hi again~
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003d
Kernel Drivers (total 166):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EE000 \WINDOWS\system32\hal.dll
0xF7987000 \WINDOWS\system32\KDCOM.DLL
0xF7897000 \WINDOWS\system32\BOOTVID.dll
0xF75A8000 ACPI.sys
0xF7989000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF7597000 pci.sys
0xF75F7000 isapnp.sys
0xF7A4F000 pciide.sys
0xF7707000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF798B000 aliide.sys
0xF798D000 cmdide.sys
0xF798F000 toside.sys
0xF7991000 viaide.sys
0xF7993000 intelide.sys
0xF7607000 MountMgr.sys
0xF74D8000 ftdisk.sys
0xF7995000 dmload.sys
0xF74B2000 dmio.sys
0xF770F000 PartMgr.sys
0xF7617000 VolSnap.sys
0xF789B000 cpqarray.sys
0xF749A000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF7482000 atapi.sys
0xF789F000 aha154x.sys
0xF7717000 sparrow.sys
0xF78A3000 symc810.sys
0xF7627000 aic78xx.sys
0xF78A7000 dac960nt.sys
0xF7637000 ql10wnt.sys
0xF78AB000 amsint.sys
0xF771F000 asc.sys
0xF78AF000 asc3550.sys
0xF7727000 mraid35x.sys
0xF772F000 i2omp.sys
0xF78B3000 ini910u.sys
0xF7647000 ql1240.sys
0xF7657000 aic78u2.sys
0xF7737000 symc8xx.sys
0xF773F000 sym_hi.sys
0xF7747000 sym_u3.sys
0xF774F000 ABP480N5.SYS
0xF7757000 asc3350p.sys
0xF7997000 cd20xrnt.sys
0xF7667000 ultra.sys
0xF786E000 adpu160m.sys
0xF775F000 dpti2o.sys
0xF7677000 ql1080.sys
0xF7687000 ql1280.sys
0xF7697000 ql12160.sys
0xF7767000 perc2.sys
0xF7999000 perc2hib.sys
0xF776F000 hpn.sys
0xF78B7000 cbidf2k.sys
0xF7842000 dac2w2k.sys
0xF76A7000 disk.sys
0xF76B7000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7967000 fltmgr.sys
0xF7830000 sr.sys
0xF76C7000 PxHelp20.sys
0xF7950000 KSecDD.sys
0xF7B52000 Ntfs.sys
0xF7A22000 NDIS.sys
0xF76D7000 Combo-Fix.sys
0xF76E7000 sisagp.sys
0xF76F7000 viaagp.sys
0xBA7E6000 Mup.sys
0xF7587000 agp440.sys
0xF7577000 alim1541.sys
0xF7567000 amdagp.sys
0xF7557000 agpCPQ.sys
0xB91A9000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB90E4000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
0xB90D0000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB90A2000 \SystemRoot\system32\DRIVERS\b57xp32.sys
0xF77DF000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB907E000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF77E7000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB8FE8000 \SystemRoot\system32\drivers\smwdm.sys
0xB8FC4000 \SystemRoot\system32\drivers\portcls.sys
0xB9199000 \SystemRoot\system32\drivers\drmk.sys
0xB8FA1000 \SystemRoot\system32\drivers\ks.sys
0xF79C9000 \SystemRoot\system32\drivers\aeaudio.sys
0xF77EF000 \SystemRoot\system32\DRIVERS\fdc.sys
0xB8F8D000 \SystemRoot\system32\DRIVERS\parport.sys
0xBA7D6000 \SystemRoot\system32\DRIVERS\serial.sys
0xBA6A9000 \SystemRoot\system32\DRIVERS\serenum.sys
0xBA7C6000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA7B6000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xBA7A6000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF77F7000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xF7AAC000 \SystemRoot\system32\DRIVERS\audstub.sys
0xBA796000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xBA6A5000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB8F76000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xBA786000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA776000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF77FF000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB8F65000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA766000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7807000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF780F000 \SystemRoot\system32\DRIVERS\raspti.sys
0xB8F35000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xBA756000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7817000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF781F000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF79CB000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB8ED7000 \SystemRoot\system32\DRIVERS\update.sys
0xF793F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xBA695000 \SystemRoot\system32\DRIVERS\omci.sys
0xA4E72000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA4E52000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF79B5000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x9F60A000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x9F8C6000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0x9DDAD000 \SystemRoot\system32\DRIVERS\WG11TND5.sys
0x9DD8A000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0xF7A09000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x9E6B7000 \SystemRoot\System32\Drivers\Null.SYS
0xF799B000 \SystemRoot\System32\Drivers\Beep.SYS
0x9F5F2000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x9F5EA000 \SystemRoot\System32\drivers\vga.sys
0xF79A5000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xB9DB2000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x9EF01000 \SystemRoot\System32\Drivers\Msfs.SYS
0x9EEF9000 \SystemRoot\System32\Drivers\Npfs.SYS
0x9F8BA000 \SystemRoot\system32\DRIVERS\rasacd.sys
0x9DD57000 \SystemRoot\system32\DRIVERS\ipsec.sys
0x9DCFE000 \SystemRoot\system32\DRIVERS\tcpip.sys
0x9DCD6000 \SystemRoot\system32\DRIVERS\netbt.sys
0x9F8B2000 \SystemRoot\System32\drivers\ws2ifsl.sys
0x9DCB4000 \SystemRoot\System32\drivers\afd.sys
0x9F6C8000 \SystemRoot\system32\DRIVERS\netbios.sys
0x9DC89000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x9DC19000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9EB73000 \SystemRoot\System32\Drivers\Fips.SYS
0x9DBF3000 \SystemRoot\system32\DRIVERS\ipnat.sys
0x9EB63000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x9EEF1000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x9E98D000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x9EB23000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x9E985000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x9E97D000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x9EB13000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0x9DE2C000 \SystemRoot\System32\drivers\Dxapi.sys
0x9EEE1000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xB9346000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF020000 \SystemRoot\System32\ialmdnt5.dll
0xBF012000 \SystemRoot\System32\ialmrnt5.dll
0xBF03E000 \SystemRoot\System32\ialmdev5.DLL
0xBF064000 \SystemRoot\System32\ialmdd5.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xA09BD000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9DAFE000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0x9DAC1000 \SystemRoot\system32\drivers\wdmaud.sys
0xA854D000 \SystemRoot\system32\drivers\sysaudio.sys
0x9E589000 \??\C:\WINDOWS\system32\Drivers\BASFND.sys
0x9D8AC000 \SystemRoot\system32\DRIVERS\srv.sys
0x9D573000 \SystemRoot\System32\Drivers\HTTP.sys
0xBA64D000 \??\C:\DOCUME~1\kelsey\LOCALS~1\Temp\mbr.sys
0xF77B7000 \??\C:\ComboFix\catchme.sys
0xF79F1000 \??\C:\WINDOWS\system32\Drivers\PROCEXP113.SYS
0x9D070000 \SystemRoot\System32\Drivers\Fastfat.SYS
0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll
Processes (total 33):
0 System Idle Process
4 System
548 C:\WINDOWS\SYSTEM32\smss.exe
780 csrss.exe
804 C:\WINDOWS\SYSTEM32\winlogon.exe
852 C:\WINDOWS\SYSTEM32\services.exe
864 C:\WINDOWS\SYSTEM32\lsass.exe
1048 C:\WINDOWS\SYSTEM32\svchost.exe
1112 svchost.exe
1152 C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
1192 C:\WINDOWS\SYSTEM32\svchost.exe
1256 svchost.exe
1360 svchost.exe
1856 C:\WINDOWS\SYSTEM32\spoolsv.exe
1952 svchost.exe
204 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
224 C:\WINDOWS\SYSTEM32\BAsfIpM.exe
244 C:\Program Files\Bonjour\mDNSResponder.exe
408 C:\Program Files\Dell\OpenManage\Client\Iap.exe
616 C:\Program Files\Java\jre6\bin\jqs.exe
708 C:\WINDOWS\SYSTEM32\svchost.exe
2288 alg.exe
3732 C:\WINDOWS\SYSTEM32\hkcmd.exe
3740 C:\Program Files\Microsoft Security Essentials\msseces.exe
3808 C:\Program Files\iTunes\iTunesHelper.exe
3904 C:\Documents and Settings\kelsey\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe
1732 C:\Program Files\iPod\bin\iPodService.exe
3004 wmiprvse.exe
3000 C:\WINDOWS\explorer.exe
2508 C:\WINDOWS\SYSTEM32\ctfmon.exe
1312 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
3828 C:\Documents and Settings\kelsey\Desktop\MBRCheck.exe
3032 MpCmdRun.exe
\\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`03ec1000 (NTFS)
\\.\F: --> \\.\PhysicalDrive2 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive1 Model Number: WDCWD800JD-75JNA0, Rev: 05.01C05
PhysicalDrive2 Model Number: WDCWD5000AACS-00ZUB0, Rev: 01.01B01
Size Device Name MBR Status
--------------------------------------------
74 GB \\.\PhysicalDrive1 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
465 GB \\.\PhysicalDrive2 Legit MBR code detected
SHA1: 317A49A9E93F077F2D004734D2A7B6CA7E7B9495
Done!
OTL logfile created on: 8/7/2010 12:39:56 am - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\kelsey\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.43 Gb Total Space | 29.36 Gb Free Space | 39.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 268.75 Gb Free Space | 57.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D2ZLV571
Current User Name: kelsey
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/08/07 00:36:17 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kelsey\Desktop\OTL.exe
PRC - [2010/06/26 15:21:33 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Documents and Settings\kelsey\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe
PRC - [2010/06/10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/06/01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2010/03/25 21:40:42 | 000,203,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
PRC - [2009/08/17 15:16:34 | 002,356,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
PRC - [2008/04/14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/04/01 17:05:48 | 000,077,824 | ---- | M] (Broadcom Corp.) -- C:\WINDOWS\SYSTEM32\BAsfIpM.exe
PRC - [2004/02/13 09:47:02 | 000,155,648 | ---- | M] (Dell Inc) -- C:\Program Files\Dell\OpenManage\Client\Iap.exe
========== Modules (SafeList) ========== MOD - [2010/08/07 00:36:17 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kelsey\Desktop\OTL.exe
MOD - [2008/04/14 06:40:22 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - [2010/06/10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2007/08/09 18:44:28 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2004/04/01 17:05:48 | 000,077,824 | ---- | M] (Broadcom Corp.) [Auto | Running] -- C:\WINDOWS\SYSTEM32\BAsfIpM.exe -- (BAsfIpM)
SRV - [2004/02/13 09:47:02 | 000,155,648 | ---- | M] (Dell Inc) [Auto | Running] -- C:\Program Files\Dell\OpenManage\Client\Iap.exe -- (Iap)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2010/03/25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\MpFilter.sys -- (MpFilter)
DRV - [2008/04/14 01:06:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/14 01:06:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2007/06/14 11:29:15 | 000,682,232 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\sptd.sys -- (sptd)
DRV - [2005/09/05 10:21:06 | 000,362,944 | ---- | M] (NETGEAR, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\WG11TND5.sys -- (AR5523)
DRV - [2004/08/03 21:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys -- (nv)
DRV - [2004/05/29 16:41:54 | 000,186,112 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\b57xp32.sys -- (b57w2k)
DRV - [2004/02/13 09:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2003/04/24 15:21:50 | 000,006,025 | ---- | M] (Broadcom Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\BASFND.sys -- (BASFND)
DRV - [2001/08/17 15:05:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ovcd.sys -- (QCDonner)
DRV - [2001/08/17 13:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 13:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 13:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 13:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 13:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 12:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 12:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 12:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 12:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 12:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 12:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 12:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 12:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 12:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 12:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/09 00:45:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/09 00:46:26 | 000,000,000 | ---D | M]
[2008/12/05 10:57:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Extensions
[2010/08/06 18:37:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\Default User\extensions
[2009/09/13 18:00:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\Default User\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/05/16 11:19:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\Default User\extensions\moveplayer@movenetworks.com
[2007/04/22 03:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\default.3dj\extensions
[2007/04/22 03:20:55 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\default.3dj\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2007/04/22 03:20:55 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\default.3dj\extensions\{641d8d09-7dda-4850-8228-ac0ab65e2ac9}
[2007/04/22 03:20:55 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\default.3dj\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/08/06 18:37:26 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/08/06 07:37:40 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe (America Online, Inc.)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: clubbox.co.kr ([]https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (Reg Error: Key error.)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134}
http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0}
http://upload.facebook.com/controls/Facebo...toUploader3.cab (Reg Error: Key error.)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC}
http://upload.facebook.com/controls/Facebo...otoUploader.cab (Reg Error: Key error.)
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E}
http://app.ipop.co.kr/gom/GomWeb.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539}
http://www.crucial.com/controls/cpcScanner.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\kelsey\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\kelsey\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 16:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/08/07 00:36:14 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\kelsey\Desktop\OTL.exe
[2010/08/06 07:22:20 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/08/06 07:22:20 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/08/06 07:22:20 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/08/06 07:22:20 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/08/04 01:29:45 | 000,000,000 | ---D | C] -- C:\rsit
[2010/07/26 22:07:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\jvytntoud
[2010/07/26 22:07:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/07/26 22:06:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/07/22 00:35:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/22 00:35:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/18 19:52:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/18 19:52:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/18 19:07:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/18 19:05:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/18 18:41:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kelsey\Local Settings\Application Data\ciomulhju
[2010/07/14 07:37:44 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/08/07 00:36:25 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\5150.doc
[2010/08/07 00:36:17 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kelsey\Desktop\OTL.exe
[2010/08/07 00:35:40 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\MBRCheck.exe
[2010/08/07 00:26:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3536787594-2409408838-4148652776-1006UA.job
[2010/08/06 17:41:23 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/06 17:36:58 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/08/06 17:25:44 | 003,816,456 | R--- | M] () -- C:\Documents and Settings\kelsey\Desktop\ComboFix.exe
[2010/08/06 15:26:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3536787594-2409408838-4148652776-1006Core.job
[2010/08/06 07:37:40 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2010/08/06 07:37:03 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2010/08/06 07:36:52 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2010/08/06 07:36:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2010/08/06 07:36:44 | 2674,012,160 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/06 07:35:46 | 011,272,192 | -H-- | M] () -- C:\Documents and Settings\kelsey\NTUSER.DAT
[2010/08/06 07:35:46 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\kelsey\NTUSER.INI
[2010/08/04 17:32:53 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\kelsey\Desktop\~$Hello.doc
[2010/08/04 01:22:14 | 000,037,376 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\Hello.doc
[2010/08/04 01:18:13 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\dds (1).scr
[2010/08/04 01:16:51 | 000,133,632 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\RKUnhookerLE (1).EXE
[2010/08/04 01:16:38 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\4vy92qh8.exe
[2010/08/04 01:16:25 | 000,339,991 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\RSIT.exe
[2010/08/04 01:16:14 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\Defogger (1).exe
[2010/07/30 13:59:05 | 000,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/30 13:52:48 | 000,033,147 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\phuket.jpg
[2010/07/28 18:23:18 | 000,074,662 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\gradschool2.jpg
[2010/07/28 18:20:32 | 000,077,687 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\gradschool.jpg
[2010/07/28 18:18:11 | 000,058,887 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\bananaclub.jpg
[2010/07/26 22:13:41 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\rkill.com
[2010/07/26 19:39:16 | 000,028,547 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\n.jpg
[2010/07/26 01:45:24 | 000,099,790 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\n19900757_32203985_8081.jpg
[2010/07/25 14:35:27 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/07/25 10:33:33 | 000,133,632 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\RKUnhookerLE.EXE
[2010/07/25 10:33:20 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\dds.scr
[2010/07/25 09:41:08 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Kqatezivanomo.dat
[2010/07/25 09:41:07 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Nlufako.bin
[2010/07/24 00:31:46 | 000,235,993 | ---- | M] () -- C:\Documents and Settings\kelsey\My Documents\560_0_resize.jpg
[2010/07/23 07:27:43 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\kelsey\My Documents\~$eeping Computer Malware Removal.doc
[2010/07/22 23:03:38 | 000,931,840 | ---- | M] () -- C:\Documents and Settings\kelsey\My Documents\Bleeping Computer Malware Removal.doc
[2010/07/22 18:19:52 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\kelsey\defogger_reenable
[2010/07/22 00:28:09 | 000,225,792 | ---- | M] () -- C:\Documents and Settings\kelsey\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/18 18:41:39 | 000,000,150 | ---- | M] () -- C:\zrpt.xml
[2010/07/10 09:53:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/08/07 00:35:39 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\MBRCheck.exe
[2010/08/06 22:00:01 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\5150.doc
[2010/08/06 07:22:20 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/08/06 07:22:20 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/08/06 07:22:20 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/08/06 07:22:20 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/08/06 07:22:20 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/08/06 07:21:20 | 003,816,456 | R--- | C] () -- C:\Documents and Settings\kelsey\Desktop\ComboFix.exe
[2010/08/04 17:32:53 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\kelsey\Desktop\~$Hello.doc
[2010/08/04 01:22:14 | 000,037,376 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\Hello.doc
[2010/08/04 01:18:09 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\dds (1).scr
[2010/08/04 01:16:50 | 000,133,632 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\RKUnhookerLE (1).EXE
[2010/08/04 01:16:37 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\4vy92qh8.exe
[2010/08/04 01:16:23 | 000,339,991 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\RSIT.exe
[2010/08/04 01:16:13 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\Defogger (1).exe
[2010/07/30 13:59:05 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/30 13:52:48 | 000,033,147 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\phuket.jpg
[2010/07/28 18:23:18 | 000,074,662 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\gradschool2.jpg
[2010/07/28 18:20:31 | 000,077,687 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\gradschool.jpg
[2010/07/28 18:18:11 | 000,058,887 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\bananaclub.jpg
[2010/07/26 22:13:36 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\rkill.com
[2010/07/26 19:39:16 | 000,028,547 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\n.jpg
[2010/07/26 01:44:45 | 000,099,790 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\n19900757_32203985_8081.jpg
[2010/07/25 10:33:33 | 000,133,632 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\RKUnhookerLE.EXE
[2010/07/24 00:31:46 | 000,235,993 | ---- | C] () -- C:\Documents and Settings\kelsey\My Documents\560_0_resize.jpg
[2010/07/23 07:27:43 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\kelsey\My Documents\~$eeping Computer Malware Removal.doc
[2010/07/22 23:03:38 | 000,931,840 | ---- | C] () -- C:\Documents and Settings\kelsey\My Documents\Bleeping Computer Malware Removal.doc
[2010/07/22 18:20:30 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\dds.scr
[2010/07/22 18:19:52 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\kelsey\defogger_reenable
[2010/07/18 19:56:07 | 2674,012,160 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/18 18:41:36 | 000,000,150 | ---- | C] () -- C:\zrpt.xml
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2008/06/18 18:59:37 | 000,000,027 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2008/05/16 09:01:14 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/04/03 21:23:10 | 002,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2008/03/19 19:45:07 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2007/10/15 17:13:10 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\bassmod.dll
[2007/08/02 23:56:52 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/08/02 22:28:04 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/05/17 13:58:10 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\libexpatw.dll
[2007/04/22 18:28:17 | 000,000,084 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2007/04/22 17:55:15 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\nod.dll
[2007/04/22 17:52:53 | 000,000,066 | ---- | C] () -- C:\WINDOWS\System32\fscflist.ini
[2007/04/22 17:52:51 | 000,000,079 | ---- | C] () -- C:\WINDOWS\System32\fscagent.ini
[2007/04/21 19:41:06 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\EAL32.INI
[2006/05/02 13:49:38 | 000,000,385 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/04/26 13:34:47 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll
[2005/03/29 22:40:22 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/03/29 22:17:46 | 000,000,367 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/11 16:25:56 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/04 04:00:00 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== Custom Scans ========== < tsvcs > < %SYSTEMDRIVE%\*.* >[2004/06/28 00:42:46 | 000,051,941 | ---- | M] () -- C:\19146.gif
[2004/03/02 02:30:58 | 000,008,202 | ---- | M] () -- C:\19146.jpg
[2003/03/24 23:10:18 | 000,012,437 | ---- | M] () -- C:\3-10photo1.jpg
[2004/07/25 01:50:04 | 000,029,797 | ---- | M] () -- C:\328503.gif
[2004/10/24 03:04:16 | 000,007,817 | ---- | M] () -- C:\a335.gif
[2010/04/11 20:36:06 | 000,000,035 | ---- | M] () -- C:\aa.txt
[2010/03/11 16:57:16 | 000,000,068 | -H-- | M] () -- C:\aaw7boot.cmd
[2010/03/11 16:44:56 | 000,000,668 | ---- | M] () -- C:\aaw7boot.log
[2004/10/12 21:45:12 | 002,636,408 | ---- | M] () -- C:\aawsepersonal.exe
[2009/12/09 01:41:56 | 077,086,488 | ---- | M] (Lavasoft ) -- C:\Ad-AwareInstallation.exe
[2005/04/05 00:47:04 | 020,798,256 | ---- | M] (Netopsystems AG ) -- C:\AdbeRdr70_enu_full.exe
[2007/05/22 10:41:53 | 021,822,168 | ---- | M] ( ) -- C:\AdbeRdr80_en_US.exe
[2005/04/10 22:38:30 | 001,374,689 | ---- | M] (XemiComputers Ltd. ) -- C:\adcsr.exe
[2003/08/08 10:33:44 | 000,203,061 | ---- | M] () -- C:\AIM+Setup.exe
[2005/04/05 02:42:24 | 001,897,860 | ---- | M] (ESTsoft Corp. ) -- C:\alzip.exe
[2007/06/25 00:11:53 | 000,089,379 | ---- | M] () -- C:\angel131.jpg
[2003/09/02 01:05:22 | 000,021,705 | ---- | M] () -- C:\Animation1.gif
[2003/09/02 01:07:14 | 000,013,584 | ---- | M] () -- C:\Animation2.gif
[2003/12/08 21:07:56 | 000,343,207 | ---- | M] () -- C:\AppleWin_1.10.zip
[2007/05/22 12:46:35 | 000,033,792 | ---- | M] () -- C:\ARPEDepartmentalApplication.xls
[2004/08/11 16:15:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2004/12/11 18:33:34 | 000,002,422 | ---- | M] () -- C:\bbc.ico
[2003/11/24 01:29:20 | 000,041,404 | ---- | M] () -- C:\billy-vector.jpg
[2003/01/15 09:25:10 | 000,863,494 | ---- | M] (Stardust Software) -- C:\blumaroobounce.exe
[2006/01/18 13:24:28 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/03/11 14:57:19 | 000,000,281 | RHS- | M] () -- C:\BOOT.INI
[2007/10/12 23:57:10 | 015,739,448 | ---- | M] () -- C:\CakeManiaSetup.exe
[2005/11/17 22:04:34 | 000,011,031 | ---- | M] () -- C:\candy bar doll me!!.gif
[2003/08/13 02:00:08 | 000,177,578 | ---- | M] () -- C:\cheat1.bmp
[2003/09/11 00:48:32 | 000,046,815 | ---- | M] () -- C:\cheygayman.jpg
[2005/11/13 20:57:22 | 000,853,672 | ---- | M] () -- C:\chinatown 004.jpg
[2006/04/30 22:05:12 | 000,132,882 | ---- | M] () -- C:\CIMG0008.JPG
[2006/04/30 22:03:56 | 000,128,192 | ---- | M] () -- C:\CIMG0012.JPG
[2006/04/08 02:22:58 | 000,956,890 | ---- | M] () -- C:\CIMG0102.JPG
[2004/08/04 00:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2010/08/06 17:41:24 | 000,010,987 | ---- | M] () -- C:\ComboFix.txt
[2004/08/11 16:15:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2005/03/29 22:18:02 | 000,003,756 | RH-- | M] () -- C:\DELL.SDR
[2003/04/28 23:09:28 | 000,044,345 | ---- | M] () -- C:\desk.JPG
[2003/05/21 00:03:44 | 000,069,954 | ---- | M] () -- C:\desk2.JPG
[2003/05/25 01:07:20 | 000,084,298 | ---- | M] () -- C:\deskcap3.JPG
[2002/07/06 02:05:14 | 003,286,795 | ---- | M] () -- C:\DivX502Bundle.exe
[2006/10/15 01:27:12 | 024,265,736 | ---- | M] (Microsoft) -- C:\dotnetfx.exe
[2006/12/30 14:22:54 | 000,363,800 | ---- | M] (Digital River, Inc.) -- C:\download-flvplayer_setup.exe.exe
[2004/03/07 01:43:44 | 000,662,307 | ---- | M] () -- C:\DSC00244-1.JPG
[2004/03/07 01:42:32 | 000,724,615 | ---- | M] () -- C:\DSC00249-1.JPG
[2006/01/29 21:21:02 | 000,783,909 | ---- | M] () -- C:\DSCF0635.JPG
[2004/07/31 17:21:36 | 000,102,487 | ---- | M] () -- C:\DTR.JPG
[2004/08/27 03:27:18 | 003,038,672 | ---- | M] () -- C:\Dynomite Deluxe 2.71.exe
[2005/09/18 00:26:06 | 000,020,473 | ---- | M] () -- C:\earrang.jpg
[2003/01/01 19:45:04 | 002,266,608 | ---- | M] () -- C:\ec22.exe
[2007/09/05 22:19:04 | 006,820,864 | ---- | M] () -- C:\epson11262.exe
[2007/09/13 11:38:16 | 007,848,448 | ---- | M] () -- C:\epson11375.exe
[2007/09/13 11:26:28 | 007,005,184 | ---- | M] () -- C:\epson11505.exe
[2007/04/29 23:42:34 | 003,224,463 | ---- | M] () -- C:\fgf173.exe
[2004/08/10 23:27:24 | 005,082,708 | ---- | M] (Mozilla) -- C:\FirefoxSetup-0.9.3.exe
[2002/10/11 14:45:28 | 000,013,071 | ---- | M] () -- C:\fwnfe.zip
[2003/06/29 11:42:10 | 000,119,602 | ---- | M] () -- C:\gm121d.zip
[2005/09/03 13:36:36 | 000,336,821 | ---- | M] () -- C:\gn 001.jpg
[2010/08/06 07:36:44 | 2674,012,160 | -HS- | M] () -- C:\hiberfil.sys
[2008/05/04 10:30:30 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\HJTInstall.exe
[2004/03/07 15:47:08 | 000,139,478 | ---- | M] () -- C:\ibrentskateboard.jpg
[2003/06/26 23:06:00 | 000,025,997 | ---- | M] () -- C:\iconsxp.zip
[2007/11/25 01:47:23 | 000,191,572 | ---- | M] () -- C:\iconsxp2.zip
[2007/11/25 01:46:58 | 000,025,997 | ---- | M] () -- C:\iconsxp3.zip
[2002/08/02 23:02:26 | 002,032,792 | ---- | M] (Microsoft Corporation) -- C:\ie_ko.exe
[2003/09/25 11:08:58 | 000,063,496 | ---- | M] () -- C:\index.1
[2004/08/11 16:27:32 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2007/04/28 17:54:45 | 008,506,408 | ---- | M] () -- C:\Install_AIM59.exe
[2006/11/20 00:27:28 | 001,410,680 | ---- | M] () -- C:\install_flash_player.exe
[2004/08/11 16:15:00 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2010/03/29 00:38:48 | 000,000,722 | -H-- | M] () -- C:\IPH.PH
[2005/11/28 05:10:06 | 056,298,664 | ---- | M] (Apple Computer, Inc. ) -- C:\iPodSetup.exe
[2004/03/07 15:48:34 | 000,130,437 | ---- | M] () -- C:\isangwall.jpg
[2006/03/21 23:45:34 | 001,321,140 | ---- | M] () -- C:\iScrobblerWin_1_1_0.exe
[2008/05/08 08:01:28 | 059,782,440 | ---- | M] (Apple Inc.) -- C:\iTunesSetup.exe
[2002/12/22 20:33:38 | 000,827,392 | ---- | M] () -- C:\iview375.exe
[2005/09/21 23:17:14 | 000,336,896 | ---- | M] () -- C:\keljudjes.jpg
[2003/11/05 22:45:32 | 003,366,186 | ---- | M] () -- C:\klitekpp243e.exe
[2007/09/22 00:02:03 | 004,217,146 | ---- | M] (Last.fm ) -- C:\Last.fm-1.3.2.13b.exe
[2003/12/27 11:50:10 | 001,760,378 | ---- | M] () -- C:\lavasoft ad-aware 6.0 build 181 (aaw6.exe).exe
[2003/03/30 15:45:54 | 000,032,955 | ---- | M] () -- C:\layout.JPG
[2003/06/21 23:55:28 | 000,393,216 | ---- | M] () -- C:\lemonade_tycoon.zip
[2006/09/18 18:08:58 | 000,359,112 | ---- | M] () -- C:\LimeWireWin.exe
[2009/03/25 23:15:16 | 002,813,421 | ---- | M] (ManiacTools.com ) -- C:\m4a-to-mp3-converter.exe
[2006/04/28 12:40:18 | 043,424,778 | ---- | M] () -- C:\making friends1.avi
[2003/04/08 19:11:36 | 000,003,644 | ---- | M] () -- C:\ma_de_item04b.gif
[2003/04/08 19:11:58 | 000,002,879 | ---- | M] () -- C:\ma_li_item04a_1.gif
[2009/12/09 01:41:45 | 004,844,296 | ---- | M] (Malwarebytes Corporation ) -- C:\mbam-setup.exe
[2003/08/17 13:41:16 | 000,092,166 | ---- | M] () -- C:\mfaq52hp.zip
[2003/08/17 13:40:18 | 001,216,000 | ---- | M] (mIRC Co. Ltd.) -- C:\mirc603.exe
[2004/10/16 00:23:54 | 012,653,296 | ---- | M] (Microsoft Corporation) -- C:\MP10Setup.exe
[2004/09/16 01:44:12 | 010,431,072 | ---- | M] (Microsoft Corporation) -- C:\mp71.exe
[2004/08/11 16:15:00 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2005/12/19 21:36:14 | 005,316,176 | ---- | M] (Microsoft Corporation) -- C:\msjavx86.exe
[2003/09/08 02:30:42 | 000,005,283 | ---- | M] () -- C:\msnemails.gif
[2004/11/17 03:35:14 | 001,035,943 | ---- | M] ( ) -- C:\myTunesReduxInstaller.exe
[2006/11/30 22:42:26 | 000,056,702 | ---- | M] () -- C:\n19900125_30251321_1358.jpg
[2007/10/17 17:12:20 | 001,305,088 | ---- | M] () -- C:\Netflix_Movie_Viewer_Installer.msi
[2004/08/04 04:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/03/12 12:42:32 | 000,250,048 | ---- | M] () -- C:\ntldr
[2007/07/06 20:48:15 | 001,088,976 | ---- | M] () -- C:\octosetup_v_l_odd.exe
[2005/04/19 00:43:04 | 000,394,451 | ---- | M] () -- C:\other_quotes.zip
[2004/01/01 01:00:00 | 000,850,622 | ---- | M] () -- C:\P1010309.JPG
[2006/02/05 14:25:58 | 000,893,121 | ---- | M] () -- C:\P1010310.JPG
[2006/02/05 14:27:02 | 000,527,928 | ---- | M] () -- C:\P1010311.JPG
[2004/01/01 01:00:00 | 000,830,522 | ---- | M] () -- C:\P1010312.JPG
[2006/04/02 12:36:04 | 000,468,299 | ---- | M] () -- C:\P1010517.JPG
[2010/08/06 07:36:43 | 792,723,456 | -HS- | M] () -- C:\pagefile.sys
[2003/04/06 17:27:52 | 031,354,419 | ---- | M] () -- C:\Paint Shop Pro 7 full.zip
[2004/10/04 23:52:50 | 001,028,385 | ---- | M] (Stardust Software) -- C:\petpetsitter.exe
[2004/12/29 12:06:34 | 000,070,367 | ---- | M] () -- C:\phpfanbase_v2.zip
[2002/08/04 16:50:28 | 001,650,357 | ---- | M] () -- C:\player304.exe
[2006/10/15 01:37:50 | 000,488,094 | ---- | M] ( ) -- C:\PlazerSetup.exe
[2004/09/05 15:30:40 | 000,481,251 | ---- | M] () -- C:\plvx2cleaner.exe
[2009/05/02 22:31:21 | 005,618,115 | ---- | M] () -- C:\Poladroid0.9.5r5-PC.zip
[2003/05/22 02:21:18 | 000,041,626 | ---- | M] () -- C:\ps-brian2.jpg
[2008/02/16 00:46:08 | 030,401,112 | ---- | M] (Logitech, Inc.) -- C:\qc1150.exe
[2008/02/16 00:39:05 | 033,344,864 | ---- | M] (Logitech, Inc.) -- C:\qc1150_x64.exe
[2007/04/25 21:57:26 | 019,994,184 | ---- | M] (Apple Computer, Inc.) -- C:\QuickTimeInstaller.exe
[2002/08/11 02:27:28 | 001,799,685 | ---- | M] () -- C:\QuickVCD.exe
[2003/09/13 13:33:40 | 000,099,269 | ---- | M] () -- C:\r89s.wav
[2010/03/11 15:32:24 | 000,002,851 | ---- | M] () -- C:\rapport.txt
[1996/10/09 03:21:18 | 000,000,780 | ---- | M] () -- C:\README.TXT
[2005/09/18 00:19:16 | 000,850,971 | ---- | M] () -- C:\rebels 004.jpg
[2005/09/18 00:26:50 | 000,035,898 | ---- | M] () -- C:\rebels 005.jpg
[2008/06/02 17:11:57 | 042,925,882 | ---- | M] () -- C:\rezcon-win.exe
[2004/03/17 14:15:30 | 000,002,485 | ---- | M] () -- C:\rickee.txt
[2003/05/12 23:14:38 | 000,286,294 | ---- | M] () -- C:\ringtone.wav
[2003/11/28 03:14:54 | 001,043,479 | ---- | M] () -- C:\RJSS95.EXE
[2010/07/26 22:26:56 | 000,000,371 | ---- | M] () -- C:\rkill.log
[1996/10/09 01:23:28 | 002,071,235 | ---- | M] () -- C:\ROMEO95.EXE
[2005/09/17 12:52:22 | 000,788,318 | ---- | M] () -- C:\roomiesdos 001.jpg
[2005/09/17 12:52:24 | 000,828,861 | ---- | M] () -- C:\roomiesdos 002.jpg
[2003/10/12 23:22:52 | 000,041,125 | ---- | M] () -- C:\runmenu.jpg
[2004/03/07 15:30:12 | 000,249,520 | ---- | M] () -- C:\sangwall.jpg
[2004/03/07 15:31:12 | 000,257,853 | ---- | M] () -- C:\sangwall2.jpg
[2007/11/25 01:52:03 | 000,399,703 | ---- | M] () -- C:\sb_quotes.zip
[2004/02/09 12:35:16 | 000,962,597 | ---- | M] () -- C:\scanogram.jpg
[2001/03/14 11:21:18 | 000,002,238 | ---- | M] () -- C:\ShinHwaicon.ico
[2008/02/16 00:55:50 | 006,997,792 | ---- | M] (SightSpeed Inc.) -- C:\SightSpeedSetup.exe
[2009/09/08 19:52:51 | 004,938,616 | ---- | M] (Microsoft Corporation) -- C:\Silverlight.exe
[2005/10/29 01:14:26 | 000,038,289 | ---- | M] () -- C:\SimpleViewer_v17.zip
[2008/06/18 18:58:01 | 000,039,409 | ---- | M] () -- C:\ski32.zip
[2002/07/15 01:43:44 | 000,230,975 | ---- | M] () -- C:\skinner120.zip
[2004/11/07 23:05:04 | 000,786,333 | ---- | M] () -- C:\slsk154test.exe
[2005/04/11 00:03:50 | 000,107,792 | ---- | M] (Microsoft Corporation) -- C:\sndrec32.exe
[2004/05/14 08:27:30 | 004,354,084 | ---- | M] (Safer Networking Limited ) -- C:\spybot 1.3 05.12.04 (spybotsd13.exe).exe
[2007/10/08 23:42:20 | 007,467,056 | ---- | M] (Safer Networking Ltd. ) -- C:\spybotsd15.exe
[2004/09/05 15:07:22 | 002,247,855 | ---- | M] (Javacool Software LLC ) -- C:\spywareblastersetup.exe
[2005/10/31 08:56:02 | 000,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe
[2004/09/09 00:51:46 | 000,065,503 | ---- | M] () -- C:\surf-flier-small.jpg
[2007/11/25 01:50:12 | 001,544,848 | ---- | M] () -- C:\sys_sounds.zip
[2003/07/22 04:25:10 | 000,387,985 | ---- | M] (Macromedia, Inc.) -- C:\take-a-break.exe
[2003/01/15 09:16:22 | 000,900,243 | ---- | M] (Stardust Software) -- C:\techodance.exe
[2007/11/25 01:54:05 | 000,844,636 | ---- | M] () -- C:\The Cheat Theme Song.zip
[2007/11/25 01:56:02 | 000,688,534 | ---- | M] () -- C:\The System is Down.zip
[2007/11/25 01:54:44 | 000,859,743 | ---- | M] () -- C:\Trogdor.zip
[2004/02/06 01:25:58 | 000,000,079 | ---- | M] () -- C:\twacker.log
[2003/08/14 05:17:16 | 000,000,062 | ---- | M] () -- C:\Untitled-1 copy.gif
[2003/05/29 22:53:42 | 000,005,361 | ---- | M] () -- C:\Untitled-2 copy.jpg
[2003/08/28 22:37:00 | 000,046,263 | ---- | M] () -- C:\untitled.GIF
[2003/06/13 03:06:02 | 000,067,429 | ---- | M] () -- C:\untitled.JPG
[2003/08/16 19:49:44 | 000,108,251 | ---- | M] () -- C:\untitled2.JPG
[2003/08/16 19:57:10 | 000,046,338 | ---- | M] () -- C:\untitled3.JPG
[2003/08/17 01:45:04 | 000,022,754 | ---- | M] () -- C:\untitled4.JPG
[2004/12/11 19:18:06 | 000,001,189 | ---- | M] () -- C:\VETlog.txt
[2006/12/30 14:00:46 | 000,014,738 | ---- | M] () -- C:\videodownloader-1.1.1-fx.xpi
[2007/05/27 14:05:24 | 009,516,033 | ---- | M] () -- C:\vlc-0.8.6b-win32.exe
[2004/08/11 08:58:14 | 000,000,014 | ---- | M] () -- C:\win2.log
[2004/08/10 22:20:56 | 005,703,377 | ---- | M] (Intel Corporation) -- C:\win2k_xp141.exe
[2007/04/22 18:28:13 | 006,718,976 | ---- | M] (Nullsoft, Inc.) -- C:\winamp533_full_emusic-7plus.exe
[2004/08/11 09:07:16 | 002,710,296 | ---- | M] (Microsoft Corporation) -- C:\WindowsXP-KB835732-x86-ENU.EXE
[2006/03/21 23:04:26 | 000,000,621 | ---- | M] () -- C:\WS_FTP.LOG
[2007/08/04 17:04:43 | 000,682,063 | ---- | M] () -- C:\ws_ftp45.exe
[2002/07/13 22:18:16 | 000,707,072 | ---- | M] () -- C:\ws_ftple.exe
[2004/10/02 11:46:46 | 003,905,464 | ---- | M] (Microsoft Corporation) -- C:\xlViewer.exe
[2003/07/17 11:32:16 | 000,142,993 | ---- | M] () -- C:\XviD-Dec-300303.exe
[2005/11/17 21:18:20 | 006,805,758 | ---- | M] () -- C:\yahoo_dynomite_tm1-1.exe
[2003/01/08 05:00:50 | 001,256,972 | ---- | M] () -- C:\ZipWizard20.exe
[2010/07/18 18:41:39 | 000,000,150 | ---- | M] () -- C:\zrpt.xml
[2004/08/24 20:50:04 | 006,113,752 | ---- | M] () -- C:\ZumaSetup.exe
[2007/08/11 07:33:56 | 000,000,221 | ---- | M] () -- C:\_audioscrobbler.log
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav >[2004/08/11 16:06:14 | 000,094,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2004/08/11 16:06:14 | 000,659,456 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2004/08/11 16:06:14 | 000,876,544 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< %systemroot%\system32\drivers\*.sys /90 > ========== Files - Unicode (All) ==========[2008/03/12 02:53:30 | 000,070,656 | ---- | M] ()(C:\Documents and Settings\kelsey\My Documents\?????.doc) -- C:\Documents and Settings\kelsey\My Documents\사랑인가요.doc
[2008/03/12 02:40:40 | 000,070,656 | ---- | C] ()(C:\Documents and Settings\kelsey\My Documents\?????.doc) -- C:\Documents and Settings\kelsey\My Documents\사랑인가요.doc
========== Alternate Data Streams ========== @Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CE2C623F
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5E1F4E0B
< End of report >
wasn't sure if you wanted extras too so in case, here it is
OTL Extras logfile created on: 8/7/2010 12:39:56 am - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\kelsey\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.43 Gb Total Space | 29.36 Gb Free Space | 39.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 268.75 Gb Free Space | 57.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D2ZLV571
Current User Name: kelsey
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\AIM95\aim.exe" = C:\Program Files\AIM95\aim.exe:*:Enabled:AOL Instant Messenger -- (America Online, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\SYSTEM32\grdmgr.exe" = C:\WINDOWS\SYSTEM32\grdmgr.exe:*:Enabled:CDN ???? ?? -- (나우콤)
"C:\Program Files\AIM95\aim.exe" = C:\Program Files\AIM95\aim.exe:*:Enabled:AOL Instant Messenger -- (America Online, Inc.)
"C:\WINDOWS\SYSTEM32\BugsSvr.exe" = C:\WINDOWS\SYSTEM32\BugsSvr.exe:*:Enabled:Bugs Music Player Control -- ()
"C:\Program Files\AIM7\aim.exe" = C:\Program Files\AIM7\aim.exe:*:Enabled:AIM -- (AOL Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series" = Canon iP2600 series
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{25D24E84-64A9-40D2-85CF-540B1C4A6D52}" = Broadcom ASF Management Applications
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java 6 Update 18
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2A539CD9-0F75-4875-9A32-E06DD93C4114}" = Adobe Extension Manager CS3
"{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A12C952-61D5-4C3B-B68B-8CFBE47E22F1}" = Adobe Setup
"{45ACEB0A-5B7F-22C5-39F8-0D2CA0918A27}" = MyFonts Order M1124785
"{48EE6C79-1CE2-4CE8-B511-F2140B6781D6}" = Google Earth Pro
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{73F1BDB7-11E1-11D5-9DC6-00C04F2FC33B}" = OMCI
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_WebDesigner_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_WebDesigner_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_WebDesigner_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0026-0000-0000-0000000FF1CE}" = Microsoft Expression Web
"{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{9037FDA8-8383-4B6F-859D-D49C3C625225}" = Microsoft Expression Web Service Pack 1 (SP1)
"{90120000-0026-0409-0000-0000000FF1CE}" = Microsoft Expression Web MUI (English)
"{90120000-0026-0409-0000-0000000FF1CE}_WebDesigner_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_WebDesigner_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_WebDesigner_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90BC0F01-9D99-4686-AC14-2EEC0246FB84}" = Poladroid
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9811A185-3D3D-11D6-9E14-00036D172B00}" = Adobe MPEG Encoder
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.
hi again~
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003d
Kernel Drivers (total 166):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EE000 \WINDOWS\system32\hal.dll
0xF7987000 \WINDOWS\system32\KDCOM.DLL
0xF7897000 \WINDOWS\system32\BOOTVID.dll
0xF75A8000 ACPI.sys
0xF7989000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF7597000 pci.sys
0xF75F7000 isapnp.sys
0xF7A4F000 pciide.sys
0xF7707000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF798B000 aliide.sys
0xF798D000 cmdide.sys
0xF798F000 toside.sys
0xF7991000 viaide.sys
0xF7993000 intelide.sys
0xF7607000 MountMgr.sys
0xF74D8000 ftdisk.sys
0xF7995000 dmload.sys
0xF74B2000 dmio.sys
0xF770F000 PartMgr.sys
0xF7617000 VolSnap.sys
0xF789B000 cpqarray.sys
0xF749A000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF7482000 atapi.sys
0xF789F000 aha154x.sys
0xF7717000 sparrow.sys
0xF78A3000 symc810.sys
0xF7627000 aic78xx.sys
0xF78A7000 dac960nt.sys
0xF7637000 ql10wnt.sys
0xF78AB000 amsint.sys
0xF771F000 asc.sys
0xF78AF000 asc3550.sys
0xF7727000 mraid35x.sys
0xF772F000 i2omp.sys
0xF78B3000 ini910u.sys
0xF7647000 ql1240.sys
0xF7657000 aic78u2.sys
0xF7737000 symc8xx.sys
0xF773F000 sym_hi.sys
0xF7747000 sym_u3.sys
0xF774F000 ABP480N5.SYS
0xF7757000 asc3350p.sys
0xF7997000 cd20xrnt.sys
0xF7667000 ultra.sys
0xF786E000 adpu160m.sys
0xF775F000 dpti2o.sys
0xF7677000 ql1080.sys
0xF7687000 ql1280.sys
0xF7697000 ql12160.sys
0xF7767000 perc2.sys
0xF7999000 perc2hib.sys
0xF776F000 hpn.sys
0xF78B7000 cbidf2k.sys
0xF7842000 dac2w2k.sys
0xF76A7000 disk.sys
0xF76B7000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7967000 fltmgr.sys
0xF7830000 sr.sys
0xF76C7000 PxHelp20.sys
0xF7950000 KSecDD.sys
0xF7B52000 Ntfs.sys
0xF7A22000 NDIS.sys
0xF76D7000 Combo-Fix.sys
0xF76E7000 sisagp.sys
0xF76F7000 viaagp.sys
0xBA7E6000 Mup.sys
0xF7587000 agp440.sys
0xF7577000 alim1541.sys
0xF7567000 amdagp.sys
0xF7557000 agpCPQ.sys
0xB91A9000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB90E4000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
0xB90D0000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB90A2000 \SystemRoot\system32\DRIVERS\b57xp32.sys
0xF77DF000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB907E000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF77E7000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB8FE8000 \SystemRoot\system32\drivers\smwdm.sys
0xB8FC4000 \SystemRoot\system32\drivers\portcls.sys
0xB9199000 \SystemRoot\system32\drivers\drmk.sys
0xB8FA1000 \SystemRoot\system32\drivers\ks.sys
0xF79C9000 \SystemRoot\system32\drivers\aeaudio.sys
0xF77EF000 \SystemRoot\system32\DRIVERS\fdc.sys
0xB8F8D000 \SystemRoot\system32\DRIVERS\parport.sys
0xBA7D6000 \SystemRoot\system32\DRIVERS\serial.sys
0xBA6A9000 \SystemRoot\system32\DRIVERS\serenum.sys
0xBA7C6000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA7B6000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xBA7A6000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF77F7000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xF7AAC000 \SystemRoot\system32\DRIVERS\audstub.sys
0xBA796000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xBA6A5000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB8F76000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xBA786000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA776000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF77FF000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB8F65000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA766000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7807000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF780F000 \SystemRoot\system32\DRIVERS\raspti.sys
0xB8F35000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xBA756000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7817000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF781F000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF79CB000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB8ED7000 \SystemRoot\system32\DRIVERS\update.sys
0xF793F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xBA695000 \SystemRoot\system32\DRIVERS\omci.sys
0xA4E72000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA4E52000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF79B5000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x9F60A000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x9F8C6000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0x9DDAD000 \SystemRoot\system32\DRIVERS\WG11TND5.sys
0x9DD8A000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0xF7A09000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x9E6B7000 \SystemRoot\System32\Drivers\Null.SYS
0xF799B000 \SystemRoot\System32\Drivers\Beep.SYS
0x9F5F2000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x9F5EA000 \SystemRoot\System32\drivers\vga.sys
0xF79A5000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xB9DB2000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x9EF01000 \SystemRoot\System32\Drivers\Msfs.SYS
0x9EEF9000 \SystemRoot\System32\Drivers\Npfs.SYS
0x9F8BA000 \SystemRoot\system32\DRIVERS\rasacd.sys
0x9DD57000 \SystemRoot\system32\DRIVERS\ipsec.sys
0x9DCFE000 \SystemRoot\system32\DRIVERS\tcpip.sys
0x9DCD6000 \SystemRoot\system32\DRIVERS\netbt.sys
0x9F8B2000 \SystemRoot\System32\drivers\ws2ifsl.sys
0x9DCB4000 \SystemRoot\System32\drivers\afd.sys
0x9F6C8000 \SystemRoot\system32\DRIVERS\netbios.sys
0x9DC89000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x9DC19000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9EB73000 \SystemRoot\System32\Drivers\Fips.SYS
0x9DBF3000 \SystemRoot\system32\DRIVERS\ipnat.sys
0x9EB63000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x9EEF1000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x9E98D000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x9EB23000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x9E985000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x9E97D000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x9EB13000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0x9DE2C000 \SystemRoot\System32\drivers\Dxapi.sys
0x9EEE1000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xB9346000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF020000 \SystemRoot\System32\ialmdnt5.dll
0xBF012000 \SystemRoot\System32\ialmrnt5.dll
0xBF03E000 \SystemRoot\System32\ialmdev5.DLL
0xBF064000 \SystemRoot\System32\ialmdd5.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xA09BD000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9DAFE000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0x9DAC1000 \SystemRoot\system32\drivers\wdmaud.sys
0xA854D000 \SystemRoot\system32\drivers\sysaudio.sys
0x9E589000 \??\C:\WINDOWS\system32\Drivers\BASFND.sys
0x9D8AC000 \SystemRoot\system32\DRIVERS\srv.sys
0x9D573000 \SystemRoot\System32\Drivers\HTTP.sys
0xBA64D000 \??\C:\DOCUME~1\kelsey\LOCALS~1\Temp\mbr.sys
0xF77B7000 \??\C:\ComboFix\catchme.sys
0xF79F1000 \??\C:\WINDOWS\system32\Drivers\PROCEXP113.SYS
0x9D070000 \SystemRoot\System32\Drivers\Fastfat.SYS
0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll
Processes (total 33):
0 System Idle Process
4 System
548 C:\WINDOWS\SYSTEM32\smss.exe
780 csrss.exe
804 C:\WINDOWS\SYSTEM32\winlogon.exe
852 C:\WINDOWS\SYSTEM32\services.exe
864 C:\WINDOWS\SYSTEM32\lsass.exe
1048 C:\WINDOWS\SYSTEM32\svchost.exe
1112 svchost.exe
1152 C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
1192 C:\WINDOWS\SYSTEM32\svchost.exe
1256 svchost.exe
1360 svchost.exe
1856 C:\WINDOWS\SYSTEM32\spoolsv.exe
1952 svchost.exe
204 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
224 C:\WINDOWS\SYSTEM32\BAsfIpM.exe
244 C:\Program Files\Bonjour\mDNSResponder.exe
408 C:\Program Files\Dell\OpenManage\Client\Iap.exe
616 C:\Program Files\Java\jre6\bin\jqs.exe
708 C:\WINDOWS\SYSTEM32\svchost.exe
2288 alg.exe
3732 C:\WINDOWS\SYSTEM32\hkcmd.exe
3740 C:\Program Files\Microsoft Security Essentials\msseces.exe
3808 C:\Program Files\iTunes\iTunesHelper.exe
3904 C:\Documents and Settings\kelsey\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe
1732 C:\Program Files\iPod\bin\iPodService.exe
3004 wmiprvse.exe
3000 C:\WINDOWS\explorer.exe
2508 C:\WINDOWS\SYSTEM32\ctfmon.exe
1312 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
3828 C:\Documents and Settings\kelsey\Desktop\MBRCheck.exe
3032 MpCmdRun.exe
\\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`03ec1000 (NTFS)
\\.\F: --> \\.\PhysicalDrive2 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive1 Model Number: WDCWD800JD-75JNA0, Rev: 05.01C05
PhysicalDrive2 Model Number: WDCWD5000AACS-00ZUB0, Rev: 01.01B01
Size Device Name MBR Status
--------------------------------------------
74 GB \\.\PhysicalDrive1 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
465 GB \\.\PhysicalDrive2 Legit MBR code detected
SHA1: 317A49A9E93F077F2D004734D2A7B6CA7E7B9495
Done!
OTL logfile created on: 8/7/2010 12:39:56 am - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\kelsey\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.43 Gb Total Space | 29.36 Gb Free Space | 39.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 268.75 Gb Free Space | 57.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D2ZLV571
Current User Name: kelsey
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/08/07 00:36:17 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kelsey\Desktop\OTL.exe
PRC - [2010/06/26 15:21:33 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Documents and Settings\kelsey\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe
PRC - [2010/06/10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/06/01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2010/03/25 21:40:42 | 000,203,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
PRC - [2009/08/17 15:16:34 | 002,356,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
PRC - [2008/04/14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/04/01 17:05:48 | 000,077,824 | ---- | M] (Broadcom Corp.) -- C:\WINDOWS\SYSTEM32\BAsfIpM.exe
PRC - [2004/02/13 09:47:02 | 000,155,648 | ---- | M] (Dell Inc) -- C:\Program Files\Dell\OpenManage\Client\Iap.exe
========== Modules (SafeList) ========== MOD - [2010/08/07 00:36:17 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kelsey\Desktop\OTL.exe
MOD - [2008/04/14 06:40:22 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - [2010/06/10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2007/08/09 18:44:28 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2004/04/01 17:05:48 | 000,077,824 | ---- | M] (Broadcom Corp.) [Auto | Running] -- C:\WINDOWS\SYSTEM32\BAsfIpM.exe -- (BAsfIpM)
SRV - [2004/02/13 09:47:02 | 000,155,648 | ---- | M] (Dell Inc) [Auto | Running] -- C:\Program Files\Dell\OpenManage\Client\Iap.exe -- (Iap)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2010/03/25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\MpFilter.sys -- (MpFilter)
DRV - [2008/04/14 01:06:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/14 01:06:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2007/06/14 11:29:15 | 000,682,232 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\sptd.sys -- (sptd)
DRV - [2005/09/05 10:21:06 | 000,362,944 | ---- | M] (NETGEAR, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\WG11TND5.sys -- (AR5523)
DRV - [2004/08/03 21:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys -- (nv)
DRV - [2004/05/29 16:41:54 | 000,186,112 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\b57xp32.sys -- (b57w2k)
DRV - [2004/02/13 09:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2003/04/24 15:21:50 | 000,006,025 | ---- | M] (Broadcom Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\BASFND.sys -- (BASFND)
DRV - [2001/08/17 15:05:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ovcd.sys -- (QCDonner)
DRV - [2001/08/17 13:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 13:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 13:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 13:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 13:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 12:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 12:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 12:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 12:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 12:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 12:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 12:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 12:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 12:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 12:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/09 00:45:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/09 00:46:26 | 000,000,000 | ---D | M]
[2008/12/05 10:57:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Extensions
[2010/08/06 18:37:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\Default User\extensions
[2009/09/13 18:00:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\Default User\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/05/16 11:19:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\Default User\extensions\moveplayer@movenetworks.com
[2007/04/22 03:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\default.3dj\extensions
[2007/04/22 03:20:55 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\default.3dj\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2007/04/22 03:20:55 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\default.3dj\extensions\{641d8d09-7dda-4850-8228-ac0ab65e2ac9}
[2007/04/22 03:20:55 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents and Settings\kelsey\Application Data\Mozilla\Firefox\Profiles\default.3dj\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/08/06 18:37:26 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/08/06 07:37:40 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe (America Online, Inc.)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: clubbox.co.kr ([]https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (Reg Error: Key error.)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134}
http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0}
http://upload.facebook.com/controls/Facebo...toUploader3.cab (Reg Error: Key error.)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC}
http://upload.facebook.com/controls/Facebo...otoUploader.cab (Reg Error: Key error.)
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E}
http://app.ipop.co.kr/gom/GomWeb.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539}
http://www.crucial.com/controls/cpcScanner.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\kelsey\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\kelsey\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 16:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/08/07 00:36:14 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\kelsey\Desktop\OTL.exe
[2010/08/06 07:22:20 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/08/06 07:22:20 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/08/06 07:22:20 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/08/06 07:22:20 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/08/04 01:29:45 | 000,000,000 | ---D | C] -- C:\rsit
[2010/07/26 22:07:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\jvytntoud
[2010/07/26 22:07:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/07/26 22:06:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/07/22 00:35:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/22 00:35:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/18 19:52:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/18 19:52:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/18 19:07:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/18 19:05:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/18 18:41:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kelsey\Local Settings\Application Data\ciomulhju
[2010/07/14 07:37:44 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/08/07 00:36:25 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\5150.doc
[2010/08/07 00:36:17 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kelsey\Desktop\OTL.exe
[2010/08/07 00:35:40 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\MBRCheck.exe
[2010/08/07 00:26:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3536787594-2409408838-4148652776-1006UA.job
[2010/08/06 17:41:23 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/06 17:36:58 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/08/06 17:25:44 | 003,816,456 | R--- | M] () -- C:\Documents and Settings\kelsey\Desktop\ComboFix.exe
[2010/08/06 15:26:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3536787594-2409408838-4148652776-1006Core.job
[2010/08/06 07:37:40 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2010/08/06 07:37:03 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2010/08/06 07:36:52 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2010/08/06 07:36:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2010/08/06 07:36:44 | 2674,012,160 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/06 07:35:46 | 011,272,192 | -H-- | M] () -- C:\Documents and Settings\kelsey\NTUSER.DAT
[2010/08/06 07:35:46 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\kelsey\NTUSER.INI
[2010/08/04 17:32:53 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\kelsey\Desktop\~$Hello.doc
[2010/08/04 01:22:14 | 000,037,376 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\Hello.doc
[2010/08/04 01:18:13 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\dds (1).scr
[2010/08/04 01:16:51 | 000,133,632 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\RKUnhookerLE (1).EXE
[2010/08/04 01:16:38 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\4vy92qh8.exe
[2010/08/04 01:16:25 | 000,339,991 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\RSIT.exe
[2010/08/04 01:16:14 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\Defogger (1).exe
[2010/07/30 13:59:05 | 000,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/30 13:52:48 | 000,033,147 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\phuket.jpg
[2010/07/28 18:23:18 | 000,074,662 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\gradschool2.jpg
[2010/07/28 18:20:32 | 000,077,687 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\gradschool.jpg
[2010/07/28 18:18:11 | 000,058,887 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\bananaclub.jpg
[2010/07/26 22:13:41 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\rkill.com
[2010/07/26 19:39:16 | 000,028,547 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\n.jpg
[2010/07/26 01:45:24 | 000,099,790 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\n19900757_32203985_8081.jpg
[2010/07/25 14:35:27 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/07/25 10:33:33 | 000,133,632 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\RKUnhookerLE.EXE
[2010/07/25 10:33:20 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\kelsey\Desktop\dds.scr
[2010/07/25 09:41:08 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Kqatezivanomo.dat
[2010/07/25 09:41:07 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Nlufako.bin
[2010/07/24 00:31:46 | 000,235,993 | ---- | M] () -- C:\Documents and Settings\kelsey\My Documents\560_0_resize.jpg
[2010/07/23 07:27:43 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\kelsey\My Documents\~$eeping Computer Malware Removal.doc
[2010/07/22 23:03:38 | 000,931,840 | ---- | M] () -- C:\Documents and Settings\kelsey\My Documents\Bleeping Computer Malware Removal.doc
[2010/07/22 18:19:52 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\kelsey\defogger_reenable
[2010/07/22 00:28:09 | 000,225,792 | ---- | M] () -- C:\Documents and Settings\kelsey\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/18 18:41:39 | 000,000,150 | ---- | M] () -- C:\zrpt.xml
[2010/07/10 09:53:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/08/07 00:35:39 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\MBRCheck.exe
[2010/08/06 22:00:01 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\5150.doc
[2010/08/06 07:22:20 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/08/06 07:22:20 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/08/06 07:22:20 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/08/06 07:22:20 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/08/06 07:22:20 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/08/06 07:21:20 | 003,816,456 | R--- | C] () -- C:\Documents and Settings\kelsey\Desktop\ComboFix.exe
[2010/08/04 17:32:53 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\kelsey\Desktop\~$Hello.doc
[2010/08/04 01:22:14 | 000,037,376 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\Hello.doc
[2010/08/04 01:18:09 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\dds (1).scr
[2010/08/04 01:16:50 | 000,133,632 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\RKUnhookerLE (1).EXE
[2010/08/04 01:16:37 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\4vy92qh8.exe
[2010/08/04 01:16:23 | 000,339,991 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\RSIT.exe
[2010/08/04 01:16:13 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\Defogger (1).exe
[2010/07/30 13:59:05 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/30 13:52:48 | 000,033,147 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\phuket.jpg
[2010/07/28 18:23:18 | 000,074,662 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\gradschool2.jpg
[2010/07/28 18:20:31 | 000,077,687 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\gradschool.jpg
[2010/07/28 18:18:11 | 000,058,887 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\bananaclub.jpg
[2010/07/26 22:13:36 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\rkill.com
[2010/07/26 19:39:16 | 000,028,547 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\n.jpg
[2010/07/26 01:44:45 | 000,099,790 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\n19900757_32203985_8081.jpg
[2010/07/25 10:33:33 | 000,133,632 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\RKUnhookerLE.EXE
[2010/07/24 00:31:46 | 000,235,993 | ---- | C] () -- C:\Documents and Settings\kelsey\My Documents\560_0_resize.jpg
[2010/07/23 07:27:43 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\kelsey\My Documents\~$eeping Computer Malware Removal.doc
[2010/07/22 23:03:38 | 000,931,840 | ---- | C] () -- C:\Documents and Settings\kelsey\My Documents\Bleeping Computer Malware Removal.doc
[2010/07/22 18:20:30 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\kelsey\Desktop\dds.scr
[2010/07/22 18:19:52 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\kelsey\defogger_reenable
[2010/07/18 19:56:07 | 2674,012,160 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/18 18:41:36 | 000,000,150 | ---- | C] () -- C:\zrpt.xml
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2008/06/18 18:59:37 | 000,000,027 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2008/05/16 09:01:14 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/04/03 21:23:10 | 002,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2008/03/19 19:45:07 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2007/10/15 17:13:10 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\bassmod.dll
[2007/08/02 23:56:52 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/08/02 22:28:04 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/05/17 13:58:10 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\libexpatw.dll
[2007/04/22 18:28:17 | 000,000,084 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2007/04/22 17:55:15 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\nod.dll
[2007/04/22 17:52:53 | 000,000,066 | ---- | C] () -- C:\WINDOWS\System32\fscflist.ini
[2007/04/22 17:52:51 | 000,000,079 | ---- | C] () -- C:\WINDOWS\System32\fscagent.ini
[2007/04/21 19:41:06 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\EAL32.INI
[2006/05/02 13:49:38 | 000,000,385 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/04/26 13:34:47 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll
[2005/03/29 22:40:22 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/03/29 22:17:46 | 000,000,367 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/11 16:25:56 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/04 04:00:00 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== Custom Scans ========== < tsvcs > < %SYSTEMDRIVE%\*.* >[2004/06/28 00:42:46 | 000,051,941 | ---- | M] () -- C:\19146.gif
[2004/03/02 02:30:58 | 000,008,202 | ---- | M] () -- C:\19146.jpg
[2003/03/24 23:10:18 | 000,012,437 | ---- | M] () -- C:\3-10photo1.jpg
[2004/07/25 01:50:04 | 000,029,797 | ---- | M] () -- C:\328503.gif
[2004/10/24 03:04:16 | 000,007,817 | ---- | M] () -- C:\a335.gif
[2010/04/11 20:36:06 | 000,000,035 | ---- | M] () -- C:\aa.txt
[2010/03/11 16:57:16 | 000,000,068 | -H-- | M] () -- C:\aaw7boot.cmd
[2010/03/11 16:44:56 | 000,000,668 | ---- | M] () -- C:\aaw7boot.log
[2004/10/12 21:45:12 | 002,636,408 | ---- | M] () -- C:\aawsepersonal.exe
[2009/12/09 01:41:56 | 077,086,488 | ---- | M] (Lavasoft ) -- C:\Ad-AwareInstallation.exe
[2005/04/05 00:47:04 | 020,798,256 | ---- | M] (Netopsystems AG ) -- C:\AdbeRdr70_enu_full.exe
[2007/05/22 10:41:53 | 021,822,168 | ---- | M] ( ) -- C:\AdbeRdr80_en_US.exe
[2005/04/10 22:38:30 | 001,374,689 | ---- | M] (XemiComputers Ltd. ) -- C:\adcsr.exe
[2003/08/08 10:33:44 | 000,203,061 | ---- | M] () -- C:\AIM+Setup.exe
[2005/04/05 02:42:24 | 001,897,860 | ---- | M] (ESTsoft Corp. ) -- C:\alzip.exe
[2007/06/25 00:11:53 | 000,089,379 | ---- | M] () -- C:\angel131.jpg
[2003/09/02 01:05:22 | 000,021,705 | ---- | M] () -- C:\Animation1.gif
[2003/09/02 01:07:14 | 000,013,584 | ---- | M] () -- C:\Animation2.gif
[2003/12/08 21:07:56 | 000,343,207 | ---- | M] () -- C:\AppleWin_1.10.zip
[2007/05/22 12:46:35 | 000,033,792 | ---- | M] () -- C:\ARPEDepartmentalApplication.xls
[2004/08/11 16:15:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2004/12/11 18:33:34 | 000,002,422 | ---- | M] () -- C:\bbc.ico
[2003/11/24 01:29:20 | 000,041,404 | ---- | M] () -- C:\billy-vector.jpg
[2003/01/15 09:25:10 | 000,863,494 | ---- | M] (Stardust Software) -- C:\blumaroobounce.exe
[2006/01/18 13:24:28 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/03/11 14:57:19 | 000,000,281 | RHS- | M] () -- C:\BOOT.INI
[2007/10/12 23:57:10 | 015,739,448 | ---- | M] () -- C:\CakeManiaSetup.exe
[2005/11/17 22:04:34 | 000,011,031 | ---- | M] () -- C:\candy bar doll me!!.gif
[2003/08/13 02:00:08 | 000,177,578 | ---- | M] () -- C:\cheat1.bmp
[2003/09/11 00:48:32 | 000,046,815 | ---- | M] () -- C:\cheygayman.jpg
[2005/11/13 20:57:22 | 000,853,672 | ---- | M] () -- C:\chinatown 004.jpg
[2006/04/30 22:05:12 | 000,132,882 | ---- | M] () -- C:\CIMG0008.JPG
[2006/04/30 22:03:56 | 000,128,192 | ---- | M] () -- C:\CIMG0012.JPG
[2006/04/08 02:22:58 | 000,956,890 | ---- | M] () -- C:\CIMG0102.JPG
[2004/08/04 00:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2010/08/06 17:41:24 | 000,010,987 | ---- | M] () -- C:\ComboFix.txt
[2004/08/11 16:15:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2005/03/29 22:18:02 | 000,003,756 | RH-- | M] () -- C:\DELL.SDR
[2003/04/28 23:09:28 | 000,044,345 | ---- | M] () -- C:\desk.JPG
[2003/05/21 00:03:44 | 000,069,954 | ---- | M] () -- C:\desk2.JPG
[2003/05/25 01:07:20 | 000,084,298 | ---- | M] () -- C:\deskcap3.JPG
[2002/07/06 02:05:14 | 003,286,795 | ---- | M] () -- C:\DivX502Bundle.exe
[2006/10/15 01:27:12 | 024,265,736 | ---- | M] (Microsoft) -- C:\dotnetfx.exe
[2006/12/30 14:22:54 | 000,363,800 | ---- | M] (Digital River, Inc.) -- C:\download-flvplayer_setup.exe.exe
[2004/03/07 01:43:44 | 000,662,307 | ---- | M] () -- C:\DSC00244-1.JPG
[2004/03/07 01:42:32 | 000,724,615 | ---- | M] () -- C:\DSC00249-1.JPG
[2006/01/29 21:21:02 | 000,783,909 | ---- | M] () -- C:\DSCF0635.JPG
[2004/07/31 17:21:36 | 000,102,487 | ---- | M] () -- C:\DTR.JPG
[2004/08/27 03:27:18 | 003,038,672 | ---- | M] () -- C:\Dynomite Deluxe 2.71.exe
[2005/09/18 00:26:06 | 000,020,473 | ---- | M] () -- C:\earrang.jpg
[2003/01/01 19:45:04 | 002,266,608 | ---- | M] () -- C:\ec22.exe
[2007/09/05 22:19:04 | 006,820,864 | ---- | M] () -- C:\epson11262.exe
[2007/09/13 11:38:16 | 007,848,448 | ---- | M] () -- C:\epson11375.exe
[2007/09/13 11:26:28 | 007,005,184 | ---- | M] () -- C:\epson11505.exe
[2007/04/29 23:42:34 | 003,224,463 | ---- | M] () -- C:\fgf173.exe
[2004/08/10 23:27:24 | 005,082,708 | ---- | M] (Mozilla) -- C:\FirefoxSetup-0.9.3.exe
[2002/10/11 14:45:28 | 000,013,071 | ---- | M] () -- C:\fwnfe.zip
[2003/06/29 11:42:10 | 000,119,602 | ---- | M] () -- C:\gm121d.zip
[2005/09/03 13:36:36 | 000,336,821 | ---- | M] () -- C:\gn 001.jpg
[2010/08/06 07:36:44 | 2674,012,160 | -HS- | M] () -- C:\hiberfil.sys
[2008/05/04 10:30:30 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\HJTInstall.exe
[2004/03/07 15:47:08 | 000,139,478 | ---- | M] () -- C:\ibrentskateboard.jpg
[2003/06/26 23:06:00 | 000,025,997 | ---- | M] () -- C:\iconsxp.zip
[2007/11/25 01:47:23 | 000,191,572 | ---- | M] () -- C:\iconsxp2.zip
[2007/11/25 01:46:58 | 000,025,997 | ---- | M] () -- C:\iconsxp3.zip
[2002/08/02 23:02:26 | 002,032,792 | ---- | M] (Microsoft Corporation) -- C:\ie_ko.exe
[2003/09/25 11:08:58 | 000,063,496 | ---- | M] () -- C:\index.1
[2004/08/11 16:27:32 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2007/04/28 17:54:45 | 008,506,408 | ---- | M] () -- C:\Install_AIM59.exe
[2006/11/20 00:27:28 | 001,410,680 | ---- | M] () -- C:\install_flash_player.exe
[2004/08/11 16:15:00 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2010/03/29 00:38:48 | 000,000,722 | -H-- | M] () -- C:\IPH.PH
[2005/11/28 05:10:06 | 056,298,664 | ---- | M] (Apple Computer, Inc. ) -- C:\iPodSetup.exe
[2004/03/07 15:48:34 | 000,130,437 | ---- | M] () -- C:\isangwall.jpg
[2006/03/21 23:45:34 | 001,321,140 | ---- | M] () -- C:\iScrobblerWin_1_1_0.exe
[2008/05/08 08:01:28 | 059,782,440 | ---- | M] (Apple Inc.) -- C:\iTunesSetup.exe
[2002/12/22 20:33:38 | 000,827,392 | ---- | M] () -- C:\iview375.exe
[2005/09/21 23:17:14 | 000,336,896 | ---- | M] () -- C:\keljudjes.jpg
[2003/11/05 22:45:32 | 003,366,186 | ---- | M] () -- C:\klitekpp243e.exe
[2007/09/22 00:02:03 | 004,217,146 | ---- | M] (Last.fm ) -- C:\Last.fm-1.3.2.13b.exe
[2003/12/27 11:50:10 | 001,760,378 | ---- | M] () -- C:\lavasoft ad-aware 6.0 build 181 (aaw6.exe).exe
[2003/03/30 15:45:54 | 000,032,955 | ---- | M] () -- C:\layout.JPG
[2003/06/21 23:55:28 | 000,393,216 | ---- | M] () -- C:\lemonade_tycoon.zip
[2006/09/18 18:08:58 | 000,359,112 | ---- | M] () -- C:\LimeWireWin.exe
[2009/03/25 23:15:16 | 002,813,421 | ---- | M] (ManiacTools.com ) -- C:\m4a-to-mp3-converter.exe
[2006/04/28 12:40:18 | 043,424,778 | ---- | M] () -- C:\making friends1.avi
[2003/04/08 19:11:36 | 000,003,644 | ---- | M] () -- C:\ma_de_item04b.gif
[2003/04/08 19:11:58 | 000,002,879 | ---- | M] () -- C:\ma_li_item04a_1.gif
[2009/12/09 01:41:45 | 004,844,296 | ---- | M] (Malwarebytes Corporation ) -- C:\mbam-setup.exe
[2003/08/17 13:41:16 | 000,092,166 | ---- | M] () -- C:\mfaq52hp.zip
[2003/08/17 13:40:18 | 001,216,000 | ---- | M] (mIRC Co. Ltd.) -- C:\mirc603.exe
[2004/10/16 00:23:54 | 012,653,296 | ---- | M] (Microsoft Corporation) -- C:\MP10Setup.exe
[2004/09/16 01:44:12 | 010,431,072 | ---- | M] (Microsoft Corporation) -- C:\mp71.exe
[2004/08/11 16:15:00 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2005/12/19 21:36:14 | 005,316,176 | ---- | M] (Microsoft Corporation) -- C:\msjavx86.exe
[2003/09/08 02:30:42 | 000,005,283 | ---- | M] () -- C:\msnemails.gif
[2004/11/17 03:35:14 | 001,035,943 | ---- | M] ( ) -- C:\myTunesReduxInstaller.exe
[2006/11/30 22:42:26 | 000,056,702 | ---- | M] () -- C:\n19900125_30251321_1358.jpg
[2007/10/17 17:12:20 | 001,305,088 | ---- | M] () -- C:\Netflix_Movie_Viewer_Installer.msi
[2004/08/04 04:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/03/12 12:42:32 | 000,250,048 | ---- | M] () -- C:\ntldr
[2007/07/06 20:48:15 | 001,088,976 | ---- | M] () -- C:\octosetup_v_l_odd.exe
[2005/04/19 00:43:04 | 000,394,451 | ---- | M] () -- C:\other_quotes.zip
[2004/01/01 01:00:00 | 000,850,622 | ---- | M] () -- C:\P1010309.JPG
[2006/02/05 14:25:58 | 000,893,121 | ---- | M] () -- C:\P1010310.JPG
[2006/02/05 14:27:02 | 000,527,928 | ---- | M] () -- C:\P1010311.JPG
[2004/01/01 01:00:00 | 000,830,522 | ---- | M] () -- C:\P1010312.JPG
[2006/04/02 12:36:04 | 000,468,299 | ---- | M] () -- C:\P1010517.JPG
[2010/08/06 07:36:43 | 792,723,456 | -HS- | M] () -- C:\pagefile.sys
[2003/04/06 17:27:52 | 031,354,419 | ---- | M] () -- C:\Paint Shop Pro 7 full.zip
[2004/10/04 23:52:50 | 001,028,385 | ---- | M] (Stardust Software) -- C:\petpetsitter.exe
[2004/12/29 12:06:34 | 000,070,367 | ---- | M] () -- C:\phpfanbase_v2.zip
[2002/08/04 16:50:28 | 001,650,357 | ---- | M] () -- C:\player304.exe
[2006/10/15 01:37:50 | 000,488,094 | ---- | M] ( ) -- C:\PlazerSetup.exe
[2004/09/05 15:30:40 | 000,481,251 | ---- | M] () -- C:\plvx2cleaner.exe
[2009/05/02 22:31:21 | 005,618,115 | ---- | M] () -- C:\Poladroid0.9.5r5-PC.zip
[2003/05/22 02:21:18 | 000,041,626 | ---- | M] () -- C:\ps-brian2.jpg
[2008/02/16 00:46:08 | 030,401,112 | ---- | M] (Logitech, Inc.) -- C:\qc1150.exe
[2008/02/16 00:39:05 | 033,344,864 | ---- | M] (Logitech, Inc.) -- C:\qc1150_x64.exe
[2007/04/25 21:57:26 | 019,994,184 | ---- | M] (Apple Computer, Inc.) -- C:\QuickTimeInstaller.exe
[2002/08/11 02:27:28 | 001,799,685 | ---- | M] () -- C:\QuickVCD.exe
[2003/09/13 13:33:40 | 000,099,269 | ---- | M] () -- C:\r89s.wav
[2010/03/11 15:32:24 | 000,002,851 | ---- | M] () -- C:\rapport.txt
[1996/10/09 03:21:18 | 000,000,780 | ---- | M] () -- C:\README.TXT
[2005/09/18 00:19:16 | 000,850,971 | ---- | M] () -- C:\rebels 004.jpg
[2005/09/18 00:26:50 | 000,035,898 | ---- | M] () -- C:\rebels 005.jpg
[2008/06/02 17:11:57 | 042,925,882 | ---- | M] () -- C:\rezcon-win.exe
[2004/03/17 14:15:30 | 000,002,485 | ---- | M] () -- C:\rickee.txt
[2003/05/12 23:14:38 | 000,286,294 | ---- | M] () -- C:\ringtone.wav
[2003/11/28 03:14:54 | 001,043,479 | ---- | M] () -- C:\RJSS95.EXE
[2010/07/26 22:26:56 | 000,000,371 | ---- | M] () -- C:\rkill.log
[1996/10/09 01:23:28 | 002,071,235 | ---- | M] () -- C:\ROMEO95.EXE
[2005/09/17 12:52:22 | 000,788,318 | ---- | M] () -- C:\roomiesdos 001.jpg
[2005/09/17 12:52:24 | 000,828,861 | ---- | M] () -- C:\roomiesdos 002.jpg
[2003/10/12 23:22:52 | 000,041,125 | ---- | M] () -- C:\runmenu.jpg
[2004/03/07 15:30:12 | 000,249,520 | ---- | M] () -- C:\sangwall.jpg
[2004/03/07 15:31:12 | 000,257,853 | ---- | M] () -- C:\sangwall2.jpg
[2007/11/25 01:52:03 | 000,399,703 | ---- | M] () -- C:\sb_quotes.zip
[2004/02/09 12:35:16 | 000,962,597 | ---- | M] () -- C:\scanogram.jpg
[2001/03/14 11:21:18 | 000,002,238 | ---- | M] () -- C:\ShinHwaicon.ico
[2008/02/16 00:55:50 | 006,997,792 | ---- | M] (SightSpeed Inc.) -- C:\SightSpeedSetup.exe
[2009/09/08 19:52:51 | 004,938,616 | ---- | M] (Microsoft Corporation) -- C:\Silverlight.exe
[2005/10/29 01:14:26 | 000,038,289 | ---- | M] () -- C:\SimpleViewer_v17.zip
[2008/06/18 18:58:01 | 000,039,409 | ---- | M] () -- C:\ski32.zip
[2002/07/15 01:43:44 | 000,230,975 | ---- | M] () -- C:\skinner120.zip
[2004/11/07 23:05:04 | 000,786,333 | ---- | M] () -- C:\slsk154test.exe
[2005/04/11 00:03:50 | 000,107,792 | ---- | M] (Microsoft Corporation) -- C:\sndrec32.exe
[2004/05/14 08:27:30 | 004,354,084 | ---- | M] (Safer Networking Limited ) -- C:\spybot 1.3 05.12.04 (spybotsd13.exe).exe
[2007/10/08 23:42:20 | 007,467,056 | ---- | M] (Safer Networking Ltd. ) -- C:\spybotsd15.exe
[2004/09/05 15:07:22 | 002,247,855 | ---- | M] (Javacool Software LLC ) -- C:\spywareblastersetup.exe
[2005/10/31 08:56:02 | 000,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe
[2004/09/09 00:51:46 | 000,065,503 | ---- | M] () -- C:\surf-flier-small.jpg
[2007/11/25 01:50:12 | 001,544,848 | ---- | M] () -- C:\sys_sounds.zip
[2003/07/22 04:25:10 | 000,387,985 | ---- | M] (Macromedia, Inc.) -- C:\take-a-break.exe
[2003/01/15 09:16:22 | 000,900,243 | ---- | M] (Stardust Software) -- C:\techodance.exe
[2007/11/25 01:54:05 | 000,844,636 | ---- | M] () -- C:\The Cheat Theme Song.zip
[2007/11/25 01:56:02 | 000,688,534 | ---- | M] () -- C:\The System is Down.zip
[2007/11/25 01:54:44 | 000,859,743 | ---- | M] () -- C:\Trogdor.zip
[2004/02/06 01:25:58 | 000,000,079 | ---- | M] () -- C:\twacker.log
[2003/08/14 05:17:16 | 000,000,062 | ---- | M] () -- C:\Untitled-1 copy.gif
[2003/05/29 22:53:42 | 000,005,361 | ---- | M] () -- C:\Untitled-2 copy.jpg
[2003/08/28 22:37:00 | 000,046,263 | ---- | M] () -- C:\untitled.GIF
[2003/06/13 03:06:02 | 000,067,429 | ---- | M] () -- C:\untitled.JPG
[2003/08/16 19:49:44 | 000,108,251 | ---- | M] () -- C:\untitled2.JPG
[2003/08/16 19:57:10 | 000,046,338 | ---- | M] () -- C:\untitled3.JPG
[2003/08/17 01:45:04 | 000,022,754 | ---- | M] () -- C:\untitled4.JPG
[2004/12/11 19:18:06 | 000,001,189 | ---- | M] () -- C:\VETlog.txt
[2006/12/30 14:00:46 | 000,014,738 | ---- | M] () -- C:\videodownloader-1.1.1-fx.xpi
[2007/05/27 14:05:24 | 009,516,033 | ---- | M] () -- C:\vlc-0.8.6b-win32.exe
[2004/08/11 08:58:14 | 000,000,014 | ---- | M] () -- C:\win2.log
[2004/08/10 22:20:56 | 005,703,377 | ---- | M] (Intel Corporation) -- C:\win2k_xp141.exe
[2007/04/22 18:28:13 | 006,718,976 | ---- | M] (Nullsoft, Inc.) -- C:\winamp533_full_emusic-7plus.exe
[2004/08/11 09:07:16 | 002,710,296 | ---- | M] (Microsoft Corporation) -- C:\WindowsXP-KB835732-x86-ENU.EXE
[2006/03/21 23:04:26 | 000,000,621 | ---- | M] () -- C:\WS_FTP.LOG
[2007/08/04 17:04:43 | 000,682,063 | ---- | M] () -- C:\ws_ftp45.exe
[2002/07/13 22:18:16 | 000,707,072 | ---- | M] () -- C:\ws_ftple.exe
[2004/10/02 11:46:46 | 003,905,464 | ---- | M] (Microsoft Corporation) -- C:\xlViewer.exe
[2003/07/17 11:32:16 | 000,142,993 | ---- | M] () -- C:\XviD-Dec-300303.exe
[2005/11/17 21:18:20 | 006,805,758 | ---- | M] () -- C:\yahoo_dynomite_tm1-1.exe
[2003/01/08 05:00:50 | 001,256,972 | ---- | M] () -- C:\ZipWizard20.exe
[2010/07/18 18:41:39 | 000,000,150 | ---- | M] () -- C:\zrpt.xml
[2004/08/24 20:50:04 | 006,113,752 | ---- | M] () -- C:\ZumaSetup.exe
[2007/08/11 07:33:56 | 000,000,221 | ---- | M] () -- C:\_audioscrobbler.log
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav >[2004/08/11 16:06:14 | 000,094,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2004/08/11 16:06:14 | 000,659,456 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2004/08/11 16:06:14 | 000,876,544 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< %systemroot%\system32\drivers\*.sys /90 > ========== Files - Unicode (All) ==========[2008/03/12 02:53:30 | 000,070,656 | ---- | M] ()(C:\Documents and Settings\kelsey\My Documents\?????.doc) -- C:\Documents and Settings\kelsey\My Documents\사랑인가요.doc
[2008/03/12 02:40:40 | 000,070,656 | ---- | C] ()(C:\Documents and Settings\kelsey\My Documents\?????.doc) -- C:\Documents and Settings\kelsey\My Documents\사랑인가요.doc
========== Alternate Data Streams ========== @Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CE2C623F
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5E1F4E0B
< End of report >
wasn't sure if you wanted extras too so in case, here it is
OTL Extras logfile created on: 8/7/2010 12:39:56 am - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\kelsey\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.43 Gb Total Space | 29.36 Gb Free Space | 39.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 268.75 Gb Free Space | 57.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D2ZLV571
Current User Name: kelsey
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\AIM95\aim.exe" = C:\Program Files\AIM95\aim.exe:*:Enabled:AOL Instant Messenger -- (America Online, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\SYSTEM32\grdmgr.exe" = C:\WINDOWS\SYSTEM32\grdmgr.exe:*:Enabled:CDN ???? ?? -- (나우콤)
"C:\Program Files\AIM95\aim.exe" = C:\Program Files\AIM95\aim.exe:*:Enabled:AOL Instant Messenger -- (America Online, Inc.)
"C:\WINDOWS\SYSTEM32\BugsSvr.exe" = C:\WINDOWS\SYSTEM32\BugsSvr.exe:*:Enabled:Bugs Music Player Control -- ()
"C:\Program Files\AIM7\aim.exe" = C:\Program Files\AIM7\aim.exe:*:Enabled:AIM -- (AOL Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series" = Canon iP2600 series
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{25D24E84-64A9-40D2-85CF-540B1C4A6D52}" = Broadcom ASF Management Applications
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java 6 Update 18
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2A539CD9-0F75-4875-9A32-E06DD93C4114}" = Adobe Extension Manager CS3
"{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A12C952-61D5-4C3B-B68B-8CFBE47E22F1}" = Adobe Setup
"{45ACEB0A-5B7F-22C5-39F8-0D2CA0918A27}" = MyFonts Order M1124785
"{48EE6C79-1CE2-4CE8-B511-F2140B6781D6}" = Google Earth Pro
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{73F1BDB7-11E1-11D5-9DC6-00C04F2FC33B}" = OMCI
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_WebDesigner_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_WebDesigner_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_WebDesigner_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0026-0000-0000-0000000FF1CE}" = Microsoft Expression Web
"{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{9037FDA8-8383-4B6F-859D-D49C3C625225}" = Microsoft Expression Web Service Pack 1 (SP1)
"{90120000-0026-0409-0000-0000000FF1CE}" = Microsoft Expression Web MUI (English)
"{90120000-0026-0409-0000-0000000FF1CE}_WebDesigner_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_WebDesigner_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_WebDesigner_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90BC0F01-9D99-4686-AC14-2EEC0246FB84}" = Poladroid
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9811A185-3D3D-11D6-9E14-00036D172B00}" = Adobe MPEG Encoder
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.