Hi Sam,
I had tried moving the "ATL71R" files with OTMoveIt2 before and didn't have any success.
It didn't work this time either...
LoadLibrary failed for c:\windows\system32\atl71r.dll
c:\windows\system32\atl71r.dll NOT unregistered.
File move failed. c:\windows\system32\atl71r.dll scheduled to be moved on reboot.
File move failed. c:\windows\system32\atl71r.dll.bak scheduled to be moved on reboot.
C:\jfidoj.exe moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 05162008_083429
Files moved on Reboot...
LoadLibrary failed for c:\windows\system32\atl71r.dll
c:\windows\system32\atl71r.dll NOT unregistered.
File move failed. c:\windows\system32\atl71r.dll scheduled to be moved on reboot.
File move failed. c:\windows\system32\atl71r.dll.bak scheduled to be moved on reboot.
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-05-16 08:39:55
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:40:06 AM, on 16/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Brownie\BrstsWnd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Brownie\brpjp04a.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Administrator.MICROSOF-2E3494\Desktop\dss.exe
C:\PROGRA~1\HIJACK~2\ADMINI~1.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\GhostSurf Platinum\SCActiveBlock.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: (no name) - {9A1A6186-8170-40FE-B21C-EA663E718749} - c:\windows\system32\atl71r.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: xuuqckbl - C:\WINDOWS\SYSTEM32\atl71r.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
--
End of file - 7129 bytes
-- Files created between 2008-04-16 and 2008-05-16 -----------------------------
2008-05-12 11:56:46 0 d-------- C:\Program Files\Panda Security
2008-05-12 10:51:42 0 --a------ C:\WINDOWS\system32\CMMGR32.EXE
2008-05-12 10:43:46 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-05-12 10:43:25 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-11 10:31:59 2078752 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-11 10:28:39 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\MailFrontier
2008-05-11 10:28:26 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-05-11 10:28:09 11264 --a------ C:\WINDOWS\system32\SpOrder.dll <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
2008-05-11 10:18:07 0 d-------- C:\WINDOWS\system32\ZoneLabs
2008-05-10 20:33:13 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage
2008-05-10 10:17:10 0 d-------- C:\Documents and Settings\Administrator.MICROSOF-2E3494\Application Data\Hide IP NG
2008-05-10 10:17:09 0 d-------- C:\Program Files\Hide IP NG
2008-05-08 18:06:15 0 d-------- C:\Documents and Settings\Administrator.MICROSOF-2E3494\Application Data\Malwarebytes
2008-05-08 18:06:09 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-08 18:06:09 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-05-08 18:05:50 0 d-------- C:\Program Files\Common Files\Download Manager
2008-05-08 17:42:31 0 d-------- C:\VundoFix Backups
2008-05-06 08:33:36 0 d-------- C:\Program Files\Rootkit Revealer
2008-05-05 14:25:26 68096 --a------ C:\WINDOWS\zip.exe
2008-05-05 14:25:26 49152 --a------ C:\WINDOWS\VFind.exe
2008-05-05 14:25:26 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-05-05 14:25:26 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-05-05 14:25:26 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-05-05 14:25:26 98816 --a------ C:\WINDOWS\sed.exe
2008-05-05 14:25:26 80412 --a------ C:\WINDOWS\grep.exe
2008-05-05 14:25:26 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-05-05 14:24:55 0 d-------- C:\Program Files\Combofix
2008-05-05 14:00:27 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Zenturi
2008-05-05 10:05:44 0 d--h----- C:\$AVG8.VAULT$
2008-05-05 09:15:25 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-05 09:15:20 0 d-------- C:\Program Files\AVG
2008-05-05 09:15:20 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2008-05-04 13:35:30 0 d-------- C:\WINDOWS\system32\BACKUP
2008-04-17 09:42:01 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
-- Find3M Report ---------------------------------------------------------------
2008-05-15 21:46:17 0 d-------- C:\Documents and Settings\Administrator.MICROSOF-2E3494\Application Data\uTorrent
2008-05-12 21:40:59 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-12 12:24:26 0 d-------- C:\Program Files\Common Files\Real
2008-05-12 12:23:41 0 d-------- C:\Documents and Settings\Administrator.MICROSOF-2E3494\Application Data\Real
2008-05-10 10:31:57 0 d-------- C:\Documents and Settings\Administrator.MICROSOF-2E3494\Application Data\Adobe
2008-05-08 18:05:50 0 d-------- C:\Program Files\Common Files
2008-05-08 17:21:51 0 d-------- C:\Program Files\Hijack This
2008-05-08 17:13:08 0 d-------- C:\Program Files\Java
2008-05-05 21:36:46 0 d-------- C:\Program Files\Ad-Aware 2007
2008-04-23 16:18:55 43264 --a------ C:\WINDOWS\system32\kdhesjwz.dat
2008-04-21 17:22:59 0 d-------- C:\Program Files\ProxyShell Hide IP
2008-04-18 17:13:29 0 d-------- C:\Documents and Settings\Administrator.MICROSOF-2E3494\Application Data\LimeWire
2008-04-14 07:29:13 6490880 --a------ C:\WINDOWS\system32\btmamkpv.dat
2008-04-13 02:23:34 35584 --a------ C:\WINDOWS\system32\rpjwrzpj.dat
2008-04-13 02:23:34 36608 --a------ C:\WINDOWS\system32\fyrlkcpz.dat
2008-04-07 19:33:14 0 d-------- C:\Program Files\iTunes
2008-04-07 19:33:06 0 d-------- C:\Program Files\iPod
2008-04-07 19:31:59 0 d-------- C:\Program Files\QuickTime
2008-04-03 20:29:37 0 d-------- C:\Program Files\Common Files\Mozilla Shared
2008-04-02 20:24:12 638208 --a------ C:\WINDOWS\system32\vcrfqvro.dat
2008-03-27 13:28:40 0 d-------- C:\Documents and Settings\Administrator.MICROSOF-2E3494\Application Data\Macromedia
2008-03-25 12:51:03 0 d-------- C:\Documents and Settings\Administrator.MICROSOF-2E3494\Application Data\EndNote
2008-03-17 16:54:53 246545 --a------ C:\WINDOWS\system32\libssl32.dll <Not Verified; OpenSSL <www.openssl.org>; OpenSSL>
2008-03-17 16:54:53 1188375 --a------ C:\WINDOWS\system32\libeay32.dll <Not Verified; OpenSSL <www.openssl.org>; OpenSSL>
2008-03-17 07:01:37 3522 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-16 16:59:01 0 d-------- C:\Program Files\Brownie
2008-03-15 17:16:49 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-14 09:09:32 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-03 20:30:06 34 --a------ C:\WINDOWS\system32\BD2170W.DAT
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A1A6186-8170-40FE-B21C-EA663E718749}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [10/08/2004 08:44 PM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [10/08/2004 08:44 PM]
"SoundMan"="SOUNDMAN.EXE" [01/12/2004 05:54 PM C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [04/10/2007 05:14 PM]
"nwiz"="nwiz.exe" [04/10/2007 05:14 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [04/10/2007 05:14 PM]
"BrStsWnd"="C:\Program Files\Brownie\BrstsWnd.exe" [31/07/2007 08:37 PM]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [05/05/2008 09:15 AM]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [02/04/2008 09:07 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [10/08/2004 08:44 PM]
"Window Washer"="C:\Program Files\Webroot\Washer\wwDisp.exe" [26/11/2007 02:47 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"=0 (0x0)
"SynchronousUserGroupPolicy"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRemoteRecursiveEvents"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=1 (0x1)
"NoLowDiskSpaceChecks"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xuuqckbl]
atl71r.dll 10/08/2004 08:44 PM 82432 C:\WINDOWS\system32\atl71r.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator.MICROSOF-2E3494^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Administrator.MICROSOF-2E3494\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Codec Update Service]
C:\Program Files\Essentials Codec Pack\update.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDUiP6210DMon]
C:\Program Files\Canon\Memory Card Utility\iP6210D\PDUiP6210DMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
lkfpazli
-- End of Deckard's System Scanner: finished at 2008-05-16 08:41:07 ------------