========== Chrome ==========
CHR - default_search_provider: facemoods (Enabled)
CHR - default_search_provider: search_url =
http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4
CHR - default_search_provider: suggest_url =
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\abc\AppData\Local\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\abc\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\abc\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\abc\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: OGPlanet Game Launcher Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npOGPPlugin.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: ncsoft login launcher module (Enabled) = C:\Program Files\plaync\NCPlugin\npncllm.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonEU\NGM\npNxGameeu.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\Nexon\NGM\npNxGame.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\abc\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: OGPlanet Game Plugin (Enabled) = C:\windows\system32\npOGPPlugin.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Collusion for Chrome = C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ganlifbpkcplnldliibcbegplfmcfigp\1.5.6_0\
CHR - Extension: AdBlock = C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.36_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/08 05:32:47 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi0.dll (Conduit Ltd.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\abc\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll (Trend Media Group)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\tbXfi0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [APLangApp] C:\Program Files\AnyPC Client\APLangApp.exe (DoctorSoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [fsn] C:\Program Files\Phoenix Technologies Ltd\FailSafe\FailSafeNotifier.exe ()
O4 - HKLM..\Run: [GamingMouse] C:\Program Files\GamingMouse\hid.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ProxyCap] C:\Program Files\Proxy Labs\ProxyCap\pcapui.exe (Proxy Labs)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [Xfire Music] C:\Program Files\Xfire\xfiremusic.exe ()
O4 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001..\Run: [Akamai NetSession Interface] C:\Users\abc\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001..\Run: [DS3 Tool] C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe (
www.motioninjoy.com)
O4 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O4 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001..\Run: [SpeedItUpEX] C:\Program Files\Speeditup Free\SpeedItUp.exe (MicroSmarts LLC.)
O4 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\abc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Creative Element Power Tools Startup.lnk = C:\Program Files\Creative Element Power Tools\Startup.exe (Creative Element)
O4 - Startup: C:\Users\abc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download All By FlashGet3 - C:\Users\abc\AppData\Roaming\FlashGetBHO\GetAllUrl.htm ()
O8 - Extra context menu item: Download By FlashGet3 - C:\Users\abc\AppData\Roaming\FlashGetBHO\GetUrl.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube Download - C:\Users\abc\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\abc\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\windows\System32\pcapwsp.dll (Proxy Labs)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - pcapwsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - pcapwsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - pcapwsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - pcapwsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - pcapwsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - pcapwsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - pcapwsp.dll File not found
O15 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001\..Trusted Domains: crunchyroll.com ([www] https in Trusted sites)
O15 - HKU\S-1-5-21-1871111397-3539990770-1974983793-1001\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downl...-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5}
http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab (Keynote Connector Launcher 2)
O16 - DPF: {51B1D5ED-67DC-43F0-A3F8-8502F1A5E404}
http://nprotect.plaync.co.kr/nProtect/netizen2007/ncsoft/npstarter.cab (nPCom2 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {BCF0F4D5-A864-4B98-BD41-72AAF2680A0C}
http://windybeta.xcdnplus.co.kr/windydev/sd/pcinfo/cab/pcCheck.cab (SysInfoCom Class)
O16 - DPF: {C1143E84-B2B1-473B-9F20-E62DD754FCAF}
http://auth.siren24.com/infovine/VineTransfer.cab (VineTransfer Control)
O16 - DPF: {C8223F3A-1420-4245-88F2-D874FC081574}
https://auth.siren24.com/MagicLineMBX/lib/MagicLineMBX.cab (MagicLineMBX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}
http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab (SysInfo Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1C212B5B-CEE6-469E-AD26-EA4B3BFE1BFE}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FAD741A8-E2ED-4452-BC35-215CE88B041D}: DhcpNameServer = 10.78.48.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/07/08 20:30:40 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\abc\Desktop\OTL.exe
[2012/07/08 16:48:23 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{2AB3CFFD-B8C0-4631-8C11-267C419AE771}
[2012/07/08 16:47:45 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{C6CDBC40-04E4-4D21-8908-3EAA436F4E4C}
[2012/07/08 12:03:38 | 000,000,000 | ---D | C] -- C:\FRST
[2012/07/08 11:17:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/07/08 11:17:03 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/07/08 11:08:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/07/08 11:08:38 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012/07/08 05:44:03 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/07/08 05:31:09 | 000,000,000 | ---D | C] -- C:\microsoft
[2012/07/08 05:29:08 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\temp
[2012/07/08 04:55:32 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2012/07/08 04:55:32 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2012/07/08 04:55:32 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2012/07/08 04:52:42 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/08 04:52:14 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2012/07/08 04:47:24 | 004,574,136 | R--- | C] (Swearware) -- C:\Users\abc\Desktop\ComboFix.exe
[2012/07/08 03:26:40 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{222753AC-2B62-443F-945F-E25D32EA28F2}
[2012/07/08 03:26:17 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{C0494E54-E2D6-4D37-9D8D-A7A75799FDBE}
[2012/07/08 02:11:52 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\abc\Desktop\dds.scr
[2012/07/08 01:23:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/08 01:23:55 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2012/07/08 01:23:55 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/07/06 23:34:01 | 000,000,000 | -H-D | C] -- C:\windows\PIF
[2012/07/05 17:47:32 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{316DE079-8561-41E8-8C6B-8D0538722CA4}
[2012/07/05 17:47:07 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{437C7BAC-6C4E-44FF-A0C1-3874E0050487}
[2012/07/03 16:02:13 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{FA1BF6D0-9FD7-4F1C-B559-3858C8234786}
[2012/07/03 16:01:59 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{053E49F7-DCA3-4683-84D4-D75CB5FE5CAF}
[2012/07/03 15:05:08 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\Macromedia
[2012/07/03 12:00:46 | 000,000,000 | -HSD | C] -- C:\windows\System32\%APPDATA%
[2012/07/03 07:50:13 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{07A7090A-D502-484D-B74C-B8EA458005EA}
[2012/07/03 07:49:54 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{DCB51446-C936-454A-9C19-10E677B52B6B}
[2012/07/02 01:50:48 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{FD5DA32B-0CEC-440A-8A3F-C2E4218072BF}
[2012/06/30 14:03:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2012/06/30 14:03:51 | 000,000,000 | ---D | C] -- C:\Program Files\Core Temp
[2012/06/30 07:17:58 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{5B5F745D-F506-45A5-B610-F2CA95822EB5}
[2012/06/29 06:32:13 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{831F87B7-737E-4174-8957-42C378BC2C7D}
[2012/06/29 06:31:48 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{98CBB1B6-D6DC-4A2E-9598-58B2AE521D81}
[2012/06/28 21:23:07 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{1EBE06BA-4C6B-4B63-8AC3-96C7F1A85EDC}
[2012/06/27 19:27:27 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{23FC9A10-8B9A-49CA-ADA3-4AD0954EC106}
[2012/06/27 01:59:23 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{946E2F39-B6B2-4113-AB69-EC73492B5F00}
[2012/06/27 01:59:08 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{B373A2AF-03E3-4078-B7EE-C10686B1B56A}
[2012/06/26 16:37:41 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{AA99DCDC-F31E-4517-8B12-F1F1F9CA711A}
[2012/06/26 15:16:13 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{7B18988A-BA62-49F2-8558-FCF0D21B6D5E}
[2012/06/25 19:23:25 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{083F5444-EFCF-48D2-8EBF-4AB54A617A6B}
[2012/06/23 11:38:49 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{F3EE9F65-412A-4A67-AF00-60817FFFBD44}
[2012/06/23 11:38:27 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{64DAE847-1049-4A5E-ABC9-A95F099CFA88}
[2012/06/23 08:02:47 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{A71CED70-26CC-4A81-BFAD-BE70695370BC}
[2012/06/23 00:43:38 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{DED5C935-8FE9-4B33-B3F3-1EC0E27DBD42}
[2012/06/23 00:43:15 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{26E1E661-4032-4091-A817-EDCB4B9263EF}
[2012/06/22 06:38:40 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{182ECDEB-6309-4641-B1FE-8AC0511C2B60}
[2012/06/20 15:00:22 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{0B080FC6-3815-4637-B2E9-B84D1B266162}
[2012/06/20 15:00:11 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{74828AD5-A6A9-4FBB-ACA0-087501851773}
[2012/06/20 14:22:28 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{C1E36BE1-CFF8-43E0-B49D-28F250BDF07C}
[2012/06/20 14:22:07 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{CD08AEBB-797B-4030-B463-D7F5BD18678F}
[2012/06/20 13:26:01 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{5026640F-C7AB-4897-A836-D9F90B8AB64F}
[2012/06/20 13:25:38 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{FBE1DCF6-C9DD-4A98-8FCD-4B7876FEFDA4}
[2012/06/19 10:02:56 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{9A00AFC4-B8F8-4CD0-AF48-1D656BC687C3}
[2012/06/18 21:59:22 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{001B426A-7AEE-464F-9187-771967E1F799}
[2012/06/17 23:57:48 | 000,056,288 | ---- | C] ((주)인포바인) -- C:\windows\System32\VineTransfer.ocx
[2012/06/17 23:57:48 | 000,000,000 | ---D | C] -- C:\Program Files\INFovine
[2012/06/17 23:57:47 | 000,048,104 | ---- | C] ((주)인포바인) -- C:\windows\System32\UbiKeyUninstall.exe
[2012/06/17 23:57:47 | 000,039,904 | ---- | C] ((주)인포바인) -- C:\windows\System32\UbiKeyWin32.dll
[2012/06/17 23:57:47 | 000,039,896 | ---- | C] ((주)인포바인) -- C:\windows\System32\UbiKey.dll
[2012/06/17 23:56:17 | 000,000,000 | ---D | C] -- C:\Program Files\DreamSecurity
[2012/06/17 22:29:10 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\com.tfhz.air.player
[2012/06/15 16:47:30 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{1B5AEE4B-1589-4550-89DF-D0F2B07DFE78}
[2012/06/14 02:55:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2012
[2012/06/14 02:55:13 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2012
[2012/06/14 02:48:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012/06/14 02:48:20 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012/06/14 02:34:14 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\Wireshark
[2012/06/14 02:01:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
[2012/06/14 02:01:20 | 000,000,000 | ---D | C] -- C:\Program Files\WinPcap
[2012/06/14 02:00:47 | 000,000,000 | ---D | C] -- C:\Program Files\Wireshark
[2012/06/12 11:09:34 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{9C345C14-32FA-44E3-BF0E-217C3AE8C6CC}
[2012/06/12 11:09:03 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{AC738615-5F55-4994-A8D8-4E64DFB1ED24}
[2012/06/11 23:44:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LAV Filters
[2012/06/11 23:44:03 | 000,000,000 | ---D | C] -- C:\Program Files\LAV Filters
[2012/06/11 06:10:25 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{EEE1F929-149C-4197-9551-0DCD26AFF15A}
[2012/06/11 06:10:05 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{9DE28C6D-38B1-4CF4-B354-1FDFCA67155E}
[2012/06/10 22:37:38 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{721354D2-2844-42D0-AB31-F4435C2B4B6C}
[2012/06/10 22:37:20 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{2B1FCF07-2BA9-48F7-937A-BA79C80D5F0C}
[2012/06/08 23:17:36 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{F505F31F-871D-4563-AA90-5B4AAEC2D2CD}
[2012/06/08 23:17:12 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{383066ED-5FD6-4ECE-A5F7-03F80D401E85}
[2012/06/08 23:11:25 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{D1161B74-82AA-4EB7-ADEA-50FC78833B4A}
[2012/06/08 23:11:02 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{454C83E5-0F38-41A0-9548-B6D0605C4BFE}
[2012/06/08 22:58:40 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{8BFAF051-4738-4C2A-8A29-31633EE205B5}
[2012/06/08 22:58:17 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{97E292A8-00D6-4ECB-8568-04970597C97D}
[2012/06/08 21:12:10 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{3A2799F4-FCD9-4372-B274-679E7FD6F794}
[2012/06/08 21:11:48 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{DB2E92B5-0176-4183-B287-33DB674CEE41}
[2012/06/08 21:09:47 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{D704EFE8-56E5-4DC4-91CF-90A64F5E5987}
[2012/06/08 21:09:24 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\{02E8258D-CB0C-4C4C-9F68-F132F94C2BE0}
[31 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\Program Files\Common Files\*.tmp files -> C:\Program Files\Common Files\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/08 20:34:01 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/07/08 20:30:41 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\abc\Desktop\OTL.exe
[2012/07/08 20:06:01 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1871111397-3539990770-1974983793-1001UA.job
[2012/07/08 19:59:01 | 000,000,886 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/08 15:08:40 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/08 15:08:40 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/08 14:05:29 | 000,000,882 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/08 08:06:03 | 000,000,856 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1871111397-3539990770-1974983793-1001Core.job
[2012/07/08 05:32:47 | 000,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[2012/07/08 05:31:45 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/07/08 04:47:51 | 004,574,136 | R--- | M] (Swearware) -- C:\Users\abc\Desktop\ComboFix.exe
[2012/07/08 02:11:52 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\abc\Desktop\dds.scr
[2012/07/08 01:54:50 | 000,302,592 | ---- | M] () -- C:\Users\abc\Desktop\pojybror.exe
[2012/07/08 01:23:56 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/07 20:39:54 | 000,003,352 | ---- | M] () -- C:\bootsqm.dat
[2012/07/07 19:40:48 | 000,676,672 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2012/07/07 19:40:48 | 000,131,056 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2012/07/03 07:31:19 | 003,784,248 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2012/06/27 01:56:11 | 000,000,000 | ---- | M] () -- C:\windows\System32\cd.dat
[2012/06/15 23:12:09 | 000,000,621 | ---- | M] () -- C:\Users\abc\Last session abc.prj
[2012/06/14 02:01:00 | 000,001,712 | ---- | M] () -- C:\Users\abc\Application Data\Microsoft\Internet Explorer\Quick Launch\Wireshark.lnk
[2012/06/09 00:51:57 | 000,002,002 | ---- | M] () -- C:\Users\abc\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[31 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\Program Files\Common Files\*.tmp files -> C:\Program Files\Common Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/08 04:55:32 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2012/07/08 04:55:32 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2012/07/08 04:55:32 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2012/07/08 04:55:32 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2012/07/08 04:55:32 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2012/07/08 01:54:49 | 000,302,592 | ---- | C] () -- C:\Users\abc\Desktop\pojybror.exe
[2012/07/08 01:23:56 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/07 20:39:54 | 000,003,352 | ---- | C] () -- C:\bootsqm.dat
[2012/06/27 01:56:11 | 000,000,000 | ---- | C] () -- C:\windows\System32\cd.dat
[2012/06/14 02:55:37 | 000,002,145 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2012.lnk
[2012/06/14 02:01:00 | 000,001,712 | ---- | C] () -- C:\Users\abc\Application Data\Microsoft\Internet Explorer\Quick Launch\Wireshark.lnk
[2012/06/14 02:01:00 | 000,001,700 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
[2012/06/01 21:42:01 | 000,000,256 | ---- | C] () -- C:\windows\System32\pool.bin
[2012/05/03 03:54:46 | 000,042,392 | ---- | C] () -- C:\windows\System32\xfcodec.dll
[2012/04/28 02:02:50 | 000,000,621 | ---- | C] () -- C:\Users\abc\Last session abc.prj
[2012/03/05 03:02:34 | 000,000,342 | ---- | C] () -- C:\Users\abc\openvpn-connect.json
[2012/02/17 14:15:08 | 000,315,392 | ---- | C] ( ) -- C:\windows\System32\sbcrreag.dll
[2012/01/13 09:03:54 | 000,000,064 | ---- | C] () -- C:\windows\GPlrLanc.dat
[2011/12/23 16:39:59 | 000,020,864 | ---- | C] () -- C:\windows\System32\drivers\msfilter.sys
[2011/10/13 12:31:48 | 000,004,096 | ---- | C] ( ) -- C:\windows\System32\IGFXDEVLib.dll
[2011/10/13 12:30:24 | 000,000,268 | ---- | C] () -- C:\windows\System32\GfxUI.exe.config
[2011/07/05 01:17:48 | 000,230,752 | ---- | C] () -- C:\windows\patchw32.dll
[2011/07/05 01:17:47 | 000,118,176 | ---- | C] () -- C:\windows\patchw.dll
[2011/06/28 13:10:43 | 000,007,605 | ---- | C] () -- C:\Users\abc\AppData\Local\Resmon.ResmonCfg
[2011/05/31 07:39:50 | 000,058,368 | ---- | C] () -- C:\windows\System32\bdmpegv.dll
[2011/05/31 07:38:18 | 000,015,360 | ---- | C] () -- C:\windows\System32\bdmjpeg.dll
[2011/04/30 07:03:29 | 000,000,532 | ---- | C] () -- C:\windows\eReg.dat
[2011/03/15 08:29:48 | 000,139,264 | ---- | C] () -- C:\windows\System32\nsldap32v50.dll
[2011/03/07 07:18:02 | 000,028,496 | ---- | C] () -- C:\windows\System32\SmartDefragBootTime.exe
[2011/03/07 07:18:02 | 000,015,672 | ---- | C] () -- C:\windows\System32\drivers\SmartDefragDriver.sys
[2011/02/27 20:22:06 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011/02/09 05:44:22 | 000,000,565 | ---- | C] () -- C:\Users\abc\AppData\Roaming\myMPQ.ini
[2011/02/02 14:53:04 | 000,109,056 | -H-- | C] () -- C:\windows\ozddyeaelgyuanfj.exe
[2011/02/02 13:46:19 | 000,002,282 | ---- | C] () -- C:\Users\abc\AppData\Local\TempGUIPic.jpg
[2011/02/02 08:10:44 | 000,039,424 | ---- | C] () -- C:\windows\System32\rpiAccessProcess.dll
[2010/10/24 01:03:39 | 000,008,704 | ---- | C] () -- C:\Users\abc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/20 14:20:25 | 000,000,014 | ---- | C] () -- C:\windows\System32\systeminfo.dll
[2010/10/02 16:59:32 | 000,108,032 | ---- | C] () -- C:\windows\System32\ff_vfw.dll
[2010/07/24 06:26:54 | 000,138,328 | ---- | C] () -- C:\windows\System32\drivers\PnkBstrK.sys
[2010/07/24 06:26:32 | 000,214,816 | ---- | C] () -- C:\windows\System32\PnkBstrB.exe
[2010/07/24 06:26:20 | 000,075,064 | ---- | C] () -- C:\windows\System32\PnkBstrA.exe
[2010/07/15 07:33:38 | 000,110,592 | ---- | C] () -- C:\windows\System32\suppdll.dll
[2010/07/15 07:33:38 | 000,035,363 | ---- | C] () -- C:\windows\System32\windrvNT.sys
[2010/07/15 07:17:22 | 000,180,224 | ---- | C] () -- C:\windows\System32\WinVd32.sys
[2010/07/15 07:17:15 | 000,007,680 | ---- | C] () -- C:\windows\System32\WinFLsrv.exe
[2010/06/14 18:28:36 | 000,002,365 | ---- | C] () -- C:\Users\abc\AppData\Local\aguans.exe
[2010/06/12 15:36:27 | 000,002,365 | ---- | C] () -- C:\Users\abc\AppData\Local\mtrygelk.exe
[2010/06/08 12:29:06 | 000,002,360 | ---- | C] () -- C:\Users\abc\AppData\Local\hblffa.exe
[2010/06/07 15:28:32 | 000,002,365 | ---- | C] () -- C:\Users\abc\AppData\Local\vhowop.exe
[2010/06/01 18:09:58 | 000,002,365 | ---- | C] () -- C:\Users\abc\AppData\Local\tafmlza.exe
[2010/05/30 07:42:37 | 000,002,360 | ---- | C] () -- C:\Users\abc\AppData\Local\opqrsabc.exe
[2010/05/29 00:53:52 | 000,002,365 | ---- | C] () -- C:\Users\abc\AppData\Local\xbmeit.exe
[2010/05/23 20:16:11 | 000,012,670 | ---- | C] () -- C:\Users\abc\.recently-used.xbel
[2010/05/22 18:49:36 | 000,002,365 | ---- | C] () -- C:\Users\abc\AppData\Local\ydwbbg.exe
[2010/05/14 03:16:40 | 000,002,365 | ---- | C] () -- C:\Users\abc\AppData\Local\frdvhzlv.exe
[2010/05/08 18:00:04 | 000,002,365 | ---- | C] () -- C:\Users\abc\AppData\Local\accfzbvx.exe
[2010/04/22 23:09:01 | 000,000,090 | ---- | C] () -- C:\Users\abc\AppData\Local\frdepbt.bat
[2010/04/09 12:31:45 | 000,000,088 | ---- | C] () -- C:\Users\abc\AppData\Local\nffee.bat
========== LOP Check ==========
[2012/02/06 22:07:18 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\IObit
[2012/02/06 22:07:18 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\IObit
[2012/02/16 04:22:03 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Atsaa
[2012/02/17 01:27:52 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Azureus
[2012/01/08 11:02:01 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\BitTorrent
[2011/12/30 17:25:30 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Blaze
[2010/12/17 15:25:51 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\CoreCodec
[2011/10/14 21:40:27 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\DAEMON Tools Lite
[2012/02/16 04:26:38 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\IObit
[2012/02/16 10:06:32 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Izbin
[2012/02/16 10:06:32 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Lereeh
[2012/01/14 19:55:17 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\MotioninJoy
[2011/09/16 19:03:01 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\NVD
[2010/07/26 01:59:27 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Opera
[2012/06/01 20:06:50 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Research In Motion
[2011/10/13 18:37:50 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\SoftGrid Client
[2011/10/13 18:30:12 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Template
[2012/06/14 18:41:09 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\TuneUp Software
[2012/06/24 11:55:16 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\uTorrent
[2012/07/08 01:08:43 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\1E754
[2012/02/13 03:48:21 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\54307
[2012/01/13 07:48:43 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Azureus
[2012/04/13 11:51:02 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\BITS
[2012/05/06 18:14:39 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\BitTorrent
[2011/12/23 16:42:20 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Blaze
[2012/02/29 09:55:34 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\BSplayer
[2010/03/24 00:34:56 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\BSplayer Pro
[2011/07/05 03:19:08 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\BugTrap Console Test108
[2011/06/07 20:02:36 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/20 18:26:51 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2011/06/07 17:11:46 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/06/17 22:29:10 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\com.tfhz.air.player
[2010/10/20 14:31:51 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\CoreCodec
[2012/01/25 03:48:47 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\CoreFTP
[2012/04/25 06:27:09 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\DAEMON Tools Lite
[2011/07/23 03:16:53 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\DVDVideoSoft
[2011/07/22 03:12:02 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/05/24 17:53:34 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\FlashGet
[2010/05/24 17:53:26 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\FlashGetBHO
[2012/05/16 09:45:19 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\fltk.org
[2010/07/04 13:46:56 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\FOG Downloader
[2012/02/14 05:08:05 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Foro
[2010/04/21 18:28:35 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Free Mp3 Wma Ogg Converter
[2010/04/09 12:04:09 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Games-Attack
[2010/11/24 02:54:41 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\GetRightToGo
[2012/05/22 12:24:45 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\globalip
[2012/01/25 02:59:53 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\IObit
[2011/05/26 19:57:53 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Keynote Systems
[2010/07/16 13:39:30 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\LolClient
[2010/03/25 20:49:32 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2012/06/01 22:56:23 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\LolClient2
[2011/02/02 01:02:05 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Mael
[2010/09/11 04:04:04 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\mkvtoolnix
[2011/07/27 21:01:48 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\MotioninJoy
[2011/02/02 01:11:29 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Notepad++
[2010/06/06 10:54:23 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\NVD
[2010/07/03 23:25:19 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Opera
[2012/06/01 20:17:39 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Research In Motion
[2012/02/14 15:56:54 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Riaz
[2012/04/25 05:19:18 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\SEGA
[2011/10/14 21:47:35 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\SoftGrid Client
[2010/06/17 15:35:48 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Synthesia
[2011/01/24 00:46:41 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\SystemRequirementsLab
[2010/12/16 17:23:33 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\TeamViewer
[2010/06/06 10:54:23 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\TP
[2012/06/14 02:55:22 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\TuneUp Software
[2012/01/05 04:01:51 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Ubisoft
[2012/07/08 20:44:46 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\uTorrent
[2012/02/16 05:49:43 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Uzoswy
[2012/06/14 02:34:14 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\Wireshark
[2012/01/13 14:27:13 | 000,000,000 | ---D | M] -- C:\Users\abc\AppData\Roaming\X-Chat 2
[2012/07/07 19:34:06 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >