Hi peku,
I just post the log like this and wait for your response?
OTS logfile created on: 1/22/2010 12:41:40 AM - Run 1
OTS by OldTimer - Version 3.1.19.2 Folder = C:\Documents and Settings\Owner\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 117.19 Gb Total Space | 25.38 Gb Free Space | 21.66% Space Free | Partition Type: NTFS
Drive D: | 180.89 Gb Total Space | 35.61 Gb Free Space | 19.69% Space Free | Partition Type: NTFS
Drive E: | 480.69 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 39.06 Gb Total Space | 2.34 Gb Free Space | 5.99% Space Free | Partition Type: NTFS
Drive G: | 18.55 Gb Total Space | 4.74 Gb Free Space | 25.53% Space Free | Partition Type: NTFS
Drive H: | 16.91 Gb Total Space | 7.52 Gb Free Space | 44.49% Space Free | Partition Type: NTFS
Drive I: | 611.13 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 608.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: USER-3276E4FE42
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
ots.exe -> C:\Documents and Settings\Owner\My Documents\OTS.exe -> [2010/01/22 00:07:20 | 00,631,808 | ---- | M] (OldTimer Tools)
firefox.exe -> C:\Program Files\Mozilla Firefox\firefox.exe -> [2010/01/07 02:25:33 | 00,908,248 | ---- | M] (Mozilla Corporation)
avgtray.exe -> C:\Program Files\AVG\AVG8\avgtray.exe -> [2009/12/12 09:42:26 | 02,043,160 | ---- | M] (AVG Technologies CZ, s.r.o.)
steam.exe -> C:\Program Files\Steam\Steam.exe -> [2009/10/26 19:08:34 | 01,217,808 | ---- | M] (Valve Corporation)
avgcsrvx.exe -> C:\Program Files\AVG\AVG8\avgcsrvx.exe -> [2009/08/19 17:54:04 | 00,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgrsx.exe -> C:\Program Files\AVG\AVG8\avgrsx.exe -> [2009/08/19 17:54:04 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgnsx.exe -> C:\Program Files\AVG\AVG8\avgnsx.exe -> [2009/08/19 17:54:01 | 00,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgemc.exe -> C:\Program Files\AVG\AVG8\avgemc.exe -> [2009/08/19 17:54:00 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> C:\Program Files\AVG\AVG8\avgwdsvc.exe -> [2009/08/19 17:53:56 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.)
hamachi.exe -> C:\Program Files\Hamachi\hamachi.exe -> [2009/04/13 21:28:04 | 00,625,952 | ---- | M] (LogMeIn Inc.)
nvsvc32.exe -> C:\WINDOWS\system32\nvsvc32.exe -> [2008/10/07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation)
pnkbstra.exe -> C:\WINDOWS\system32\PnkBstrA.exe -> [2008/07/06 22:43:04 | 00,066,872 | ---- | M] ()
daemon.exe -> C:\Program Files\DAEMON Tools\daemon.exe -> [2007/04/04 06:29:15 | 00,165,784 | ---- | M] (DT Soft Ltd.)
rthdcpl.exe -> C:\WINDOWS\RTHDCPL.exe -> [2006/09/06 11:44:20 | 16,262,656 | R--- | M] (Realtek Semiconductor Corp.)
explorer.exe -> C:\WINDOWS\explorer.exe -> [2006/02/28 20:00:00 | 01,032,192 | ---- | M] (Microsoft Corporation)
tcpsvcs.exe -> C:\WINDOWS\system32\tcpsvcs.exe -> [2006/02/28 20:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation)
wscntfy.exe -> C:\WINDOWS\system32\wscntfy.exe -> [2006/02/28 20:00:00 | 00,013,824 | ---- | M] (Microsoft Corporation)
mdnsresponder.exe -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2006/02/28 12:42:38 | 00,229,376 | ---- | M] (Apple Computer, Inc.)
tablet.exe -> C:\WINDOWS\system32\Tablet.exe -> [2005/12/06 12:00:44 | 00,753,664 | ---- | M] (Wacom Technology, Corp.)
tabuserw.exe -> C:\WINDOWS\system32\WTablet\TabUserW.exe -> [2005/12/06 11:59:02 | 00,114,688 | ---- | M] (Wacom Technology, Corp.)
[Modules - Safe List]
ots.exe -> C:\Documents and Settings\Owner\My Documents\OTS.exe -> [2010/01/22 00:07:20 | 00,631,808 | ---- | M] (OldTimer Tools)
comctl32.dll -> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll -> [2006/02/28 20:00:00 | 01,050,624 | ---- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
(gupdate) Google アップデート サービス (gupdate) [Auto | Stopped] -> C:\Program Files\Google\Update\GoogleUpdate.exe -> [2009/12/09 22:18:40 | 00,135,664 | ---- | M] (Google Inc.)
(avg8emc) AVG8 E-mail Scanner [Auto | Running] -> C:\Program Files\AVG\AVG8\avgemc.exe -> [2009/08/19 17:54:00 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.)
(avg8wd) AVG8 WatchDog [Auto | Running] -> C:\Program Files\AVG\AVG8\avgwdsvc.exe -> [2009/08/19 17:53:56 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.)
(npggsvc) nProtect GameGuard Service [On_Demand | Stopped] -> C:\WINDOWS\System32\GameMon.des -> [2009/02/19 06:21:00 | 02,769,658 | ---- | M] (INCA Internet Co., Ltd.)
(NVSvc) NVIDIA Display Driver Service [Auto | Running] -> C:\WINDOWS\system32\nvsvc32.exe -> [2008/10/07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation)
(PnkBstrA) PnkBstrA [Auto | Running] -> C:\WINDOWS\system32\PnkBstrA.exe -> [2008/07/06 22:43:04 | 00,066,872 | ---- | M] ()
(Adobe LM Service) Adobe LM Service [On_Demand | Stopped] -> C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -> [2007/11/08 22:57:50 | 00,072,704 | ---- | M] (Adobe Systems)
(FLEXnet Licensing Service) FLEXnet Licensing Service [On_Demand | Stopped] -> C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2007/08/21 17:33:03 | 00,654,848 | ---- | M] (Macrovision Europe Ltd.)
(p2pgasvc) Peer Networking Group Authentication [On_Demand | Stopped] -> C:\WINDOWS\system32\p2pgasvc.dll -> [2006/02/28 20:00:00 | 00,086,016 | ---- | M] (Microsoft Corporation)
(SimpTcp) Simple TCP/IP Services [Auto | Running] -> C:\WINDOWS\system32\tcpsvcs.exe -> [2006/02/28 20:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation)
(Bonjour Service) ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## [Auto | Running] -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2006/02/28 12:42:38 | 00,229,376 | ---- | M] (Apple Computer, Inc.)
(TabletService) TabletService [Auto | Running] -> C:\WINDOWS\system32\Tablet.exe -> [2005/12/06 12:00:44 | 00,753,664 | ---- | M] (Wacom Technology, Corp.)
(Iprip) RIP Listener [Auto | Running] -> C:\WINDOWS\system32\iprip.dll -> [2004/08/04 20:00:00 | 00,035,328 | ---- | M] (Microsoft Corporation)
(Irmon) Infrared Monitor [Auto | Running] -> C:\WINDOWS\system32\irmon.dll -> [2004/08/04 08:56:44 | 00,027,136 | ---- | M] (Microsoft Corporation)
[Driver Services - Safe List]
(GarenaPEngine) GarenaPEngine [Kernel | On_Demand | Stopped] -> C:\Documents and Settings\Owner\Local Settings\Temp\FUHA1.tmp -> [2010/01/17 23:25:08 | 00,025,616 | ---- | M] ()
(AvgLdx86) AVG AVI Loader Driver x86 [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\avgldx86.sys -> [2009/08/19 17:54:04 | 00,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> C:\WINDOWS\System32\Drivers\avgmfx86.sys -> [2009/08/19 17:54:04 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgTdiX) AVG8 Network Redirector [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\avgtdix.sys -> [2009/05/06 18:39:37 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.)
(nv) nv [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\nv4_mini.sys -> [2008/10/07 13:33:00 | 06,133,856 | ---- | M] (NVIDIA Corporation)
(Secdrv) Secdrv [Kernel | Auto | Running] -> C:\WINDOWS\system32\drivers\secdrv.sys -> [2008/05/21 22:24:58 | 00,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(hamachi) Hamachi Network Interface [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\hamachi.sys -> [2007/11/30 21:07:00 | 00,025,280 | ---- | M] (LogMeIn, Inc.)
(LMouKE) SetPoint Mouse Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\LMouKE.Sys -> [2007/11/29 02:18:04 | 00,078,992 | ---- | M] (Logitech, Inc.)
(LMouFilt) Logitech SetPoint KMDF Mouse Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\LMouFilt.Sys -> [2007/11/29 02:17:56 | 00,036,368 | ---- | M] (Logitech, Inc.)
(LHidFilt) Logitech SetPoint KMDF HID Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\LHidFilt.Sys -> [2007/11/29 02:17:48 | 00,035,088 | ---- | M] (Logitech, Inc.)
(L8042mou) SetPoint PS/2 Mouse Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\L8042mou.Sys -> [2007/11/29 02:17:34 | 00,063,120 | ---- | M] (Logitech, Inc.)
(L8042Kbd) Logitech SetPoint Keyboard Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\L8042Kbd.sys -> [2007/11/29 02:17:28 | 00,020,240 | ---- | M] (Logitech, Inc.)
(Haspnt) Haspnt [Kernel | Auto | Running] -> C:\WINDOWS\system32\drivers\Haspnt.sys -> [2007/08/12 00:43:30 | 00,047,616 | ---- | M] (Aladdin Knowledge Systems)
(sptd) sptd [Kernel | Boot | Running] -> C:\WINDOWS\System32\Drivers\sptd.sys -> [2007/07/17 23:46:16 | 00,682,232 | ---- | M] ()
(LUsbFilt) Logitech SetPoint KMDF USB Filter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\LUsbFilt.sys -> [2007/04/11 15:33:14 | 00,028,688 | ---- | M] (Logitech, Inc.)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\RtkHDAud.Sys -> [2006/09/06 16:04:12 | 04,377,600 | R--- | M] (Realtek Semiconductor Corp.)
(nvnetbus) NVIDIA Network Bus Enumerator [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\nvnetbus.sys -> [2006/05/16 19:25:02 | 00,018,944 | R--- | M] (NVIDIA Corporation)
(NVENETFD) NVIDIA nForce Networking Controller Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\NVENETFD.sys -> [2006/05/16 19:25:00 | 00,052,736 | R--- | M] (NVIDIA Corporation)
(nvata) nvata [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\nvata.sys -> [2006/04/24 17:52:28 | 00,100,736 | R--- | M] (NVIDIA Corporation)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ptilink.sys -> [2006/02/28 20:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(FsVga) FsVga [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\fsvga.sys -> [2006/02/28 20:00:00 | 00,012,160 | ---- | M] (Microsoft Corporation)
(PenClass) Pen Class [Kernel | Boot | Running] -> C:\WINDOWS\system32\Drivers\PenClass.sys -> [2005/11/30 12:50:42 | 00,008,138 | ---- | M] (Wacom Technology Corporation)
(Hardlock) Hardlock [Kernel | Auto | Running] -> C:\WINDOWS\system32\drivers\hardlock.sys -> [2005/07/28 08:18:40 | 00,685,056 | ---- | M] (Aladdin Knowledge Systems Ltd.)
(AmdK8) AMD Processor Driver [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\AmdK8.sys -> [2005/03/09 14:53:00 | 00,036,352 | R--- | M] (Advanced Micro Devices)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\Hdaudbus.sys -> [2005/01/07 17:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider)
(irsir) Microsoft Serial Infrared Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\irsir.sys -> [2001/08/17 21:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation)
(Sentinel) Sentinel [Kernel | Auto | Running] -> C:\WINDOWS\System32\Drivers\SENTINEL.SYS -> [2001/06/21 21:39:02 | 00,073,728 | ---- | M] (Rainbow Technologies, Inc.)
(Sntnlusb) Rainbow USB SuperPro [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\SNTNLUSB.SYS -> [2001/06/21 21:39:02 | 00,020,032 | R--- | M] (Rainbow Technologies Inc.)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\] > -> ->
HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\: SearchURL\\"provider" -> ->
HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\: "ProxyEnable" -> 0 ->
HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\: "ProxyOverride" -> *.local ->
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\6ho963th.default\prefs.js ->
browser.startup.homepage -> "www.google.com.sg" ->
extensions.enabledItems -> {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.7 ->
network.proxy.backup.ftp -> "" ->
network.proxy.backup.ftp_port -> 0 ->
network.proxy.backup.gopher -> "" ->
network.proxy.backup.gopher_port -> 0 ->
network.proxy.backup.socks -> "" ->
network.proxy.backup.socks_port -> 0 ->
network.proxy.backup.ssl -> "" ->
network.proxy.backup.ssl_port -> 0 ->
network.proxy.ftp -> "66.63.165.62" ->
network.proxy.ftp_port -> 3128 ->
network.proxy.gopher -> "66.63.165.62" ->
network.proxy.gopher_port -> 3128 ->
network.proxy.http -> "66.63.165.62" ->
network.proxy.http_port -> 3128 ->
network.proxy.share_proxy_settings -> true ->
network.proxy.socks -> "66.63.165.62" ->
network.proxy.socks_port -> 3128 ->
network.proxy.ssl -> "66.63.165.62" ->
network.proxy.ssl_port -> 3128 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> C:\Program Files\AVG\AVG8\Firefox [C:\PROGRAM FILES\AVG\AVG8\FIREFOX] -> [2009/12/22 20:50:55 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components -> C:\Program Files\Mozilla Firefox\components [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2010/01/16 00:06:49 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins -> C:\Program Files\Mozilla Firefox\plugins [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2010/01/17 12:25:10 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions -> ->
HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components -> C:\Program Files\Mozilla Thunderbird\components [C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS] -> [2009/08/22 21:41:29 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins -> C:\Program Files\Mozilla Thunderbird\plugins [C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS] -> [2010/01/15 21:45:40 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions -> [2008/12/18 19:52:01 | 00,000,000 | ---D | M]
-> C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6ho963th.default\extensions -> [2010/01/22 00:00:09 | 00,000,000 | ---D | M]
FireFTP -> C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6ho963th.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} -> [2009/12/08 19:34:50 | 00,000,000 | ---D | M]
Greasemonkey -> C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6ho963th.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} -> [2009/12/18 17:37:39 | 00,000,000 | ---D | M]
< FireFox Extensions [Program Folders] > ->
-> C:\Program Files\Mozilla Firefox\extensions -> [2010/01/17 00:49:47 | 00,000,000 | ---D | M]
Java Console -> C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} -> [2007/07/01 23:36:19 | 00,000,000 | ---D | M]
< HOSTS File > (371233 bytes and 12842 lines) -> C:\WINDOWS\system32\drivers\etc\hosts ->
First 25 entries...
Reset Hosts
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [Adobe PDF Link Helper] -> [2009/12/21 18:27:44 | 00,075,200 | ---- | M] (Adobe Systems Incorporated)
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} [HKLM] -> C:\Program Files\FlashGet\jccatch.dll [FGCatchUrl] -> [2007/06/29 19:44:36 | 00,094,308 | ---- | M] (www.flashget.com)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Program Files\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009/12/12 09:42:28 | 01,111,320 | ---- | M] (AVG Technologies CZ, s.r.o.)
{5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre1.6.0\bin\ssv.dll [SSVHelper Class] -> [2007/07/01 23:36:13 | 00,501,384 | ---- | M] (Sun Microsystems, Inc.)
{F156768E-81EF-470C-9057-481BA8380DBA} [HKLM] -> C:\Program Files\FlashGet\getflash.dll [FlashGet GetFlash Class] -> [2007/05/16 13:05:16 | 00,163,840 | ---- | M] (www.flashget.com)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Adobe ARM" -> C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe ["C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"] -> [2009/12/11 15:57:56 | 00,948,672 | R--- | M] (Adobe Systems Incorporated)
"Adobe Photo Downloader" -> C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe ["C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"] -> File not found
"Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"] -> [2009/12/22 01:57:28 | 00,035,760 | ---- | M] (Adobe Systems Incorporated)
"Alcmtr" -> C:\WINDOWS\Alcmtr.exe [ALCMTR.EXE] -> [2005/05/03 18:43:28 | 00,069,632 | R--- | M] (Realtek Semiconductor Corp.)
"AVG8_TRAY" -> C:\Program Files\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2009/12/12 09:42:26 | 02,043,160 | ---- | M] (AVG Technologies CZ, s.r.o.)
"IMJPMIG8.1" -> C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE ["C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] -> [2004/08/04 20:00:00 | 00,208,952 | ---- | M] (Microsoft Corporation)
"Kernel and Hardware Abstraction Layer" -> C:\WINDOWS\KHALMNPR.Exe [KHALMNPR.EXE] -> [2007/11/29 02:17:20 | 00,055,824 | ---- | M] (Logitech, Inc.)
"Logitech Hardware Abstraction Layer" -> C:\WINDOWS\KHALMNPR.Exe [KHALMNPR.EXE] -> [2007/11/29 02:17:20 | 00,055,824 | ---- | M] (Logitech, Inc.)
"MSPY2002" -> C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe [C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC] -> [2004/08/04 20:00:00 | 00,059,392 | ---- | M] ()
"NeroFilterCheck" -> C:\WINDOWS\system32\NeroCheck.exe [C:\WINDOWS\system32\NeroCheck.exe] -> [2001/07/09 10:50:42 | 00,155,648 | ---- | M] (Ahead Software Gmbh)
"NvCplDaemon" -> C:\WINDOWS\System32\NvCpl.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2008/10/07 13:33:00 | 13,574,144 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" -> C:\WINDOWS\System32\NvMcTray.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2008/10/07 13:33:00 | 00,086,016 | ---- | M] (NVIDIA Corporation)
"nwiz" -> C:\WINDOWS\System32\nwiz.exe [nwiz.exe /install] -> [2008/10/07 13:33:00 | 01,630,208 | ---- | M] ()
"PHIME2002A" -> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2004/08/04 20:00:00 | 00,455,168 | ---- | M] (Microsoft Corporation)
"PHIME2002ASync" -> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> [2004/08/04 20:00:00 | 00,455,168 | ---- | M] (Microsoft Corporation)
"QuickTime Task" -> C:\Program Files\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2008/09/06 15:09:14 | 00,413,696 | ---- | M] (Apple Inc.)
"RTHDCPL" -> C:\WINDOWS\RTHDCPL.exe [RTHDCPL.EXE] -> [2006/09/06 11:44:20 | 16,262,656 | R--- | M] (Realtek Semiconductor Corp.)
"SkyTel" -> C:\WINDOWS\SkyTel.exe [SkyTel.EXE] -> [2006/05/16 18:04:26 | 02,879,488 | R--- | M] (Realtek Semiconductor Corp.)
< Run [HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\] > -> HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"DAEMON Tools" -> C:\Program Files\DAEMON Tools\daemon.exe ["C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033] -> [2007/04/04 06:29:15 | 00,165,784 | ---- | M] (DT Soft Ltd.)
"NCsoft Launcher" -> C:\Program Files\NCsoft\Launcher\NCLauncher.exe [C:\Program Files\NCsoft\Launcher\NCLauncher.exe /Minimized] -> File not found
"Network IPv6" -> C:\WINDOWS\Network-IPv6\network.exe [C:\WINDOWS\Network-IPv6\network.exe] -> File not found
"Steam" -> C:\Program Files\Steam\Steam.exe ["C:\Program Files\Steam\Steam.exe" -silent] -> [2009/10/26 19:08:34 | 01,217,808 | ---- | M] (Valve Corporation)
"UserLogon" -> C:\Documents and Settings\Owner\winlogon.exe [C:\Documents and Settings\Owner\winlogon.exe] -> File not found
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk -> C:\WINDOWS\system32\WTablet\TabUserW.exe -> [2005/12/06 11:59:02 | 00,114,688 | ---- | M] (Wacom Technology, Corp.)
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup ->
< Owner Startup Folder > -> C:\Documents and Settings\Owner\Start Menu\Programs\Startup ->
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk -> C:\Program Files\ERUNT\AUTOBACK.EXE -> [2005/10/20 12:04:08 | 00,038,912 | ---- | M] ()
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\hamachi.lnk -> C:\Program Files\Hamachi\hamachi.exe -> [2009/04/13 21:28:04 | 00,625,952 | ---- | M] (LogMeIn Inc.)
< Software Policy Settings [HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003] > -> HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [91 00 00 00 [binary data]] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [91 00 00 00 [binary data]] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003] > -> HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [36] -> File not found
\\"NoDriveAutoRun" -> [FF FF FF FF [binary data]] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003] > -> HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\] > -> HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\Software\Microsoft\Internet Explorer\MenuExt\ ->
&Download All with FlashGet -> C:\Program Files\FlashGet\JC_ALL.HTM [C:\Program Files\FlashGet\jc_all.htm] -> [2007/05/15 17:10:34 | 00,001,049 | ---- | M] ()
&Download with FlashGet -> C:\Program Files\FlashGet\JC_LINK.HTM [C:\Program Files\FlashGet\jc_link.htm] -> [2007/05/15 17:10:34 | 00,001,898 | ---- | M] ()
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}:Exec [HKLM] -> C:\Program Files\FlashGet\flashget.exe [Button: FlashGet] -> [2007/06/29 19:44:34 | 01,990,704 | ---- | M] (FlashGet.com)
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}:Exec [HKLM] -> C:\Program Files\FlashGet\flashget.exe [Menu: FlashGet] -> [2007/06/29 19:44:34 | 01,990,704 | ---- | M] (FlashGet.com)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\] > -> HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}" [HKLM] -> C:\Program Files\FlashGet\flashget.exe [FlashGet] -> [2007/06/29 19:44:34 | 01,990,704 | ---- | M] (FlashGet.com)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 6618 domain(s) found. ->
58 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 6617 domain(s) found. ->
57 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 6617 domain(s) found. ->
57 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\] > -> HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 6617 domain(s) found. ->
57 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\] > -> HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-484763869-1637723038-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{5C051655-FCD5-4969-9182-770EA5AA5565} [HKLM] -> http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab [Solitaire Showdown Class] ->
{6414512B-B978-451D-A0D8-FCFDF33E833C} [HKLM] -> http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194533315765 [WUWebControl Class] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab [Java Plug-in 1.6.0] ->
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} [HKLM] -> http://acs.pandasoftware.com/activescan/as5free/asinst.cab [ActiveScan Installer Class] ->
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab [MessengerStatsClient Class] ->
{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab [Java Plug-in 1.6.0] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab [Java Plug-in 1.6.0] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{FE6685E5-269D-46EA-A43E-E52FCA78EF34}\\NameServer -> 202.156.1.48,202.156.1.58 (NVIDIA nForce Networking Controller) ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\WINDOWS\explorer.exe -> [2006/02/28 20:00:00 | 01,032,192 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
avgrsstarter -> C:\WINDOWS\System32\avgrsstx.dll -> [2009/08/19 17:54:04 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> File not found
"C:\Program Files\NCsoft\Exteel\System\Exteel.exe" -> C:\Program Files\NCsoft\Exteel\System\Exteel.exe [C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel] -> File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" -> C:\Program Files\Windows Live\Messenger\wlcsdk.exe [C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2009/02/06 18:21:00 | 00,583,024 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"C:\Documents and Settings\Owner\Desktop\lancraft.exe" -> C:\Documents and Settings\Owner\Desktop\lancraft.exe [C:\Documents and Settings\Owner\Desktop\lancraft.exe:*:Enabled:lancraft] -> [2002/07/12 01:40:00 | 00,713,216 | ---- | M] ()
"C:\Documents and Settings\Owner\Desktop\utorrent.exe" -> C:\Documents and Settings\Owner\Desktop\utorrent.exe [C:\Documents and Settings\Owner\Desktop\utorrent.exe:*:Enabled:µTorrent] -> [2009/12/23 14:30:43 | 00,289,584 | ---- | M] (BitTorrent, Inc.)
"C:\Program Files\Autodesk\Maya8.5\bin\maya.exe" -> C:\Program Files\Autodesk\Maya8.5\bin\maya.exe [C:\Program Files\Autodesk\Maya8.5\bin\maya.exe:*:Enabled:Maya] -> [2007/06/07 05:58:32 | 00,225,280 | ---- | M] (Autodesk)
"C:\Program Files\AVG\AVG8\avgemc.exe" -> C:\Program Files\AVG\AVG8\avgemc.exe [C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe] -> [2009/08/19 17:54:00 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> [2009/12/12 09:42:09 | 01,143,064 | ---- | M] (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2006/02/28 12:42:38 | 00,229,376 | ---- | M] (Apple Computer, Inc.)
"C:\Program Files\Bothtec\MacrossVOXP\mcr.exe" -> C:\Program Files\Bothtec\MacrossVOXP\mcr.exe [C:\Program Files\Bothtec\MacrossVOXP\mcr.exe:*:Enabled:MACROSS VO] -> File not found
"C:\Program Files\FlashGet\flashget.exe" -> C:\Program Files\FlashGet\flashget.exe [C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget] -> [2007/06/29 19:44:34 | 01,990,704 | ---- | M] (FlashGet.com)
"C:\Program Files\Garena\Garena.exe" -> C:\Program Files\Garena\Garena.exe [C:\Program Files\Garena\Garena.exe:*:Enabled:Garena] -> [2009/09/02 15:45:02 | 03,224,848 | ---- | M] (Garena Interactive PTE LTD)
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" -> C:\Program Files\Grisoft\AVG7\avgamsvr.exe [C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe] -> File not found
"C:\Program Files\Grisoft\AVG7\avgcc.exe" -> C:\Program Files\Grisoft\AVG7\avgcc.exe [C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe] -> File not found
"C:\Program Files\Grisoft\AVG7\avginet.exe" -> C:\Program Files\Grisoft\AVG7\avginet.exe [C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe] -> File not found
"C:\Program Files\Hamachi\hamachi.exe" -> C:\Program Files\Hamachi\hamachi.exe [C:\Program Files\Hamachi\hamachi.exe:*:Enabled:Hamachi Client] -> [2009/04/13 21:28:04 | 00,625,952 | ---- | M] (LogMeIn Inc.)
"C:\Program Files\Java\jre1.6.0\bin\javaws.exe" -> C:\Program Files\Java\jre1.6.0\bin\javaws.exe [C:\Program Files\Java\jre1.6.0\bin\javaws.exe:*:Enabled:Java(TM) Web Start Launcher] -> [2007/07/01 23:36:13 | 00,139,264 | ---- | M] (Sun Microsystems, Inc.)
"C:\Program Files\KVIrc\kvirc.exe" -> C:\Program Files\KVIrc\kvirc.exe [C:\Program Files\KVIrc\kvirc.exe:*:Enabled:kvirc] -> [2005/02/26 02:59:40 | 01,912,832 | ---- | M] ()
"C:\Program Files\Microsoft Games\Age of Mythology\aom.exe" -> C:\Program Files\Microsoft Games\Age of Mythology\aom.exe [C:\Program Files\Microsoft Games\Age of Mythology\aom.exe:*:Enabled:Age of Mythology] -> File not found
"C:\Program Files\Mozilla Firefox\firefox.exe" -> C:\Program Files\Mozilla Firefox\firefox.exe [C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox] -> [2010/01/07 02:25:33 | 00,908,248 | ---- | M] (Mozilla Corporation)
"C:\Program Files\Mozilla Thunderbird\thunderbird.exe" -> C:\Program Files\Mozilla Thunderbird\thunderbird.exe [C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird] -> [2009/08/22 21:41:27 | 08,318,056 | ---- | M] (Mozilla Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> File not found
"C:\Program Files\NCsoft\Exteel\System\Exteel.exe" -> C:\Program Files\NCsoft\Exteel\System\Exteel.exe [C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel] -> File not found
"C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe" -> C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe [C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe:*:Enabled:PlayOnline Viewer] -> [2008/03/11 18:53:46 | 01,691,648 | ---- | M] (SQUARE ENIX CO., LTD.)
"C:\Program Files\Qianhong\Qianhong.exe" -> C:\Program Files\Qianhong\Qianhong.exe [C:\Program Files\Qianhong\Qianhong.exe:*:Enabled:Qianhong Application] -> File not found
"C:\Program Files\Steam\Steam.exe" -> C:\Program Files\Steam\Steam.exe [C:\Program Files\Steam\Steam.exe:*:Enabled:Steam Client] -> [2009/10/26 19:08:34 | 01,217,808 | ---- | M] (Valve Corporation)
"C:\Program Files\Steam\steamapps\neojava\team fortress 2\hl2.exe" -> C:\Program Files\Steam\steamapps\neojava\team fortress 2\hl2.exe [C:\Program Files\Steam\steamapps\neojava\team fortress 2\hl2.exe:*:Enabled:hl2] -> [2009/01/16 23:31:33 | 00,098,304 | ---- | M] ()
"C:\Program Files\Steam\steamapps\ss0ul_climax@hotmail.com\day of defeat\hl.exe" -> C:\Program Files\Steam\steamapps\ss0ul_climax@hotmail.com\day of defeat\hl.exe [C:\Program Files\Steam\steamapps\ss0ul_climax@hotmail.com\day of defeat\hl.exe:*:Enabled:Half-Life Launcher] -> File not found
"C:\Program Files\Steam\steamapps\ss0ul_climax@hotmail.com\half-life\hl.exe" -> C:\Program Files\Steam\steamapps\ss0ul_climax@hotmail.com\half-life\hl.exe [C:\Program Files\Steam\steamapps\ss0ul_climax@hotmail.com\half-life\hl.exe:*:Enabled:Half-Life Launcher] -> File not found
"C:\Program Files\Steam\steamapps\ss0ul_climax@hotmail.com\team fortress 2\hl2.exe" -> C:\Program Files\Steam\steamapps\ss0ul_climax@hotmail.com\team fortress 2\hl2.exe [C:\Program Files\Steam\steamapps\ss0ul_climax@hotmail.com\team fortress 2\hl2.exe:*:Enabled:hl2] -> [2009/12/23 20:33:15 | 00,103,736 | ---- | M] ()
"C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe" -> C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe [C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade] -> File not found
"C:\Program Files\Ventrilo\Ventrilo.exe" -> C:\Program Files\Ventrilo\Ventrilo.exe [C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe] -> [2009/04/22 21:11:32 | 01,675,776 | ---- | M] (Flagship Industries, Inc.)
"C:\Program Files\Warcraft III\War3.exe" -> C:\Program Files\Warcraft III\War3.exe [C:\Program Files\Warcraft III\War3.exe:*:Enabled:Warcraft III] -> [2009/10/22 03:14:23 | 00,471,040 | ---- | M] (Blizzard Entertainment)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" -> C:\Program Files\Windows Live\Messenger\wlcsdk.exe [C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2009/02/06 18:21:00 | 00,583,024 | ---- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\dplaysvr.exe" -> C:\WINDOWS\System32\dplaysvr.exe [C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper] -> [2006/02/28 20:00:00 | 00,030,208 | ---- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\PnkBstrA.exe" -> C:\WINDOWS\System32\PnkBstrA.exe [C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA] -> [2008/07/06 22:43:04 | 00,066,872 | ---- | M] ()
"C:\WINDOWS\system32\PnkBstrB.exe" -> C:\WINDOWS\System32\PnkBstrB.exe [C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB] -> [2009/06/27 19:15:35 | 00,111,928 | ---- | M] ()
"F:\Program Files\mIRC\mirc.exe" -> F:\Program Files\mIRC\mirc.exe [F:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC] -> File not found
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2007/06/30 17:29:09 | 00,000,000 | ---- | M] ()
D:\autorun.inf [[AutoRun] | open=h0.exe | shell\open\Command=h0.exe | ] -> D:\autorun.inf [ NTFS ] -> [2010/01/03 20:55:38 | 00,000,051 | RHS- | M] ()
E:\autoplay.exe [MZ | ] -> E:\autoplay.exe [ CDFS ] -> [2003/05/19 02:54:20 | 00,061,440 | R--- | M] ()
E:\autorun.inf [[autorun] | open=autoplay.exe | icon=appicon.ico | | ] -> E:\autorun.inf [ CDFS ] -> [2003/02/12 15:01:48 | 00,000,050 | R--- | M] ()
F:\autorun.inf [[AutoRun] | open=h0.exe | shell\open\Command=h0.exe | ] -> F:\autorun.inf [ NTFS ] -> [2010/01/03 20:55:38 | 00,000,051 | RHS- | M] ()
G:\autorun.inf [[AutoRun] | open=h0.exe | shell\open\Command=h0.exe | ] -> G:\autorun.inf [ NTFS ] -> [2010/01/03 20:55:38 | 00,000,051 | RHS- | M] ()
H:\autorun.inf [[AutoRun] | open=h0.exe | shell\open\Command=h0.exe | ] -> H:\autorun.inf [ NTFS ] -> [2010/01/03 20:55:38 | 00,000,051 | RHS- | M] ()
J:\AUTORUN.INF [[autorun] | OPEN=SETUP.EXE | ICON=BW.ICO | ] -> J:\AUTORUN.INF [ CDFS ] -> [1998/12/13 22:43:32 | 00,000,040 | R--- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
[Files/Folders - Created Within 30 Days]
OTS.exe -> C:\Documents and Settings\Owner\My Documents\OTS.exe -> [2010/01/22 00:07:19 | 00,631,808 | ---- | C] (OldTimer Tools)
Config.Msi -> C:\Config.Msi -> [2010/01/15 21:44:51 | 00,000,000 | -HSD | C]
Adobe AIR -> C:\Program Files\Common Files\Adobe AIR -> [2010/01/15 21:43:43 | 00,000,000 | ---D | C]
NOS -> C:\Documents and Settings\All Users\Application Data\NOS -> [2010/01/15 21:42:09 | 00,000,000 | ---D | C]
UserData -> C:\Documents and Settings\Owner\UserData -> [2010/01/11 17:27:10 | 00,000,000 | --SD | C]
_OTM -> C:\_OTM -> [2010/01/11 00:27:51 | 00,000,000 | ---D | C]
OTM.exe -> C:\Documents and Settings\Owner\Desktop\OTM.exe -> [2010/01/11 00:26:37 | 00,480,256 | ---- | C] (OldTimer Tools)
ESET -> C:\Program Files\ESET -> [2010/01/08 00:47:23 | 00,000,000 | ---D | C]
TFC.exe -> C:\Documents and Settings\Owner\My Documents\TFC.exe -> [2010/01/07 18:04:49 | 00,410,624 | ---- | C] (OldTimer Tools)
Malwarebytes -> C:\Documents and Settings\Owner\Application Data\Malwarebytes -> [2010/01/07 02:19:50 | 00,000,000 | ---D | C]
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2010/01/07 02:19:45 | 00,038,224 | ---- | C] (Malwarebytes Corporation)
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2010/01/07 02:19:43 | 00,019,160 | ---- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2010/01/07 02:19:43 | 00,000,000 | ---D | C]
Malwarebytes -> C:\Documents and Settings\All Users\Application Data\Malwarebytes -> [2010/01/07 02:19:43 | 00,000,000 | ---D | C]
mbam-setup.exe -> C:\Documents and Settings\Owner\My Documents\mbam-setup.exe -> [2010/01/06 17:12:19 | 05,061,520 | ---- | C] (Malwarebytes Corporation )
rsit -> C:\rsit -> [2010/01/06 01:33:58 | 00,000,000 | ---D | C]
Downloads -> C:\Documents and Settings\Owner\My Documents\Downloads -> [2010/01/05 01:58:12 | 00,000,000 | ---D | C]
ERDNT -> C:\WINDOWS\ERDNT -> [2010/01/03 21:27:23 | 00,000,000 | ---D | C]
ERUNT -> C:\Program Files\ERUNT -> [2010/01/03 21:26:51 | 00,000,000 | ---D | C]
erunt-setup.exe -> C:\Documents and Settings\Owner\My Documents\erunt-setup.exe -> [2010/01/03 21:26:14 | 00,791,393 | ---- | C] (Lars Hederer )
Spybot - Search & Destroy -> C:\Program Files\Spybot - Search & Destroy -> [2010/01/03 20:19:20 | 00,000,000 | ---D | C]
Spybot - Search & Destroy -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy -> [2010/01/03 20:19:20 | 00,000,000 | ---D | C]
spybotsd162.exe -> C:\Documents and Settings\Owner\My Documents\spybotsd162.exe -> [2010/01/03 20:10:24 | 16,409,960 | ---- | C] (Safer Networking Limited )
Trend Micro -> C:\Program Files\Trend Micro -> [2010/01/03 20:05:04 | 00,000,000 | ---D | C]
HijackThisInstaller.exe -> C:\Documents and Settings\Owner\My Documents\HijackThisInstaller.exe -> [2010/01/03 20:04:59 | 00,812,344 | ---- | C] (Trend Micro Inc.)
Google -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google -> [2009/12/09 22:23:00 | 00,000,000 | ---D | M]
Google -> C:\Documents and Settings\LocalService\Local Settings\Application Data\Google -> [2009/12/09 22:18:52 | 00,000,000 | ---D | M]
Microsoft -> C:\Documents and Settings\NetworkService\Application Data\Microsoft -> [2008/07/11 22:37:20 | 00,000,000 | --SD | M]
Microsoft -> C:\Documents and Settings\LocalService\Application Data\Microsoft -> [2008/07/11 22:37:20 | 00,000,000 | --SD | M]
Microsoft -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft -> [2008/07/11 22:37:20 | 00,000,000 | ---D | M]
Microsoft -> C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft -> [2008/07/11 22:37:20 | 00,000,000 | ---D | M]
Apple -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple -> [2007/09/19 22:26:00 | 00,000,000 | ---D | M]
[Files/Folders - Modified Within 30 Days]
GoogleUpdateTaskMachineUA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job -> [2010/01/22 00:23:00 | 00,000,690 | ---- | M] ()
OTS.exe -> C:\Documents and Settings\Owner\My Documents\OTS.exe -> [2010/01/22 00:07:20 | 00,631,808 | ---- | M] (OldTimer Tools)
GoogleUpdateTaskMachineCore.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job -> [2010/01/21 22:23:00 | 00,000,686 | ---- | M] ()
incavi.avm -> C:\WINDOWS\System32\drivers\Avg\incavi.avm -> [2010/01/21 17:40:21 | 54,428,785 | ---- | M] ()
tablet.dat -> C:\WINDOWS\System32\tablet.dat -> [2010/01/21 17:38:22 | 00,012,941 | ---- | M] ()
nvapps.xml -> C:\WINDOWS\System32\nvapps.xml -> [2010/01/21 17:38:21 | 00,192,534 | ---- | M] ()
TempFile -> C:\WINDOWS\TempFile -> [2010/01/21 17:38:09 | 08,405,015 | ---- | M] ()
SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2010/01/21 17:37:57 | 00,000,006 | -H-- | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2010/01/21 17:37:56 | 00,002,048 | --S- | M] ()
NTUSER.DAT -> C:\Documents and Settings\Owner\NTUSER.DAT -> [2010/01/21 00:55:39 | 18,612,224 | -H-- | M] ()
ntuser.ini -> C:\Documents and Settings\Owner\ntuser.ini -> [2010/01/21 00:55:26 | 00,000,178 | -HS- | M] ()
microavi.avg -> C:\WINDOWS\System32\drivers\Avg\microavi.avg -> [2010/01/20 17:42:34 | 00,142,495 | ---- | M] ()
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2010/01/20 17:40:35 | 00,013,646 | ---- | M] ()
RETRO1.mp3 -> C:\Documents and Settings\Owner\My Documents\RETRO1.mp3 -> [2010/01/16 17:52:33 | 68,495,488 | ---- | M] ()
BANZAI.mp3 -> C:\Documents and Settings\Owner\My Documents\BANZAI.mp3 -> [2010/01/16 17:47:57 | 52,596,736 | ---- | M] ()
SecurityCheck.exe -> C:\Documents and Settings\Owner\My Documents\SecurityCheck.exe -> [2010/01/14 01:00:20 | 00,843,187 | ---- | M] ()
OTM.exe -> C:\Documents and Settings\Owner\Desktop\OTM.exe -> [2010/01/11 00:26:39 | 00,480,256 | ---- | M] (OldTimer Tools)
Flash_Disinfector.exe -> C:\Documents and Settings\Owner\Desktop\Flash_Disinfector.exe -> [2010/01/11 00:26:18 | 00,132,597 | ---- | M] ()
esetsmartinstaller_enu.exe -> C:\Documents and Settings\Owner\My Documents\esetsmartinstaller_enu.exe -> [2010/01/08 00:47:14 | 02,672,312 | ---- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2010/01/07 23:45:15 | 00,058,880 | ---- | M] ()
TFC.exe -> C:\Documents and Settings\Owner\My Documents\TFC.exe -> [2010/01/07 18:04:50 | 00,410,624 | ---- | M] (OldTimer Tools)
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation)
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2010/01/07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation)
Welcome_to_the_NHK_-_Puzzle.mp3 -> C:\Documents and Settings\Owner\My Documents\Welcome_to_the_NHK_-_Puzzle.mp3 -> [2010/01/06 20:42:12 | 05,955,712 | ---- | M] ()
mbam-setup.exe -> C:\Documents and Settings\Owner\My Documents\mbam-setup.exe -> [2010/01/06 17:12:24 | 05,061,520 | ---- | M] (Malwarebytes Corporation )
RSIT.exe -> C:\Documents and Settings\Owner\Desktop\RSIT.exe -> [2010/01/06 01:33:19 | 00,781,909 | ---- | M] ()
hosts -> C:\WINDOWS\System32\drivers\etc\hosts -> [2010/01/04 18:05:41 | 00,371,233 | R--- | M] ()
Spybot - Search & Destroy.lnk -> C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk -> [2010/01/03 21:31:19 | 00,000,963 | ---- | M] ()
ERUNT AutoBackup.lnk -> C:\Documents and Settings\Owner\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk -> [2010/01/03 21:27:07 | 00,000,767 | ---- | M] ()
NTREGOPT.lnk -> C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk -> [2010/01/03 21:26:55 | 00,000,611 | ---- | M] ()
ERUNT.lnk -> C:\Documents and Settings\Owner\Desktop\ERUNT.lnk -> [2010/01/03 21:26:54 | 00,000,592 | ---- | M] ()
erunt-setup.exe -> C:\Documents and Settings\Owner\My Documents\erunt-setup.exe -> [2010/01/03 21:26:21 | 00,791,393 | ---- | M] (Lars Hederer )
wininit.ini -> C:\WINDOWS\wininit.ini -> [2010/01/03 20:55:39 | 00,000,120 | ---- | M] ()
spybotsd162.exe -> C:\Documents and Settings\Owner\My Documents\spybotsd162.exe -> [2010/01/03 20:16:02 | 16,409,960 | ---- | M] (Safer Networking Limited )
HijackThis.lnk -> C:\Documents and Settings\Owner\Desktop\HijackThis.lnk -> [2010/01/03 20:05:05 | 00,001,734 | ---- | M] ()
HijackThisInstaller.exe -> C:\Documents and Settings\Owner\My Documents\HijackThisInstaller.exe -> [2010/01/03 20:04:59 | 00,812,344 | ---- | M] (Trend Micro Inc.)
anoataly.exe -> C:\anoataly.exe -> [2009/12/31 18:43:08 | 00,106,496 | RHS- | M] ()
utorrent.exe -> C:\Documents and Settings\Owner\Desktop\utorrent.exe -> [2009/12/23 14:30:43 | 00,289,584 | ---- | M] (BitTorrent, Inc.)
6 C:\Documents and Settings\Owner\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Owner\Local Settings\Temp\*.tmp ->
[Files - No Company Name]
BANZAI.mp3 -> C:\Documents and Settings\Owner\My Documents\BANZAI.mp3 -> [2010/01/16 17:32:26 | 52,596,736 | ---- | C] ()
RETRO1.mp3 -> C:\Documents and Settings\Owner\My Documents\RETRO1.mp3 -> [2010/01/16 17:31:31 | 68,495,488 | ---- | C] ()
SecurityCheck.exe -> C:\Documents and Settings\Owner\My Documents\SecurityCheck.exe -> [2010/01/14 01:00:20 | 00,843,187 | ---- | C] ()
Flash_Disinfector.exe -> C:\Documents and Settings\Owner\Desktop\Flash_Disinfector.exe -> [2010/01/11 00:26:14 | 00,132,597 | ---- | C] ()
esetsmartinstaller_enu.exe -> C:\Documents and Settings\Owner\My Documents\esetsmartinstaller_enu.exe -> [2010/01/08 00:47:00 | 02,672,312 | ---- | C] ()
Welcome_to_the_NHK_-_Puzzle.mp3 -> C:\Documents and Settings\Owner\My Documents\Welcome_to_the_NHK_-_Puzzle.mp3 -> [2010/01/06 20:41:50 | 05,955,712 | ---- | C] ()
RSIT.exe -> C:\Documents and Settings\Owner\Desktop\RSIT.exe -> [2010/01/06 01:33:13 | 00,781,909 | ---- | C] ()
ERUNT AutoBackup.lnk -> C:\Documents and Settings\Owner\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk -> [2010/01/03 21:27:07 | 00,000,767 | ---- | C] ()
NTREGOPT.lnk -> C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk -> [2010/01/03 21:26:55 | 00,000,611 | ---- | C] ()
ERUNT.lnk -> C:\Documents and Settings\Owner\Desktop\ERUNT.lnk -> [2010/01/03 21:26:54 | 00,000,592 | ---- | C] ()
wininit.ini -> C:\WINDOWS\wininit.ini -> [2010/01/03 20:55:39 | 00,000,120 | ---- | C] ()
Spybot - Search & Destroy.lnk -> C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk -> [2010/01/03 20:19:29 | 00,000,963 | ---- | C] ()
HijackThis.lnk -> C:\Documents and Settings\Owner\Desktop\HijackThis.lnk -> [2010/01/03 20:05:05 | 00,001,734 | ---- | C] ()
anoataly.exe -> C:\anoataly.exe -> [2009/12/31 18:42:55 | 00,106,496 | RHS- | C] ()
{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini -> C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini -> [2009/09/20 19:29:21 | 00,000,262 | ---- | C] ()
AgCPanelTraditionalChinese.dll -> C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll -> [2008/06/11 09:02:34 | 00,058,648 | ---- | C] ()
AgCPanelSwedish.dll -> C:\WINDOWS\System32\AgCPanelSwedish.dll -> [2008/06/11 09:02:34 | 00,058,648 | ---- | C] ()
AgCPanelSpanish.dll -> C:\WINDOWS\System32\AgCPanelSpanish.dll -> [2008/06/11 09:02:34 | 00,058,648 | ---- | C] ()
AgCPanelSimplifiedChinese.dll -> C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll -> [2008/06/11 09:02:34 | 00,058,648 | ---- | C] ()
AgCPanelPortugese.dll -> C:\WINDOWS\System32\AgCPanelPortugese.dll -> [2008/06/11 09:02:34 | 00,058,648 | ---- | C] ()
AgCPanelKorean.dll -> C:\WINDOWS\System32\AgCPanelKorean.dll -> [2008/06/11 09:02:34 | 00,058,648 | ---- | C] ()
AgCPanelJapanese.dll -> C:\WINDOWS\System32\AgCPanelJapanese.dll -> [2008/06/11 09:02:32 | 00,058,648 | ---- | C] ()
AgCPanelGerman.dll -> C:\WINDOWS\System32\AgCPanelGerman.dll -> [2008/06/11 09:02:32 | 00,058,648 | ---- | C] ()
AgCPanelFrench.dll -> C:\WINDOWS\System32\AgCPanelFrench.dll -> [2008/06/11 09:02:32 | 00,058,648 | ---- | C] ()
physxcudart_20.dll -> C:\WINDOWS\System32\physxcudart_20.dll -> [2008/06/05 08:58:26 | 00,197,912 | ---- | C] ()
BlendSettings.ini -> C:\WINDOWS\BlendSettings.ini -> [2008/01/20 17:24:21 | 00,000,023 | ---- | C] ()
ZPORT4AS.dll -> C:\WINDOWS\System32\ZPORT4AS.dll -> [2007/11/08 13:50:40 | 00,011,776 | ---- | C] ()
PnkBstrK.sys -> C:\WINDOWS\System32\drivers\PnkBstrK.sys -> [2007/09/14 13:15:52 | 00,139,152 | ---- | C] ()
game.ini -> C:\WINDOWS\game.ini -> [2007/09/14 13:15:08 | 00,000,319 | ---- | C] ()
NPSWF32.dll -> C:\WINDOWS\System32\NPSWF32.dll -> [2007/08/21 17:39:55 | 02,463,976 | ---- | C] ()
BASSMOD.dll -> C:\WINDOWS\System32\BASSMOD.dll -> [2007/08/20 01:10:09 | 00,034,308 | ---- | C] ()
haspdos.sys -> C:\WINDOWS\System32\haspdos.sys -> [2007/08/12 00:43:30 | 00,000,383 | ---- | C] ()
sptd.sys -> C:\WINDOWS\System32\drivers\sptd.sys -> [2007/07/17 23:46:16 | 00,682,232 | ---- | C] ()
NeroDigital.ini -> C:\WINDOWS\NeroDigital.ini -> [2007/07/08 23:00:17 | 00,000,116 | ---- | C] ()
kvirc-3.2.0.ini -> C:\WINDOWS\kvirc-3.2.0.ini -> [2007/07/01 23:12:02 | 00,000,075 | ---- | C] ()
RtlCPAPI.dll -> C:\WINDOWS\System32\RtlCPAPI.dll -> [2007/06/30 18:06:31 | 00,143,360 | R--- | C] ()
nvwdmcpl.dll -> C:\WINDOWS\System32\nvwdmcpl.dll -> [2007/04/12 23:44:00 | 01,703,936 | ---- | C] ()
nview.dll -> C:\WINDOWS\System32\nview.dll -> [2007/04/12 23:44:00 | 01,486,848 | ---- | C] ()
nvwimg.dll -> C:\WINDOWS\System32\nvwimg.dll -> [2007/04/12 23:44:00 | 01,019,904 | ---- | C] ()
nvshell.dll -> C:\WINDOWS\System32\nvshell.dll -> [2007/04/12 23:44:00 | 00,466,944 | ---- | C] ()
nvnt4cpl.dll -> C:\WINDOWS\System32\nvnt4cpl.dll -> [2007/04/12 23:44:00 | 00,286,720 | ---- | C] ()
ieencode.dll -> C:\WINDOWS\System32\ieencode.dll -> [2006/02/28 20:00:00 | 00,081,920 | ---- | C] ()
RGSS102J.dll -> C:\WINDOWS\System32\RGSS102J.dll -> [2005/08/30 00:00:00 | 00,781,312 | ---- | C] ()
RGSS102E.dll -> C:\WINDOWS\System32\RGSS102E.dll -> [2005/08/30 00:00:00 | 00,778,752 | ---- | C] ()
RGSS100J.dll -> C:\WINDOWS\System32\RGSS100J.dll -> [2005/08/30 00:00:00 | 00,771,584 | ---- | C] ()
msbuaas.dll -> C:\WINDOWS\System32\msbuaas.dll -> [2004/12/05 04:52:19 | 00,006,144 | ---- | C] ()
nl_msgs.dll -> C:\WINDOWS\System32\nl_msgs.dll -> [2003/10/13 15:09:10 | 00,049,152 | ---- | C] ()
nl_msgc.dll -> C:\WINDOWS\System32\nl_msgc.dll -> [2003/10/13 15:09:02 | 00,065,536 | ---- | C] ()
[Files/Folders - Unicode - All]
C:\????????2.torrent -> C:\人妻コスプレ喫茶2.torrent -> [2008/05/14 20:18:46 | 00,070,508 | ---- | M] ()
C:\????????2.torrent -> C:\人妻コスプレ喫茶2.torrent -> [2008/05/14 20:18:51 | 00,070,508 | ---- | C] ()
C:\Documents and Settings\Owner\Desktop\[2000fun@halofish1991][080820]???? [????Frontier] May'n & ???.rar -> C:\Documents and Settings\Owner\Desktop\[2000fun@halofish1991][080820]ライオン [マクロスFrontier] May'n & 中島愛.rar -> [2008/08/18 16:31:07 | 29,455,957 | ---- | C] ()
C:\Documents and Settings\Owner\Desktop\[2000fun@halofish1991][080820]???? [????Frontier] May'n & ???.rar -> C:\Documents and Settings\Owner\Desktop\[2000fun@halofish1991][080820]ライオン [マクロスFrontier] May'n & 中島愛.rar -> [2008/08/18 16:34:47 | 29,455,957 | ---- | M] ()
C:\(???5)(????)[efs] ????? (tta+cue).rar -> C:\(例大祭5)(同人音楽)[efs] 夜桜幻想郷 (tta+cue).rar -> [2009/09/23 00:13:33 | 24,856,9714 | ---- | C] ()
C:\(???5)(????)[efs] ????? (tta+cue).rar -> C:\(例大祭5)(同人音楽)[efs] 夜桜幻想郷 (tta+cue).rar -> [2009/09/23 01:31:31 | 24,856,9714 | ---- | M] ()
C:\[Audio-4U] [????] (M3-23) [efs] Atomic Heat (flac+cue+jpg) -> C:\[Audio-4U] [同人音楽] (M3-23) [efs] Atomic Heat (flac+cue+jpg) -> [2009/09/23 13:26:46 | 00,000,000 | ---D | C]
C:\[Audio-4U] [????] (M3-23) [efs] Atomic Heat (flac+cue+jpg) -> C:\[Audio-4U] [同人音楽] (M3-23) [efs] Atomic Heat (flac+cue+jpg) -> [2009/09/24 19:16:59 | 00,000,000 | ---D | M]
< End of report >