; BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D;&ownload; all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D;&ownload; all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.download.com
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {0B96BF84-DA5C-46F4-A7FC-5319CFF74163} (MnetLauncher Control) - http://player.mnet.com/package/cjmuset.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} (DaumBGMCtrl Class) - http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-2062e4c29cecd973.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} - http://www.maxmp3.co.kr/Ver2/App/totalApp/…r/maxhelper.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://cafeimg.hanmail.net/cto/1_2_3_5/xman.cab?ver=1,2,3,5
O16 - DPF: {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} (BugsInstallEx Control) - http://install.bugs.co.kr/install/BugsInstallerEx.cab
O16 - DPF: {BFB6D72C-1030-47E4-88A2-614ACCC92467} (MaxMp3VSet Class) - http://www.maxmp3.co.kr/MaxMP3/Html/MPlaye…ge/p3mxvset.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} (MultiUpload Control) - http://www.clubbox.co.kr/neo.fld/MultiUpload.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 7792 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{030A0F33-5B99-482E-83F5-2EEB8457878B}]
675873 Class - C:\WINDOWS\system32\675873\675873.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-09-30 455960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 440056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2008-02-22 352256]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-10-01 1234712]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-07-30 289064]
"MSConfig"=C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [2008-04-13 169984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-07-22 116040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClubBox]
C:\WINDOWS\system32\clubbox.exe [2008-02-28 1536000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo R300 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE [2003-06-04 99840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1140128537\ee\AOLSoftware.exe [2006-05-09 50760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe [2006-02-17 124520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPlusAgent2]
C:\Program Files\iriver\iriver plus 2\iAgent2.exe [2005-06-07 237568]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-07-30 289064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
C:\Program Files\Plaxo\2.13.1.6\PlaxoHelper.exe [2008-04-14 227914]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar]
C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe [2004-04-21 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SFP]
C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE [2003-09-05 561152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\program files\steam\steam.exe [2008-03-27 1271032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe [2006-11-09 49263]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirRL2009]
C:\Program Files\VirRL2009\VirRL2009.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~3.0\Reader\READER~1.EXE [2005-09-23 29696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-08-21 122880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-11-01 348160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe"="C:\Program Files\Common Files\AOL\1140128537\ee\aolsoftware.exe:*:Enabled:AOL Services"
"C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe"="C:\Program Files\Common Files\AOL\1140128537\ee\aim6.exe:*:Enabled:AIM"
"C:\WINDOWS\system32\p3bvsvr.exe"="C:\WINDOWS\system32\p3bvsvr.exe:*:Enabled:Bugs Music VoD Control"
"C:\WINDOWS\system32\P3MxSvr.exe"="C:\WINDOWS\system32\P3MxSvr.exe:*:Enabled:Maxmp3 AoD Control"
"C:\WINDOWS\system32\BugsSvr.exe"="C:\WINDOWS\system32\BugsSvr.exe:*:Enabled:Bugs Music Player Control"
"C:\WINDOWS\system32\p3mxvsvr.exe"="C:\WINDOWS\system32\p3mxvsvr.exe:*:Enabled:MAXMP3 VOD Control"
"C:\WINDOWS\system32\clubbox.exe"="C:\WINDOWS\system32\clubbox.exe:*:Enabled:CLUBBOX File Transfer Manager"
"C:\WINDOWS\system32\fscagent.exe"="C:\WINDOWS\system32\fscagent.exe:*:Enabled:???? ???? ??"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"C:\WINDOWS\system32\skcbgm.exe"="C:\WINDOWS\system32\skcbgm.exe:*:Enabled:SK Communications Cyworld BGM Player"
"C:\WINDOWS\system32\cjmvsvr.exe"="C:\WINDOWS\system32\cjmvsvr.exe:*:Enabled:CJMUSIC VoD Control"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"
"C:\ijji\ENGLISH\u_gbound.exe"="C:\ijji\ENGLISH\u_gbound.exe:*:Enabled:"
"C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme"="C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme:*:Enabled:GunBound"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1140128537\ee\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
shell\AutoRun\command - I:\LaunchU3.exe -a


======List of files/folders created in the last 1 months======

2008-10-19 19:26:59 —-D—- C:\rsit
2008-10-19 18:35:54 —-A—- C:\WINDOWS\system32\tmp.txt
2008-10-19 18:35:44 —-A—- C:\rapport.txt
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\WS2Fix.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\VCCLSID.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\VACFix.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\swxcacls.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\swsc.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\swreg.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\SrchSTS.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\Process.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\o4Patch.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\IEDFix.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\IEDFix.C.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\dumphive.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-10-19 18:35:31 —-A—- C:\WINDOWS\system32\404Fix.exe
2008-10-19 17:36:29 —-D—- C:\WINDOWS\system32\675873
2008-10-19 17:35:28 —-HD—- C:\$AVG8.VAULT$
2008-10-14 23:18:30 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-14 23:18:24 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-14 23:18:14 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-14 23:16:29 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-14 23:16:17 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-14 23:12:46 —-HDC—- C:\WINDOWS\$NtUninstallKB956390$
2008-10-05 13:42:40 —-D—- C:\ijji
2008-09-30 23:27:12 —-A—- C:\WINDOWS\ALCFDRTM.EXE
2008-09-30 23:23:36 —-A—- C:\WINDOWS\system32\ChCfg.exe
2008-09-30 23:22:24 —-D—- C:\Program Files\Realtek AC97
2008-09-30 23:22:18 —-A—- C:\WINDOWS\system32\RTLCPL.exe
2008-09-30 23:22:12 —-A—- C:\WINDOWS\system32\RtlCPAPI.dll
2008-09-30 23:22:12 —-A—- C:\WINDOWS\soundman.exe
2008-09-30 23:22:11 —-A—- C:\WINDOWS\alcupd.exe
2008-09-30 23:22:11 —-A—- C:\WINDOWS\Alcrmv.exe
2008-09-30 23:10:45 —-SHD—- C:\RECYCLER
2008-09-30 21:38:44 —-D—- C:\ComboFix
2008-09-30 21:12:39 —-D—- C:\WINDOWS\temp
2008-09-30 21:12:38 —-A—- C:\ComboFix.txt
2008-09-30 16:40:51 —-D—- C:\Program Files\Realtek
2008-09-30 16:40:43 —-A—- C:\WINDOWS\HideWin.exe
2008-09-30 16:40:42 —-A—- C:\WINDOWS\RtlExUpd.dll
2008-09-30 15:14:02 —-A—- C:\WINDOWS\system32\avgrsstx.dll
2008-09-30 12:50:56 —-D—- C:\Documents and Settings\winxp\Application Data\Malwarebytes
2008-09-30 12:50:25 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-30 12:50:23 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-30 12:49:33 —-D—- C:\Program Files\Common Files\Download Manager
2008-09-30 12:21:21 —-D—- C:\WINDOWS\ERDNT
2008-09-30 12:20:01 —-D—- C:\Program Files\ERUNT
2008-09-29 20:51:14 —-D—- C:\Program Files\Trend Micro
2008-09-28 13:41:56 —-D—- C:\Documents and Settings\All Users\Application Data\Avg8
2008-09-27 21:35:35 —-D—- C:\Program Files\Yahoo!
2008-09-27 21:29:28 —-D—- C:\Program Files\AVG
2008-09-27 21:17:47 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-09-27 21:17:47 —-D—- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-27 20:30:25 —-A—- C:\WINDOWS\system32\6b8b34b0-.txt
2008-09-20 22:52:02 —-A—- C:\WINDOWS\system32\PubPlugin.dll

======List of files/folders modified in the last 1 months======

2008-10-19 19:26:53 —-D—- C:\WINDOWS\Prefetch
2008-10-19 19:23:26 —-D—- C:\WINDOWS\system32
2008-10-19 18:53:07 —-A—- C:\WINDOWS\ntbtlog.txt
2008-10-19 18:35:56 —-RD—- C:\Program Files
2008-10-19 18:32:06 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-19 17:52:13 —-ASH—- C:\boot.ini
2008-10-19 17:52:13 —-A—- C:\WINDOWS\win.ini
2008-10-19 17:52:13 —-A—- C:\WINDOWS\system.ini
2008-10-19 17:40:29 —-D—- C:\WINDOWS\system
2008-10-16 23:22:40 —-SHD—- C:\WINDOWS\Installer
2008-10-16 23:22:40 —-SHD—- C:\Config.Msi
2008-10-16 23:20:14 —-A—- C:\WINDOWS\winamp.ini
2008-10-15 12:32:53 —-D—- C:\WINDOWS
2008-10-14 23:18:32 —-HD—- C:\WINDOWS\inf
2008-10-14 23:18:31 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-14 23:18:31 —-D—- C:\WINDOWS\system32\drivers
2008-10-14 23:18:28 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-14 23:18:26 —-A—- C:\WINDOWS\imsins.BAK
2008-10-14 23:12:51 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-14 23:05:41 —-D—- C:\WINDOWS\system32\wbem
2008-10-14 23:05:39 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-07 15:19:40 —-A—- C:\WINDOWS\system32\MRT.exe
2008-09-30 23:22:11 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-30 21:40:25 —-SHD—- C:\System Volume Information
2008-09-30 21:40:25 —-D—- C:\WINDOWS\system32\Restore
2008-09-30 21:09:27 —-D—- C:\WINDOWS\AppPatch
2008-09-30 21:09:27 —-D—- C:\Program Files\Common Files
2008-09-30 19:58:12 —-D—- C:\WINDOWS\system32\config
2008-09-30 18:08:04 —-D—- C:\Temp
2008-09-30 18:08:03 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-09-30 16:41:15 —-D—- C:\WINDOWS\system32\CatRoot
2008-09-30 16:16:51 —-D—- C:\Program Files\AOL
2008-09-30 16:10:07 —-D—- C:\Program Files\Real
2008-09-30 16:08:35 —-D—- C:\Program Files\AhnLab
2008-09-30 16:07:27 —-D—- C:\Program Files\Verizon
2008-09-30 16:07:24 —-D—- C:\Program Files\Common Files\Motive
2008-09-30 16:07:09 —-D—- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-30 15:33:05 —-D—- C:\WINDOWS\pss
2008-09-30 15:26:32 —-D—- C:\Program Files\Steam
2008-09-30 15:23:11 —-D—- C:\Program Files\Plaxo
2008-09-30 15:19:57 —-SD—- C:\Documents and Settings\winxp\Application Data\Microsoft
2008-09-30 15:08:24 —-A—- C:\WINDOWS\setuplog.txt
2008-09-30 14:59:37 —-D—- C:\Program Files\Common Files\AhnLab
2008-09-30 13:25:51 —-D—- C:\Program Files\CyberLink DVD Solution
2008-09-30 13:13:42 —-D—- C:\WINDOWS\system32\MAGIX
2008-09-30 13:07:32 —-D—- C:\dxm6temp
2008-09-28 13:08:41 —-A—- C:\WINDOWS\WININIT.INI
2008-09-27 22:22:44 —-D—- C:\WINDOWS\Minidump
2008-09-27 21:29:02 —-D—- C:\WINDOWS\WinSxS

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [2002-07-17 16512]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-09-30 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-09-30 26824]
R1 FsVga;FsVga; C:\WINDOWS\system32\DRIVERS\fsvga.sys [2004-08-04 12160]
R1 InCDPass;InCDPass; C:\WINDOWS\System32\DRIVERS\InCDPass.sys [2005-06-10 29696]
R1 incdrm;InCD Reader; C:\WINDOWS\system32\drivers\incdrm.sys [2005-06-10 28160]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R2 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-09-30 76040]
R2 STEC3;STEC3; \??\C:\WINDOWS\system32\STEC3.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-01-24 4127488]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-08-21 2417664]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-01-29 16168]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
R3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R4 InCDfs;InCD File System; C:\WINDOWS\system32\drivers\InCDfs.sys [2005-06-10 99584]
S3 ASPI;Advanced SCSI Programming Interface Driver; \??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cusbohcn;cusbohcn; \??\C:\DOCUME~1\winxp\LOCALS~1\Temp\cusbohcn.sys []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-11-01 773565]
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MSICPL;MSICPL; \??\D:\install4\MSICPL.sys []
S3 npkcrypt;npkcrypt; \??\C:\Program Files\Gravity\RO\npkcrypt.sys []
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 Pcouffin;Low level access layer for CD devices; C:\WINDOWS\System32\Drivers\Pcouffin.sys []
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-03 74496]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-07-22 32000]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-07-22 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-08-21 487424]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-30 875288]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-30 231704]
R2 InCDsrv;InCD Helper; C:\Program Files\Ahead\InCD\InCDsrv.exe [2005-06-10 869888]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-01-05 66872]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-07-30 532264]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2007-08-21 593920]
S2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]

—————–EOF—————–




info.txt logfile of random's system information tool 1.04 2008-10-19 19:27:12

======Uninstall list======

–>C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
AC-3 ACM Codec–>C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\AC3ACM.inf
Adobe Download Manager 2.0 (Remove Only)–>"C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.8–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
Adobe Reader Korean Fonts–>MsiExec.exe /I{AC76BA86-7AD7-5670-0000-7E8A45000001}
Adobe Shockwave Player–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Advanced WMA Workshop version 2.2–>"C:\Program Files\LitexMedia\Advanced WMA Workshop\unins000.exe"
AIM 6–>C:\Program Files\AIM6\uninst.exe
AOL Uninstaller (Choose which Products to Remove)–>C:\Program Files\Common Files\AOL\uninstaller.exe
Apple Mobile Device Support–>MsiExec.exe /I{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ATI - Software Uninstall Utility–>C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AVG Free 8.0–>C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
AviSynth 2.5–>"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Battlefield 2™–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}\setup.exe" -l0x9 -removeonly
BitComet 0.84–>C:\Program Files\BitComet\uninst.exe
Bonjour–>MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Create-Ringtone 4.7–>"C:\Program Files\Create-Ringtone\unins000.exe"
DivX ;-) Audio Compressor 4.02–>C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_DivX 132 C:\WINDOWS\INF\DivXAudioCompressor4.02.inf
DivX Converter–>C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
DivX Player–>C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DVD Solution–>"C:\Program Files\Uninstall_CDS.exe"
EPSON CardMonitor–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{109D28C7-FB38-483A-9C91-001CB59E2699}\Setup.exe" -l0x9 uninst
EPSON PhotoStarter3.0–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5983C895-DDA4-45D9-A8D1-877D5DE7693E}\Setup.exe" uninst
EPSON Print CD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}\Setup.exe" -l0x9 -SYSTEM
EPSON Printer Software–>C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON SPR300 Reference Guide–>C:\Program Files\epson\guide\spr300_e\uninstall.exe
ERUNT 1.1j–>"C:\Program Files\ERUNT\unins000.exe"
FileSpecs plug-in for Ad-Aware SE–>C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\FILESP~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\FILESP~1\INSTALL.LOG
Gunbound Revolution–>"c:\ijji\ENGLISH\Gunbound Revolution\unins000.exe"
HangulPhonics–>MsiExec.exe /I{FBCEC735-9079-46B1-97AB-22B9B219AE24}
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
ijji Auto Installer–>"C:\Program Files\InstallShield Installation Information\{1DCC7418-2089-4BDD-B321-3771956160FC}\setup.exe" -runfromtemp -l0x0009 -removeonly
InCD–>C:\WINDOWS\NuNInst.exe /UNINSTALL
Intel® Graphics Media Accelerator Driver–>RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV;_2782 PCI\VEN_8086&DEV;_2582
iriver plus 2 (remove only)–>"C:\Program Files\iriver\iriver plus 2\uninstall.exe"
iTunes–>MsiExec.exe /I{3DE0053C-FD9A-483E-B7C9-B06E4392206E}
J2SE Runtime Environment 5.0 Update 10–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 3–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}
J2SE Runtime Environment 5.0 Update 6–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
K-Lite Mega Codec Pack 1.53–>"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Korean Language Support–>RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\ko.inf, Uninstall
LimeWire PRO 4.10.7–>"C:\Program Files\LimeWire\uninstall.exe"
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Standard Edition 2003–>MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSN–>C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
Multimedia Launcher–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
Nero OEM–>C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Plaxo Toolbar for Outlook and Outlook Express–>C:\Program Files\Plaxo\2.13.1.6\uninstall.exe
QuickTime–>MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
Ragnarok Online–>"C:\WINDOWS\IFinst27.exe" -UC:\Program Files\Gravity\RO\IFU10.inf
ReadPhonics–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\VisionWork\ReadPhonics\Uninst.isu"
ReadPhonics–>MsiExec.exe /I{BE944291-CEEE-4788-8795-AF1DCCFED89B}
Realtek AC'97 Audio–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x9 -removeonly
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB911565)–>"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950759)–>"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)–>"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)–>"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956390)–>"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Steam–>C:\PROGRA~1\Steam\UNWISE.EXE C:\PROGRA~1\Steam\INSTALL.LOG
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Ventrilo Client–>MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
VeohTV BETA–>C:\Program Files\InstallShield Installation Information\{D1B11537-EA51-4DD8-BF1E-098BEE48868D}\setup.exe -runfromtemp -l0x0409
VideoLAN VLC media player 0.8.6d–>C:\Program Files\VideoLAN\VLC\uninstall.exe
Videora iPod classic Converter 3.07–>C:\Program Files\Red Kawa\Video Converter 3\uninstaller.exe
Viewpoint Media Player–>C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Winamp (remove only)–>"C:\Program Files\Winamp\UninstWA.exe"
Windows Genuine Advantage v1.3.0254.0–>MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
Windows Live Messenger–>MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Safety Alert–>C:\Documents and Settings\winxp\Local Settings\temp\xrg2.exe /del
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe
Xvid 1.1.3 final uninstall–>"I:\Xvid\unins000.exe"

======Security center information======

AV: AVG Anti-Virus Free

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\K-Lite Codec Pack\QuickTime\QTSystem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 3, GenuineIntel
"PROCESSOR_REVISION"=0403
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip

—————–EOF—————–
No, you didn't do this step properly, can you re-do it

Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {030A0F33-5B99-482E-83F5-2EEB8457878B} [HKLM] -> %SystemRoot%\system32\675873\675873.dll [675873 Class]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{144A6B24-0EBC-4D89-BF09-A06A718E57B5}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{867AB302-E62F-4e8e-B297-6444A9C81D09}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{9034A523-D068-4BE8-A284-9DF278BE776E}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List
YN -> "C:\Program Files\AIM\aim.exe" -> C:\Program Files\AIM\aim.exe [C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YY -> "C:\WINDOWS\system32\BugsSvr.exe" -> C:\WINDOWS\system32\BugsSvr.exe [C:\WINDOWS\system32\BugsSvr.exe:*:Enabled:Bugs Music Player Control]
YY -> "C:\WINDOWS\system32\cjmvsvr.exe" -> C:\WINDOWS\system32\cjmvsvr.exe [C:\WINDOWS\system32\cjmvsvr.exe:*:Enabled:CJMUSIC VoD Control]
YY -> "C:\WINDOWS\system32\p3bvsvr.exe" -> C:\WINDOWS\system32\p3bvsvr.exe [C:\WINDOWS\system32\p3bvsvr.exe:*:Enabled:Bugs Music VoD Control]
YY -> "C:\WINDOWS\system32\P3MxSvr.exe" -> C:\WINDOWS\system32\P3MxSvr.exe [C:\WINDOWS\system32\P3MxSvr.exe:*:Enabled:Maxmp3 AoD Control]
YY -> "C:\WINDOWS\system32\p3mxvsvr.exe" -> C:\WINDOWS\system32\p3mxvsvr.exe [C:\WINDOWS\system32\p3mxvsvr.exe:*:Enabled:MAXMP3 VOD Control]
YY -> "C:\WINDOWS\system32\skcbgm.exe" -> C:\WINDOWS\system32\skcbgm.exe [C:\WINDOWS\system32\skcbgm.exe:*:Enabled:SK Communications Cyworld BGM Player]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> \I\Shell\AutoRun\command\\"" -> I:\LaunchU3.exe [I:\LaunchU3.exe -a]
[Registry - Additional Scans - Safe List]
< Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\
YN -> HotKeysCmds hkey= key= ->
YN -> IgfxTray hkey= key= ->
YN -> InCD hkey= key= ->
YN -> NeroFilterCheck hkey= key= ->
YN -> QuickTime Task hkey= key= ->
YN -> SoundMan hkey= key= ->
YN -> updateMgr hkey= key= ->
YN -> VirRL2009 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\VirRL2009\VirRL2009.exe
[Files/Folders - Created Within 90 Days]
NY -> 1 C:\*.tmp files -> C:\*.tmp
NY -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> tmp.reg -> %SystemRoot%\System32\tmp.reg
NY -> VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe
NY -> SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe
NY -> swreg.exe -> %SystemRoot%\System32\swreg.exe
NY -> AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe
NY -> VACFix.exe -> %SystemRoot%\System32\VACFix.exe
NY -> o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe
NY -> IEDFix.exe -> %SystemRoot%\System32\IEDFix.exe
NY -> IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe
NY -> 404Fix.exe -> %SystemRoot%\System32\404Fix.exe
NY -> swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe
NY -> Process.exe -> %SystemRoot%\System32\Process.exe
NY -> dumphive.exe -> %SystemRoot%\System32\dumphive.exe
NY -> swsc.exe -> %SystemRoot%\System32\swsc.exe
NY -> WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe
NY -> SmitfraudFix -> %UserProfile%\Desktop\SmitfraudFix
NY -> SmitfraudFix.exe -> %UserProfile%\Desktop\SmitfraudFix.exe
NY -> tmp3.reg -> %SystemDrive%\tmp3.reg
NY -> 675873 -> %SystemRoot%\System32\675873
NY -> ComboFix -> %SystemDrive%\ComboFix
NY -> udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll
[Files/Folders - Modified Within 90 Days]
NY -> udhkejos.dll -> %SystemRoot%\System32\udhkejos.dll
NY -> mgxoschk.ini -> %SystemRoot%\mgxoschk.ini
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.
