OTL Part I
OTL logfile created on: 5/11/2011 7:26:03 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Lin Yue\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 612.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.76 Gb Total Space | 23.72 Gb Free Space | 30.89% Space Free | Partition Type: NTFS
Drive D: | 22.96 Gb Total Space | 9.31 Gb Free Space | 40.57% Space Free | Partition Type: NTFS
Computer Name: LINYUE-FPC | User Name: Lin Yue | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/11 19:25:17 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lin Yue\Desktop\OTL.exe
PRC - [2011/05/04 07:42:12 | 024,172,208 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Lin Yue\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2011/03/13 11:45:14 | 000,148,520 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
PRC - [2011/03/13 11:41:50 | 000,159,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
PRC - [2011/03/13 11:41:36 | 000,165,000 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
PRC - [2011/03/12 19:07:00 | 001,306,216 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
PRC - [2010/05/18 18:05:27 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/04/01 17:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2010/03/25 10:50:00 | 002,516,296 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2009/09/12 23:09:10 | 000,103,768 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\concentr.exe
PRC - [2009/09/12 23:09:04 | 000,550,232 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\wfcrun32.exe
PRC - [2008/04/14 08:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/03/05 21:58:16 | 004,554,752 | ---- | M] () -- C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
PRC - [2006/08/02 00:38:30 | 000,802,816 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2006/08/02 00:32:44 | 000,696,320 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2006/08/02 00:27:54 | 000,479,232 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2006/07/22 10:10:08 | 000,233,472 | R--- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\SSUtility\FJSSDMN.exe
PRC - [2006/03/09 11:11:54 | 000,090,112 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
PRC - [2006/01/27 21:17:44 | 000,073,728 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
PRC - [2005/11/18 20:19:14 | 000,331,776 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\updnavi\updnavi.exe
PRC - [2005/11/04 15:48:22 | 000,061,440 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
PRC - [2005/11/04 02:35:18 | 001,052,672 | ---- | M] (AuthenTec, Inc.) -- C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
PRC - [2005/07/21 14:21:28 | 000,242,688 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
PRC - [2005/06/16 11:11:42 | 000,049,152 | ---- | M] () -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
PRC - [1999/02/28 02:32:52 | 000,124,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mdm.exe
========== Modules (SafeList) ==========
MOD - [2011/05/11 19:25:17 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lin Yue\Desktop\OTL.exe
MOD - [2010/08/24 00:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2010/05/18 18:06:41 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2006/02/02 13:57:16 | 000,028,672 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\VFuj02b1.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/03/17 16:38:42 | 000,361,712 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2011/03/13 11:45:14 | 000,148,520 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe -- (mfevtp)
SRV - [2011/03/13 11:41:50 | 000,159,832 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2011/03/13 11:41:36 | 000,165,000 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2007/03/05 21:58:16 | 004,554,752 | ---- | M] () [Auto | Running] -- C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe -- (MySQL)
SRV - [2006/09/12 23:11:44 | 000,053,248 | ---- | M] (Apache Software Foundation) [Auto | Stopped] -- C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe -- (Tomcat5)
SRV - [2005/09/13 15:30:14 | 000,057,344 | ---- | M] (O2Micro International) [On_Demand | Stopped] -- C:\WINDOWS\system32\o2flash.exe -- (O2Flash)
========== Driver Services (SafeList) ==========
DRV - [2011/03/13 11:20:10 | 000,459,728 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/03/13 11:20:10 | 000,337,912 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\WINDOWS\system32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/03/13 11:20:10 | 000,179,248 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2011/03/13 11:20:10 | 000,118,784 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2011/03/13 11:20:10 | 000,089,368 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\WINDOWS\system32\drivers\mfetdi2k.sys -- (mfetdi2k)
DRV - [2011/03/13 11:20:10 | 000,085,984 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Stopped] -- C:\WINDOWS\system32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/03/13 11:20:10 | 000,083,688 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfendisk.sys -- (mfendiskmp)
DRV - [2011/03/13 11:20:10 | 000,083,688 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mfendisk.sys -- (mfendisk)
DRV - [2011/03/13 11:20:10 | 000,059,288 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2011/03/13 11:20:10 | 000,057,432 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\WINDOWS\system32\drivers\cfwids.sys -- (cfwids)
DRV - [2009/12/27 22:11:49 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/10/13 17:50:00 | 000,133,632 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2kfNT.sys -- (Mkd2kfNt)
DRV - [2009/09/08 18:13:16 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2009/07/13 17:37:00 | 000,079,360 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2Nadr.sys -- (Mkd2Nadr)
DRV - [2009/04/13 06:31:32 | 000,007,168 | ---- | M] (FUJITSU LIMITED) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\FJGSDisk.sys -- (FJGSDisk)
DRV - [2008/07/10 02:49:14 | 000,242,712 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\RsFx0102.sys -- (RsFx0102)
DRV - [2006/09/19 22:14:10 | 000,019,345 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMPR5.sys -- (MREMPR5)
DRV - [2006/09/19 22:14:10 | 000,018,003 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRENDIS5.sys -- (MRENDIS5)
DRV - [2006/08/02 01:27:48 | 000,012,544 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/07/06 08:56:00 | 000,248,832 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2006/06/14 10:04:00 | 004,299,264 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/04/28 18:16:28 | 000,036,768 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\o2media.sys -- (O2MDRDR)
DRV - [2006/04/27 13:30:30 | 000,028,544 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\o2sd.sys -- (O2SDRDR)
DRV - [2006/03/17 14:36:42 | 001,155,584 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2005/11/04 15:48:22 | 000,021,120 | ---- | M] (FUJITSU LIMITED) [Kernel | Auto | Running] -- C:\Program Files\Fujitsu\BtnHnd\BtnHnd.sys -- (BtnHnd)
DRV - [2005/07/21 14:56:22 | 000,007,196 | ---- | M] (FUJITSU LIMITED) [Kernel | Auto | Running] -- C:\Program Files\Fujitsu\FlashAid\FlashDrv.sys -- (FlashDrv)
DRV - [2004/08/04 20:00:00 | 000,012,160 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\fsvga.sys -- (FsVga)
DRV - [2004/01/18 12:15:20 | 000,004,864 | R--- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fuj02e3.sys -- (FUJ02E3)
DRV - [2001/09/07 00:01:00 | 000,006,000 | ---- | M] (Fujitsu Limited) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FUJ02E1.sys -- (FUJ02E1)
DRV - [2001/08/17 20:10:28 | 000,035,913 | ---- | M] (SMC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)
DRV - [2001/08/01 05:00:22 | 000,005,248 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fuj02b1.sys -- (FUJ02B1)
DRV - [1999/11/18 17:20:00 | 000,003,872 | ---- | M] (FUJITSU LIMITED.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ADVNTDRV.SYS -- (ADVNTDRV)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.facebook.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems:
firebug@software.joehewitt.com:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems:
wappalyzer@crunchlabz.com:1.13.2
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/05/18 18:06:42 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/05 02:44:33 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/04 00:06:59 | 000,000,000 | ---D | M]
[2009/04/12 18:44:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Extensions
[2011/05/11 19:10:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Firefox\Profiles\169fjpom.default\extensions
[2010/04/28 10:25:27 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Firefox\Profiles\169fjpom.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/29 00:56:39 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Firefox\Profiles\169fjpom.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/04/15 16:52:04 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Firefox\Profiles\169fjpom.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/02/06 17:43:02 | 000,000,000 | ---D | M] (Firebug) -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Firefox\Profiles\169fjpom.default\extensions\firebug@software.joehewitt.com
[2010/09/02 15:55:50 | 000,000,000 | ---D | M] (SQLite Manager) -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Firefox\Profiles\169fjpom.default\extensions\SQLiteManager@mrinalkant.blogspot(2).com
[2011/04/30 19:04:52 | 000,000,000 | ---D | M] (Wappalyzer) -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Firefox\Profiles\169fjpom.default\extensions\wappalyzer@crunchlabz.com
[2009/07/04 14:27:50 | 000,001,587 | ---- | M] () -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Firefox\Profiles\169fjpom.default\searchplugins\dictionary---referencecom.xml
[2009/07/04 14:26:51 | 000,002,042 | ---- | M] () -- C:\Documents and Settings\Lin Yue\Application Data\Mozilla\Firefox\Profiles\169fjpom.default\searchplugins\facebook.xml
[2011/05/07 22:01:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/14 02:08:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/13 17:37:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/29 00:33:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/14 23:52:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/21 00:57:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/05/18 18:06:42 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/05/14 02:08:10 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/10/13 22:28:54 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2009/09/12 23:05:42 | 000,124,240 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\CCMSDK.dll
[2009/09/12 23:06:22 | 000,070,488 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2009/09/12 23:06:32 | 000,091,480 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2009/09/12 23:06:28 | 000,022,360 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/09/12 23:08:36 | 000,406,864 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2009/09/12 23:06:24 | 000,023,896 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
[2011/04/15 00:26:53 | 000,002,423 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
O1 HOSTS File: ([2011/05/09 12:50:45 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110425194121.dll (McAfee, Inc.)
O2 - BHO: (IE Developer Toolbar BHO) - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [ATSwpNav] C:\Program Files\Fingerprint Sensor\ATSwpNav.exe (AuthenTec, Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [FJUPDNV_Chitose] C:\Program Files\Fujitsu\updnavi\updnavi.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SSUtility] C:\Program Files\Fujitsu\SSUtility\FJSSDMN.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
O4 - Startup: C:\Documents and Settings\Lin Yue\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Lin Yue\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Lin Yue\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Lin Yue\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71}
http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1239576703515 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1239526907578 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853}
http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab (ZPA_SHVL Object)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}
http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4}
http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab (ChessControl Class)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP AG, Walldorf)
O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP AG, Walldorf)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Lin Yue\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lin Yue\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/08/04 12:59:13 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/11 19:24:48 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Lin Yue\Desktop\OTL.exe
[2011/05/11 18:56:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/05/09 14:36:05 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/05/09 12:38:56 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/05/09 12:30:25 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/05/09 12:30:25 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/05/09 12:30:25 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/05/09 12:30:25 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/05/09 12:30:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/05/09 12:29:33 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/05/09 12:18:20 | 000,083,968 | ---- | C] (eSage Lab) -- C:\Documents and Settings\Lin Yue\Desktop\remover.exe
[2011/05/07 00:33:25 | 000,000,000 | ---D | C] -- D:\My Documents\Downloads
[2011/04/25 00:29:53 | 000,455,168 | ---- | C] (Mysoft) -- C:\Documents and Settings\Lin Yue\Desktop\GiFFY.exe
[2011/04/15 01:29:11 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/04/15 01:29:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/15 01:29:07 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/04/15 01:29:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/15 00:25:17 | 000,000,000 | ---D | C] -- C:\Program Files\Yuna Software
[2009/04/30 00:07:21 | 003,100,672 | ---- | C] (SAP Technology,Inc) -- C:\Program Files\Common Files\sapxlhelper.dll
[2009/04/30 00:07:20 | 000,192,512 | ---- | C] (SAP Tech Inc.) -- C:\Program Files\Common Files\sapconsr3.dll
[2009/04/30 00:07:18 | 000,626,688 | ---- | C] (SAP AG) -- C:\Program Files\Common Files\sapconsaccess.dll
[2009/04/30 00:07:16 | 000,040,960 | ---- | C] (SAP-TECHNOLOGY) -- C:\Program Files\Common Files\DigitalSignature.ocx
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/11 19:25:17 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lin Yue\Desktop\OTL.exe
[2011/05/11 19:14:18 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1990911110-2150341681-62948162-1006.job
[2011/05/11 19:14:16 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1990911110-2150341681-62948162-1006.job
[2011/05/11 19:01:10 | 000,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1990911110-2150341681-62948162-1006UA.job
[2011/05/11 18:56:34 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2011/05/11 18:56:21 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/05/11 18:56:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/11 18:56:17 | 1063,178,240 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/09 12:50:45 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/05/09 12:39:03 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/05/09 12:22:24 | 004,343,905 | R--- | M] () -- C:\Documents and Settings\Lin Yue\Desktop\ComboFix.exe
[2011/05/09 12:17:54 | 000,039,605 | ---- | M] () -- C:\Documents and Settings\Lin Yue\Desktop\bootkit_remover.rar
[2011/05/08 03:07:03 | 000,002,280 | ---- | M] () -- C:\Documents and Settings\Lin Yue\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/08 03:07:02 | 000,002,302 | ---- | M] () -- C:\Documents and Settings\Lin Yue\Desktop\Google Chrome.lnk
[2011/05/06 21:11:12 | 000,001,022 | ---- | M] () -- C:\Documents and Settings\Lin Yue\Start Menu\Programs\Startup\Dropbox.lnk
[2011/05/06 21:11:10 | 000,001,022 | ---- | M] () -- C:\Documents and Settings\Lin Yue\Desktop\Dropbox.lnk
[2011/04/30 18:01:01 | 000,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1990911110-2150341681-62948162-1006Core.job
[2011/04/24 23:13:34 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/17 01:08:27 | 000,299,640 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/17 00:30:39 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/04/17 00:26:05 | 000,598,646 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/04/17 00:26:05 | 000,120,292 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/04/15 01:53:23 | 000,002,187 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/04/15 01:29:12 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/09 12:39:02 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/05/09 12:38:59 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/05/09 12:30:25 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/05/09 12:30:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/05/09 12:30:25 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/05/09 12:30:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/05/09 12:30:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/05/09 12:21:29 | 004,343,905 | R--- | C] () -- C:\Documents and Settings\Lin Yue\Desktop\ComboFix.exe
[2011/05/09 12:17:59 | 000,039,605 | ---- | C] () -- C:\Documents and Settings\Lin Yue\Desktop\bootkit_remover.rar
[2011/04/15 01:29:12 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/12 23:24:47 | 000,000,200 | ---- | C] () -- C:\WINDOWS\System32\msexcr.ini
[2010/09/03 20:51:31 | 000,070,640 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/03/26 12:04:10 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2010/02/14 22:07:33 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/01/25 17:18:15 | 000,758,018 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/01/25 17:18:15 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/01/07 21:03:22 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/12/08 17:21:57 | 000,059,936 | ---- | C] () -- C:\WINDOWS\System32\plm.exe
[2009/12/08 17:21:57 | 000,024,064 | ---- | C] () -- C:\WINDOWS\System32\PjsHotKeySvr.exe
[2009/12/08 17:21:56 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\PjsDlg32.dll
[2009/12/08 17:21:55 | 002,822,659 | ---- | C] () -- C:\WINDOWS\System32\eng2chn32.dll
[2009/12/08 16:43:55 | 000,000,028 | ---- | C] () -- C:\WINDOWS\hsvision.ini
[2009/11/23 16:41:11 | 000,000,025 | ---- | C] () -- C:\WINDOWS\libem.INI
[2009/11/04 07:53:17 | 002,076,672 | ---- | C] () -- C:\WINDOWS\System32\libmysql.dll
[2009/08/05 17:34:15 | 000,000,153 | ---- | C] () -- C:\WINDOWS\sapgrph.ini
[2009/06/10 17:08:12 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/05/01 12:45:33 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/04/30 00:14:33 | 000,029,474 | ---- | C] () -- C:\WINDOWS\saplogon.ini
[2009/04/30 00:14:33 | 000,000,155 | ---- | C] () -- C:\WINDOWS\sapmsg.ini
[2009/04/30 00:14:33 | 000,000,102 | ---- | C] () -- C:\WINDOWS\saproute.ini
[2009/04/30 00:07:18 | 001,124,864 | ---- | C] () -- C:\Program Files\Common Files\SAPActiveXL_nosig.xlt
[2009/04/30 00:07:17 | 001,129,984 | ---- | C] () -- C:\Program Files\Common Files\SAPActiveXL.xlt
[2009/04/30 00:01:40 | 000,095,744 | ---- | C] () -- C:\WINDOWS\System32\h5rtf32.dll
[2009/04/30 00:01:40 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\h5tool32.dll
[2009/04/30 00:01:39 | 001,064,960 | ---- | C] () -- C:\WINDOWS\System32\h5krnl32.dll
[2009/04/30 00:01:39 | 000,188,928 | ---- | C] () -- C:\WINDOWS\System32\h5icon32.dll
[2009/04/30 00:01:39 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\h5menu32.dll
[2009/04/30 00:01:27 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\vtssm32.dll
[2009/04/29 10:52:18 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/04/19 15:47:29 | 000,063,488 | ---- | C] () -- C:\Documents and Settings\Lin Yue\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/13 06:29:26 | 000,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2009/04/13 06:29:26 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2009/04/13 06:15:31 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/04/12 18:44:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/08/04 13:01:03 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/08/04 12:57:42 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/08/04 08:52:13 | 000,003,111 | ---- | C] () -- C:\WINDOWS\System32\FJSaver.ini
[2006/08/04 05:55:37 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/08/04 05:55:00 | 000,299,640 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/08/03 11:10:03 | 000,000,720 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/08/03 11:09:34 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/08/03 11:09:32 | 000,598,646 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/08/03 11:09:32 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/08/03 11:09:32 | 000,120,292 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/08/03 11:09:32 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/08/03 11:09:31 | 000,004,555 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/08/03 11:09:30 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/08/03 11:09:29 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/08/03 11:09:25 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/08/03 11:09:25 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/08/03 11:09:18 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/08/03 11:09:13 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/04/13 00:38:23 | 000,000,013 | -H-- | C] () -- C:\Program Files\IMAGE1.DAT
[2005/09/02 14:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 21:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2005/06/11 11:47:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\fpprintmon.dll
[2005/01/21 13:02:28 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\RMDevice.dll
[2004/07/20 17:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 14:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
========== LOP Check ==========
[2010/08/02 13:07:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/09/02 15:17:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BSD
[2009/04/13 23:40:04 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/01/26 23:06:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJMSetup
[2011/01/26 23:08:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2011/01/26 23:29:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2010/10/09 23:15:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2009/12/27 22:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/11/20 00:53:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/08/18 12:45:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2010/01/21 17:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2009/04/22 15:17:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/10/30 20:09:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2010/08/02 13:21:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/27 14:48:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
[2010/08/19 00:44:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/04/30 20:20:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/09/02 14:18:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\4Media
[2009/11/23 19:27:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\BITS
[2010/09/02 15:17:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\BSD
[2011/01/26 23:27:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\Canon
[2009/08/01 16:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/10/09 00:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\DAEMON Tools Lite
[2011/05/11 19:16:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\Dropbox
[2010/10/29 00:56:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\DVDVideoSoftIEHelpers
[2010/04/19 20:25:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\FileZilla
[2009/11/23 16:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\FlashGetBHO
[2010/09/02 15:55:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\GetRightToGo
[2010/10/09 23:14:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\ICAClient
[2009/08/31 14:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\iMirus
[2010/01/10 11:12:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\MySQL
[2009/04/22 15:17:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\PlayFirst
[2009/06/10 16:54:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\SystemRequirementsLab
[2010/12/13 01:45:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\WeGame
[2010/09/02 15:56:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lin Yue\Application Data\WindSolutions
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/08/04 12:59:13 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/04/14 09:19:25 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/05/09 12:39:03 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:02 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2011/05/09 14:20:13 | 000,022,778 | ---- | M] () -- C:\ComboFix.txt
[2006/08/04 12:59:13 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2011/05/11 18:56:17 | 1063,178,240 | -HS- | M] () -- C:\hiberfil.sys
[2007/11/07 08:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2006/08/04 12:59:13 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2006/08/04 12:59:13 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/04 20:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/04/12 17:33:07 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011/05/11 18:56:15 | 1598,029,824 | -HS- | M] () -- C:\pagefile.sys
[2010/08/18 02:02:17 | 000,003,072 | -H-- | M] () -- C:\photothumb.db
[2009/04/13 06:29:31 | 000,000,499 | ---- | M] () -- C:\RHDSetup.log
[2009/05/12 08:31:55 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2009/05/12 13:53:40 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2009/05/19 01:02:43 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2009/06/11 14:30:07 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2009/06/27 01:27:56 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2009/06/27 13:45:08 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2009/06/27 14:12:40 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2009/06/27 14:34:43 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2009/07/27 11:49:05 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2009/08/12 02:19:01 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2009/08/28 01:40:05 | 000,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2009/09/12 02:02:14 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2009/09/13 01:59:06 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2009/09/14 02:12:12 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2009/09/29 17:26:46 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2009/10/29 10:34:07 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2009/05/12 08:31:55 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2009/05/12 13:53:40 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2009/05/19 01:02:43 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2009/06/11 14:30:07 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2009/06/27 01:27:56 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2009/06/27 13:45:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2009/06/27 14:12:40 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2009/06/27 14:34:43 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2009/07/27 11:49:05 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2009/08/12 02:19:01 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2009/08/28 01:40:05 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2009/09/12 02:02:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2009/09/13 01:59:06 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2009/09/14 02:12:12 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2009/09/29 17:26:46 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2009/10/29 10:34:07 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2007/11/07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI