:OTL IE - HKU\S-1-5-21-2511343510-2362421710-3736614235-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421; O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2511343510-2362421710-3736614235-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present [2012/04/02 18:30:37 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA% [2012/04/05 19:49:34 | 000,000,000 | -HS- | M] () -- C:\Windows\SysNative\dds_log_ad13.cmd [2011/11/19 14:17:20 | 000,000,000 | ---- | C] () -- C:\ProgramData\8C227oEtM.dat [2010/10/28 19:14:34 | 000,000,000 | ---D | M](C:\Users\Zack\Documents\?? ???) -- C:\Users\Zack\Documents\넥슨 플러그 [2010/10/28 19:14:34 | 000,000,000 | ---D | C](C:\Users\Zack\Documents\?? ???) -- C:\Users\Zack\Documents\넥슨 플러그 :Reg [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Users\Zack\AppData\Roaming\n4f9.exe"=- "C:\Windows\System32\config\systemprofile\AppData\Roaming\n4f9.exe"=- "C:\Users\Zack\AppData\Roaming\lssas.exe"=- "C:\Users\Zack\AppData\Roaming\manager.exe"=- "C:\Users\Zack\AppData\Roaming\n4f9.exe"=- "C:\Windows\System32\config\systemprofile\AppData\Roaming\n4f9.exe"=- "C:\Users\Zack\AppData\Roaming\lssas.exe"=- "C:\Users\Zack\AppData\Roaming\manager.exe"=- :Files C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} ipconfig /flushdns /c :Commands [emptytemp] [CREATERESTOREPOINT] [Reboot]