oohh, my bad Explorer killed successfully [Registry - Safe List] Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{030A0F33-5B99-482E-83F5-2EEB8457878B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{030A0F33-5B99-482E-83F5-2EEB8457878B}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{144A6B24-0EBC-4D89-BF09-A06A718E57B5} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{144A6B24-0EBC-4D89-BF09-A06A718E57B5}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{867AB302-E62F-4e8e-B297-6444A9C81D09} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{867AB302-E62F-4e8e-B297-6444A9C81D09}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{9034A523-D068-4BE8-A284-9DF278BE776E} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9034A523-D068-4BE8-A284-9DF278BE776E}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\AIM\aim.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\BugsSvr.exe deleted successfully. C:\WINDOWS\system32\BugsSvr.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\cjmvsvr.exe deleted successfully. C:\WINDOWS\system32\cjmvsvr.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\p3bvsvr.exe deleted successfully. C:\WINDOWS\system32\p3bvsvr.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\P3MxSvr.exe deleted successfully. C:\WINDOWS\system32\P3MxSvr.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\p3mxvsvr.exe deleted successfully. C:\WINDOWS\system32\p3mxvsvr.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\skcbgm.exe deleted successfully. C:\WINDOWS\system32\skcbgm.exe moved successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\Shell\AutoRun\command\\ deleted successfully. [Registry - Additional Scans - Safe List] Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HotKeysCmds hkey= key=\ not found. File not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IgfxTray hkey= key=\ not found. File not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\InCD hkey= key=\ not found. File not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NeroFilterCheck hkey= key=\ not found. File not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task hkey= key=\ not found. File not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SoundMan hkey= key=\ not found. File not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\updateMgr hkey= key=\ not found. File not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\VirRL2009 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ not found. File not found. [Files/Folders - Created Within 90 Days] C:\WINDOWS\msdownld.tmp folder deleted successfully. C:\WINDOWS\System32\tmp.reg moved successfully. C:\WINDOWS\System32\VCCLSID.exe moved successfully. C:\WINDOWS\System32\SrchSTS.exe moved successfully. C:\WINDOWS\System32\swreg.exe moved successfully. C:\WINDOWS\System32\AntiXPVSTFix.exe moved successfully. C:\WINDOWS\System32\VACFix.exe moved successfully. C:\WINDOWS\System32\o4Patch.exe moved successfully. C:\WINDOWS\System32\IEDFix.exe moved successfully. C:\WINDOWS\System32\IEDFix.C.exe moved successfully. C:\WINDOWS\System32\404Fix.exe moved successfully. C:\WINDOWS\System32\swxcacls.exe moved successfully. C:\WINDOWS\System32\Process.exe moved successfully. C:\WINDOWS\System32\dumphive.exe moved successfully. C:\WINDOWS\System32\swsc.exe moved successfully. C:\WINDOWS\System32\WS2Fix.exe moved successfully. C:\Documents and Settings\winxp\Desktop\SmitfraudFix folder moved successfully. C:\Documents and Settings\winxp\Desktop\SmitfraudFix.exe moved successfully. C:\tmp3.reg moved successfully. C:\WINDOWS\System32\675873 folder moved successfully. C:\ComboFix folder moved successfully. File C:\WINDOWS\System32\udhkejos.dll not found! [Files/Folders - Modified Within 90 Days] File C:\WINDOWS\System32\udhkejos.dll not found! C:\WINDOWS\mgxoschk.ini moved successfully. [Empty Temp Folders] User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. RecycleBin -> emptied. Explorer started successfully < End of fix log > OTScanIt2 by OldTimer - Version 1.0.0.17b fix logfile created on 10202008_205225 Files moved on Reboot… File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI