I seem to have picked up some malware in which everytime I open internet explorer, multiple iexplorer.exe pop up in the task manager DRASTICALLY slowing down performance. In addition, one pop up or so occurs due to this every 30 mins roughly. I've tried multiple anti-malware programs to fix this including Malware Bytes, SuperAntiSpyware and a few others, but this one seems to elude their grasps.
Attached is the OTL file.
To whomever picks this file up and helps me, I thank you very much as I know you are doing this of your own free time and will.
Now to the nasty bit:
OTL logfile created on: 9/12/2011 5:00:05 PM - Run 1
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Documents and Settings\Jean\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 63.92% Memory free
3.84 Gb Paging File | 3.24 Gb Available in Paging File | 84.26% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 294.73 Gb Total Space | 240.61 Gb Free Space | 81.64% Space Free | Partition Type: NTFS
Computer Name: SONG | User Name: Jean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/09/12 16:58:05 | 000,581,632 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jean\Desktop\OTL.exe
PRC - [2011/09/07 12:05:02 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/06/29 08:04:18 | 000,020,480 | ---- | M] (AG Interactive) -- C:\Program Files\AGI\core\4.2.0.10754\AGCoreService.exe
PRC - [2009/08/23 16:59:45 | 000,186,912 | ---- | M] (INCA Internet Co., Ltd.) -- C:\WINDOWS\system32\npkcmsvc.exe
PRC - [2009/05/21 10:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/10/10 09:56:01 | 009,965,437 | ---- | M] (K.G.Y.L. Associates, Inc.) -- \\Server\ATI\main.exe
PRC - [2008/10/02 15:34:34 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2008/08/13 18:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/06/11 22:43:26 | 000,640,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/01/31 15:01:38 | 000,159,744 | R--- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
PRC - [2005/09/23 18:08:12 | 000,176,128 | ---- | M] (Fasoo.com) -- C:\Program Files\Fasoo DRM\fph.exe
PRC - [2004/04/07 13:07:32 | 001,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
========== Modules (No Company Name) ==========
MOD - [2011/09/07 12:05:02 | 001,846,232 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/08/10 03:12:18 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\70a1400affdc775d7c7398e036359286\System.ServiceProcess.ni.dll
MOD - [2011/08/10 03:12:18 | 000,141,312 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\585e68739b2a8aff61ee6b2786513245\System.Configuration.Install.ni.dll
MOD - [2011/08/10 03:12:13 | 000,627,712 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\75f452279422a7898e840ee5768c9d2e\System.EnterpriseServices.ni.dll
MOD - [2011/08/10 03:11:59 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\77df2cd21a5b85a1605b335aa9ad9d44\System.Configuration.ni.dll
MOD - [2011/08/10 03:10:00 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\10154dcad2d62f226af2fd4211460a4b\System.Xml.ni.dll
MOD - [2011/08/10 03:08:26 | 007,950,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e6c79e1d71b0c9000afd7e5e439b5c54\System.ni.dll
MOD - [2011/06/16 03:21:32 | 011,490,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll
MOD - [2011/05/28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2010/02/05 14:27:45 | 001,291,776 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2010/01/26 21:07:32 | 003,884,312 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2008/06/11 22:32:28 | 002,666,496 | ---- | M] () -- C:\Program Files\Adobe\Acrobat 9.0\PDFMaker\Common\AdobePDFMakerX.dll
MOD - [2008/04/13 20:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 20:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2006/08/18 14:17:36 | 000,056,056 | ---- | M] () -- C:\WINDOWS\system32\DLAAPI_W.DLL
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2010/09/17 18:33:04 | 000,919,416 | ---- | M] (ESTsoft Corp) [Auto | Stopped] -- C:\Program Files\ESTsoft\ALYac\AYServiceNT.aye -- (ALYac_PZSrv)
SRV - [2010/06/29 08:04:18 | 000,020,480 | ---- | M] (AG Interactive) [Auto | Running] -- C:\Program Files\AGI\core\4.2.0.10754\AGCoreService.exe -- (AGCoreService)
SRV - [2009/08/23 16:59:45 | 000,186,912 | ---- | M] (INCA Internet Co., Ltd.) [Auto | Running] -- C:\WINDOWS\system32\npkcmsvc.exe -- (npkcmsvc)
SRV - [2008/10/02 15:34:34 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/08/13 18:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/01/23 10:45:44 | 000,032,768 | ---- | M] (Inter-Tel (Delaware), Inc) [Disabled | Stopped] -- C:\Documents and Settings\Jean\My Documents\Inter-Tel\Collaboration Client 2.0\lkWebLink.exe -- (LkWebLink)
SRV - [2004/04/07 13:07:32 | 001,135,728 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -- (AOL ACS)
========== Driver Services (SafeList) ==========
DRV - [2010/12/21 01:55:02 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2010/12/21 01:55:02 | 000,121,576 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2010/12/21 01:55:02 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2010/12/21 01:55:02 | 000,096,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus) SAMSUNG Android USB Composite Device driver (WDM)
DRV - [2010/12/21 01:55:02 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010/12/21 01:55:02 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2010/12/21 01:55:02 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl) SAMSUNG Android USB Modem (Filter)
DRV - [2010/08/01 20:23:48 | 000,189,656 | ---- | M] (SoftCamp) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\scskusbs.sys -- (scskusbs)
DRV - [2010/08/01 20:23:48 | 000,018,232 | ---- | M] (SoftCamp) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\scskusbf.sys -- (scskusbf)
DRV - [2009/12/21 02:14:00 | 000,121,504 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\AhnLab\ASP\MyFirewall 4.0\mfipsent.sys -- (MfIPSEnt)
DRV - [2009/12/21 02:14:00 | 000,101,336 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\AhnLab\ASP\MyFirewall 4.0\mffwent.sys -- (MfFWEnt)
DRV - [2009/12/18 04:28:00 | 000,095,592 | ---- | M] (AhnLab, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmonTDNt.sys -- (AMonTDnt)
DRV - [2009/08/05 23:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009/07/20 21:13:00 | 000,019,616 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CdmDrvNt.sys -- (CdmDrvNt)
DRV - [2009/05/08 16:32:08 | 000,021,248 | ---- | M] (Space International,Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\ezty2usb.sys -- (ezty2usb)
DRV - [2009/02/09 15:06:44 | 000,053,536 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\npkcrypt.sys -- (npkcrypt)
DRV - [2009/01/19 14:46:34 | 000,043,424 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\npkcusb.sys -- (npkcusb)
DRV - [2008/12/18 20:57:44 | 000,024,312 | ---- | M] (ESTsoft Corp) [Kernel | On_Demand | Stopped] -- C:\Program Files\ESTsoft\ALYac\AYDrvSP.sys -- (AYDrvSP_ALYAC)
DRV - [2008/09/26 14:06:40 | 000,020,424 | ---- | M] (ESTsoft Corp) [Kernel | On_Demand | Stopped] -- C:\Program Files\ESTsoft\ALYac\AYDrvNT.sys -- (AYDrvNT_ALYAC)
DRV - [2008/07/30 15:09:37 | 000,017,408 | ---- | M] (MobileTop) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSPUSB.sys -- (shspusb)
DRV - [2008/05/08 10:02:52 | 000,203,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rmcast.sys -- (RMCAST)
DRV - [2008/04/13 14:39:44 | 000,092,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mqac.sys -- (MQAC)
DRV - [2008/03/18 20:41:01 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2007/10/28 20:31:22 | 000,009,216 | ---- | M] (SoftForum Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\JRSKD24.sys -- (JRSKD24)
DRV - [2007/10/28 20:31:22 | 000,006,784 | ---- | M] (SoftForum Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\JRSUKD24.sys -- (JRSUKD24)
DRV - [2007/07/16 21:48:54 | 004,403,712 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/08/18 14:18:08 | 000,009,400 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResM.SYS -- (DLADResM)
DRV - [2006/08/18 14:17:46 | 000,035,096 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABMFSM.SYS -- (DLABMFSM)
DRV - [2006/08/18 14:17:44 | 000,097,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/08/18 14:17:44 | 000,094,648 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/08/18 14:17:42 | 000,026,008 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/08/18 14:17:40 | 000,032,472 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/08/18 14:17:38 | 000,104,472 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/08/18 14:17:38 | 000,014,520 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/08/11 11:35:18 | 000,012,920 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/08/11 11:35:16 | 000,028,184 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)
DRV - [2005/01/26 11:10:14 | 000,004,598 | ---- | M] (Fasoo.com) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\f_kp.sys -- (f_kp)
DRV - [2004/08/04 07:00:00 | 000,012,160 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\fsvga.sys -- (FsVga)
DRV - [2003/11/17 16:59:20 | 000,212,224 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2003/11/17 16:58:02 | 000,680,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/11/17 16:56:26 | 001,042,432 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2003/01/10 17:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1080319
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1080319
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co...html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co...html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://asp.editrade.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npaosmgr.1: C:\Program Files\AhnLab\ASP\Components\aosmgr\conflict_315\npaosmgr.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\UnifiedToolbar\3.2\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/07 12:05:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/08/29 15:58:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jean\Application Data\Mozilla\Extensions
[2011/08/29 15:58:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009/06/24 20:34:55 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/09/07 12:05:02 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/08/11 23:16:35 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2008/10/02 16:27:32 | 000,000,070 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 60.210.176.251
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (ALToolBar) - {38FBE93D-4CA1-4414-AF6A-94920C5BD8DA} - C:\Program Files\ESTsoft\ALToolBar\ALToolBand_1520.dll (ESTsoft Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3: - HKCU\..\Toolbar\WebBrowser - No CLSID value found.
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [FPH Exe] C:\Program Files\Fasoo DRM\fph.exe (Fasoo.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google 사이드위키... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: editrade.com ([asp] http in Trusted sites)
O15 - HKCU\..Trusted Domains: editrade.com ([asp] https in Trusted sites)
O15 - HKCU\..Trusted Domains: koreanair.com ([cargo] http in Trusted sites)
O16 - DPF: {044123B5-35DF-4C4E-BAED-26B8ED964342} http://fx.hauri.net/...iveRobotWeb.cab (HLiveRobotWeb Control)
O16 - DPF: {063F7D71-5E0B-48F2-87D5-F63C5917947E} http://ahnlabdownloa...ugin/aosmgr.cab (Aosmgr Control)
O16 - DPF: {1A000B1F-B285-4FBF-B3CD-B50845003EBA} http://ecos.bok.or.k...070614_0910.cab (CyMiInstaller320 Class)
O16 - DPF: {27BCC3E9-D724-493B-A79E-C2E12C03407A} http://www.iloveschool.co.kr/cfcli.cab (CfClient Class)
O16 - DPF: {2DCB00FB-3485-486B-BD41-C49AD605264D} http://portal.custom.../easykeytec.cab (EZKeytecWeb Class)
O16 - DPF: {39461460-2552-4D51-A062-3AB6A7B902E9} http://img.shinhan.c...down/INIS70.cab (INISAFE Updater Control)
O16 - DPF: {39FC0CF9-86F3-4502-B773-D16706EDEC83} http://img.shinhan.c...03151/SCSK4.cab (SCSK Control)
O16 - DPF: {3D64E58D-CB55-4344-B809-CFE38F900838} http://portal.custom...agicLoaderX.cab (MagicLoaderX Class)
O16 - DPF: {3DBD0562-7FB7-461A-842C-F63A1AD8C2DE} http://www.hanjin.co...gnE_Install.cab (XESignE Class)
O16 - DPF: {42D683F7-9C1B-11D7-A860-005056C00001} http://www.editrade....dp/TPRDPenN.cab (.print Client RDP Webinstall)
O16 - DPF: {53EED863-B547-40F8-B24A-2D6DE807CFE8} http://img.shinhan.c...t/Printmade.cab (Printmade Control)
O16 - DPF: {66413DC2-F891-40BC-822D-B7EEC8ADC281} http://img.shinhan.c...orksGrid_78.cab (ProWorksGrid Control)
O16 - DPF: {6CE20149-ABE3-462E-A1B4-5B549971AA38} http://ck.softforum....eb/CKKeyPro.cab (XecureCKKB Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1206050226968 (MUWebControl Class)
O16 - DPF: {6E4FE796-2693-4404-A4ED-A2565CAD7ABB} http://www.etrade.co...x/EtradeWeb.cab (ETWebGate Control)
O16 - DPF: {6FE760D3-7851-4879-8838-62D9881D7177} http://61.40.216.19/IniMasPlugin.cab (IniMasHandler Class)
O16 - DPF: {710E4921-F77C-4D42-8EC4-4DFDEE52508F} http://210.90.46.53/...X/ictPrintX.cab (ictPrintXForm Control)
O16 - DPF: {7A0D1738-10EA-47FF-92BE-4E137B5BE1A4} https://mpsnare.iesnare.com/StmOCX.cab (Stm Class)
O16 - DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} http://www2.hanjin.c.../xw_install.cab (XecureWeb 4.0 Client Control)
O16 - DPF: {81A15AF3-21E3-4F07-A5BD-3FA8AE83AF83} http://www.jjangdisk...DiskControl.CAB (JJangDisk File Share Control 5)
O16 - DPF: {8569D715-FF88-44BA-8D1D-AD3E59543DDE} http://isf.freightst...com/arview2.cab (ActiveReports Viewer2)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} https://asp.editrade.com/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {95A57FEB-0909-4FEA-B819-63DA7C4D9E1E} http://img.shinhan.c...madeActiveX.cab (Printmade S 1.5.9)
O16 - DPF: {9FC84F7D-D177-4A75-A7BB-429DA5BD0A3E} Reg Error: Key error. (SG_CAppAtx Control)
O16 - DPF: {A977FF0C-8757-4E76-8533-482F91946233} http://dl.sayclub.co...ayctl/sayax.cab (Sayclub Login Control)
O16 - DPF: {AD6870C0-44B7-42FB-A119-C2C6BD9CD005} http://portal.custom.../MagicPassX.cab (MagicPass Class)
O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} http://mail.daum.net...cab?ver=2,0,0,8 (Daum ActiveX manager Class)
O16 - DPF: {BBB0FC2D-1D95-45CA-BDCF-03B53F247FCC} http://portal.custom...taller_full.cab (EwsLoader Class)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://images3.pnime...veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C7C7225A-9476-47AC-B0B0-FF3B79D55E67} http://203.232.224.1.../ZTransferX.cab (ZTransferX Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CB5C683C-416A-4701-B018-0F1B21D64D6B} http://cyimg7.cyworl...age/skcinst.cab (SKCInst1 Class)
O16 - DPF: {CC796C4C-12F5-4BEE-ABB3-3A9F863B8D6E} http://webmail.hufs....iFileUpload.cab (KebiFileUpload Control)
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} http://update.nprote.../module/npx.cab (NPX Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} http://update.nprote...eowiz/npkcx.cab (NPKCX Control)
O16 - DPF: {D912AABC-6CB0-416F-85B6-CABBB86FD558} https://plugin.inici...INIwallet60.cab (INIwallet60 Control)
O16 - DPF: {E986BA49-C761-4E8F-B1A8-7F3CBE402683} http://webmail.hufs....biInstaller.cab (KebiInstaller Control)
O16 - DPF: {EA0995BF-45DD-4DB0-ADD5-A39C37397841} http://img.shinhan.c...oTrustSiteX.cab (ShbAutoTrustSite Control)
O16 - DPF: {EC5D5118-9FDE-4A3E-84F3-C2B711740E70} http://www.etrade.co...cx/SKCommAX.cab (SKCommAX Control)
O16 - DPF: {FAB9B41C-87D6-474D-AB7E-F07D78F2422E} file:///C:/Documents%20and%20Settings/CHB/Local%20Settings/Compatible%20LocalLow/TOBESOFT/MiPlatform320/Setup/Win32_3.2/teechart7Langs.cab (TeeChart Pro Activex control v7)
O16 - DPF: {FE342FC7-4374-4EBE-86DB-D73AE861F779} http://file.naver.co...averAXGuide.cab (NaverAXGuide Class)
O16 - DPF: CabBuilder http://kiw.imgag.com...llerControl.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{55F5769F-9D2C-4A9D-B00C-D18A1B88E07A}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\s-http {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - C:\Program Files\INITECH\SHTTP\InitechSHTTPInterface.10121.dll (© INITECH)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (acaptuser32.dll) -C:\WINDOWS\System32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 19:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{ca2aea90-f6a1-11dc-aeb5-001d098beab1}\Shell - "" = AutoRun
O33 - MountPoints2\{ca2aea90-f6a1-11dc-aeb5-001d098beab1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ca2aea90-f6a1-11dc-aeb5-001d098beab1}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL \SystemVolumeInformation\system.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/12 16:58:05 | 000,581,632 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jean\Desktop\OTL.exe
[2011/09/03 06:17:37 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
[2011/08/31 10:02:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jean\Application Data\SuperAdBlocker.com
[2011/08/31 10:02:15 | 000,000,000 | ---D | C] -- C:\Program Files\SuperAdBlocker.com
[2011/08/29 17:52:36 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/08/29 17:52:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jean\Start Menu\Programs\HiJackThis
[2011/08/29 16:27:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jean\My Documents\Downloads
[2011/08/29 15:58:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jean\Local Settings\Application Data\Mozilla
[2011/08/29 15:58:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jean\Application Data\Mozilla
[2011/08/29 15:58:03 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/08/29 13:47:43 | 000,000,000 | ---D | C] -- C:\Program Files\Emsisoft Anti-Malware
[2011/08/26 16:17:07 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/08/26 16:17:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/08/24 14:38:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2011/08/24 12:48:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jean\Application Data\Malwarebytes
[2011/08/24 12:48:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/08/24 12:48:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/08/24 12:36:45 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Jean\IECompatCache
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/12 16:59:00 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{C3DD6D76-D049-455C-932E-077DC6DC0A74}.job
[2011/09/12 16:58:05 | 000,581,632 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jean\Desktop\OTL.exe
[2011/09/12 16:50:00 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011/09/12 16:44:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/12 16:07:22 | 000,000,458 | ---- | M] () -- C:\Documents and Settings\Jean\Desktop\Server.lnk
[2011/09/12 16:05:33 | 000,089,387 | ---- | M] () -- C:\Documents and Settings\Jean\Desktop\KO-110811.pdf
[2011/09/12 16:05:20 | 000,074,723 | ---- | M] () -- C:\Documents and Settings\Jean\Desktop\KO-110809.pdf
[2011/09/12 12:44:46 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/09/08 11:29:41 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/09/08 11:29:26 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2011/09/08 11:29:25 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/08 11:29:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/09/08 11:29:19 | 2136,129,536 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/08 11:21:28 | 000,000,894 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Status Monitor.lnk
[2011/09/03 06:17:37 | 000,599,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
[2011/09/01 09:16:23 | 000,002,445 | ---- | M] () -- C:\Documents and Settings\Jean\Desktop\HiJackThis.lnk
[2011/08/31 18:51:52 | 000,000,000 | ---- | M] () -- C:\WINDOWS\ORUN32.EXE
[2011/08/31 18:51:48 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\CMMGR32.EXE
[2011/08/29 15:58:07 | 000,000,788 | ---- | M] () -- C:\Documents and Settings\Jean\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/08/29 15:08:52 | 000,000,567 | ---- | M] () -- C:\Documents and Settings\Jean\Desktop\Shortcut to main.exe.lnk
[2011/08/24 14:36:02 | 000,000,000 | ---- | M] () -- C:\WINDOWS\1678668021
[2011/08/23 17:49:00 | 000,763,041 | ---- | M] () -- C:\Documents and Settings\Jean\Desktop\A WHSE.pdf
[2011/08/23 17:49:00 | 000,345,515 | ---- | M] () -- C:\Documents and Settings\Jean\Desktop\BIZ INFO.pdf
[2011/08/15 14:55:29 | 000,000,426 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/12 16:05:33 | 000,089,387 | ---- | C] () -- C:\Documents and Settings\Jean\Desktop\KO-110811.pdf
[2011/09/12 16:05:20 | 000,074,723 | ---- | C] () -- C:\Documents and Settings\Jean\Desktop\KO-110809.pdf
[2011/08/31 18:51:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ORUN32.EXE
[2011/08/31 18:51:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\CMMGR32.EXE
[2011/08/31 09:02:06 | 2136,129,536 | -HS- | C] () -- C:\hiberfil.sys
[2011/08/29 17:52:37 | 000,002,445 | ---- | C] () -- C:\Documents and Settings\Jean\Desktop\HiJackThis.lnk
[2011/08/29 15:58:07 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\Jean\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/08/29 15:58:07 | 000,000,776 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/08/29 15:07:46 | 000,000,567 | ---- | C] () -- C:\Documents and Settings\Jean\Desktop\Shortcut to main.exe.lnk
[2011/08/24 12:39:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\1678668021
[2011/08/23 17:49:00 | 000,763,041 | ---- | C] () -- C:\Documents and Settings\Jean\Desktop\A WHSE.pdf
[2011/08/23 17:49:00 | 000,345,515 | ---- | C] () -- C:\Documents and Settings\Jean\Desktop\BIZ INFO.pdf
[2011/06/06 17:26:59 | 000,000,530 | ---- | C] () -- C:\Documents and Settings\Jean\Application Data\wklnhst.dat
[2011/03/22 13:57:19 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Jean\Application Data\$_hpcst$.hpc
[2011/01/04 16:40:36 | 000,000,065 | ---- | C] () -- C:\WINDOWS\System32\bd7040.dat
[2011/01/04 16:39:56 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\BRLMW03A.INI
[2011/01/04 16:39:43 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll
[2010/11/04 19:21:32 | 000,000,072 | ---- | C] () -- C:\WINDOWS\hdkctnts.ini
[2010/08/01 20:23:48 | 000,000,024 | ---- | C] () -- C:\WINDOWS\System32\scskConfigEH.ini
[2010/08/01 19:47:40 | 000,066,920 | ---- | C] () -- C:\WINDOWS\CMListControl.dll
[2009/08/26 20:02:31 | 000,005,042 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\xqkcebzs.dik
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/02 12:41:33 | 000,066,920 | ---- | C] () -- C:\WINDOWS\System32\CMListControl.dll
[2009/04/15 14:00:52 | 000,000,581 | ---- | C] () -- C:\WINDOWS\HDINFO50.INI
[2009/02/18 16:31:55 | 000,339,968 | ---- | C] () -- C:\WINDOWS\System32\pythoncom25.dll
[2009/02/18 16:31:55 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\pywintypes25.dll
[2009/01/05 19:52:19 | 000,121,299 | ---- | C] () -- C:\WINDOWS\hpoins15.dat
[2009/01/05 19:52:19 | 000,001,037 | ---- | C] () -- C:\WINDOWS\hpomdl15.dat
[2008/12/26 18:28:47 | 000,000,079 | ---- | C] () -- C:\WINDOWS\System32\ETKCommInfoWeb.ini
[2008/12/17 17:43:46 | 000,589,824 | ---- | C] () -- C:\WINDOWS\System32\INICRYPTOSDK.dll
[2008/10/10 15:43:10 | 000,218,194 | ---- | C] () -- C:\WINDOWS\System32\MaPrintInfoDamon.dat
[2008/07/30 15:09:01 | 000,000,092 | ---- | C] () -- C:\WINDOWS\System32\drivers\ftdiun2k.ini
[2008/07/30 15:09:00 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\drivers\GetMP4Info.dll
[2008/07/30 15:09:00 | 000,000,091 | ---- | C] () -- C:\WINDOWS\System32\drivers\FTDIUNIN.INI
[2008/07/30 15:08:59 | 000,618,496 | ---- | C] () -- C:\WINDOWS\System32\stlpmt45.dll
[2008/07/30 15:08:59 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2008/07/25 12:43:45 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008/07/16 16:44:06 | 000,000,065 | ---- | C] () -- C:\WINDOWS\System32\BD7020.DAT
[2008/05/05 11:22:44 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/05/05 11:22:44 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2008/04/29 13:13:57 | 000,000,889 | ---- | C] () -- C:\WINDOWS\UninstFW.ini
[2008/04/24 14:59:41 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\npScan.dll
[2008/04/24 14:59:41 | 000,000,198 | ---- | C] () -- C:\WINDOWS\CHB.INI
[2008/04/10 19:54:56 | 000,000,040 | ---- | C] () -- C:\WINDOWS\Hjimesv.ini
[2008/04/10 19:53:52 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\winhcfga.ini
[2008/03/26 20:43:13 | 000,000,051 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2008/03/26 20:43:13 | 000,000,040 | ---- | C] () -- C:\WINDOWS\opt_2460.ini
[2008/03/26 14:35:04 | 000,000,825 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini
[2008/03/26 14:35:04 | 000,000,152 | ---- | C] () -- C:\WINDOWS\brpcfx.ini
[2008/03/26 14:35:04 | 000,000,065 | ---- | C] () -- C:\WINDOWS\System32\BD7820N.dat
[2008/03/26 14:35:03 | 000,000,052 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2008/03/26 14:33:30 | 000,027,019 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2008/03/24 11:58:03 | 000,000,034 | ---- | C] () -- C:\WINDOWS\ATPlayer.INI
[2008/03/24 11:56:15 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\H263Encoder.dll
[2008/03/24 11:56:15 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\H263Decoder.dll
[2008/03/24 11:56:15 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\AnsZip35.dll
[2008/03/24 11:56:13 | 000,000,447 | ---- | C] () -- C:\WINDOWS\nanumixp.ini
[2008/03/21 12:33:36 | 000,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2008/03/20 14:01:10 | 000,000,636 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/03/18 20:44:18 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/03/18 20:40:20 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/03/18 20:34:20 | 000,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/03/18 20:34:20 | 000,000,120 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/03/18 20:11:23 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2008/03/18 20:11:19 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/03/18 20:10:08 | 000,001,119 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2008/02/16 23:12:14 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\ASPRTMM0.DLL
[2007/10/16 10:13:46 | 000,083,344 | ---- | C] () -- C:\WINDOWS\System32\MaCommAPI.dll
[2007/10/10 21:15:50 | 000,042,384 | ---- | C] () -- C:\WINDOWS\System32\MaMakeUp.dll
[2007/07/25 04:24:30 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/06/29 22:11:36 | 000,045,113 | ---- | C] () -- C:\WINDOWS\System32\ETKCommAPIWeb.dll
[2007/06/29 22:11:34 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ETKDataMngrWeb.dll
[2006/12/12 11:15:00 | 000,008,517 | ---- | C] () -- C:\WINDOWS\System32\np_kor.ini
[2006/11/07 06:25:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/09/17 11:12:46 | 000,950,272 | ---- | C] () -- C:\WINDOWS\System32\npdownv.exe
[2006/09/17 00:36:50 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/02/26 05:08:28 | 000,585,728 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/01/05 17:02:22 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\npnv3uninst.exe
[2005/11/18 16:53:56 | 000,505,856 | ---- | C] () -- C:\WINDOWS\System32\ictprn.dll
[2005/08/01 19:46:48 | 000,042,496 | ---- | C] () -- C:\WINDOWS\System32\ALZZip.BIN
[2005/08/01 19:46:08 | 000,062,464 | ---- | C] () -- C:\WINDOWS\System32\ALZALZ.BIN
[2005/06/14 21:27:46 | 000,225,280 | ---- | C] () -- C:\WINDOWS\System32\HKDown.exe
[2005/05/17 16:36:26 | 000,008,023 | ---- | C] () -- C:\WINDOWS\System32\np_eng.ini
[2005/05/12 17:29:36 | 000,008,821 | ---- | C] () -- C:\WINDOWS\System32\np_jpn.ini
[2005/03/08 13:38:20 | 000,006,808 | ---- | C] () -- C:\WINDOWS\System32\np_chs.ini
[2004/08/11 19:24:19 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/11 19:19:30 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/11 19:12:14 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 19:11:31 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 19:07:24 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/11 19:06:43 | 000,379,608 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 19:00:30 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/11 19:00:28 | 000,487,662 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/11 19:00:28 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/11 19:00:28 | 000,089,124 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/11 19:00:28 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/11 19:00:27 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/11 19:00:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/11 19:00:24 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/11 19:00:19 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/11 19:00:19 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/11 19:00:12 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/11 19:00:04 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/01/10 17:26:02 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\MACS.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/04 10:16:34 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
========== Files - Unicode (All) ==========
[2011/03/04 10:48:03 | 000,038,912 | ---- | M] ()(C:\Documents and Settings\Jean\My Documents\OCEAN ?? ??.doc) -- C:\Documents and Settings\Jean\My Documents\OCEAN 작업 단계.doc
[2011/03/02 18:39:10 | 000,016,384 | ---- | M] ()(C:\Documents and Settings\Jean\My Documents\?? ???? ??.xls) -- C:\Documents and Settings\Jean\My Documents\해상 소요시간 비교.xls
[2011/03/02 18:39:10 | 000,016,384 | ---- | C] ()(C:\Documents and Settings\Jean\My Documents\?? ???? ??.xls) -- C:\Documents and Settings\Jean\My Documents\해상 소요시간 비교.xls
[2011/02/22 19:03:59 | 000,038,912 | ---- | C] ()(C:\Documents and Settings\Jean\My Documents\OCEAN ?? ??.doc) -- C:\Documents and Settings\Jean\My Documents\OCEAN 작업 단계.doc
[2011/01/19 10:16:01 | 000,016,384 | ---- | M] ()(C:\Documents and Settings\Jean\My Documents\LAX SAV ?? ??.xls) -- C:\Documents and Settings\Jean\My Documents\LAX SAV 해상 운임.xls
[2011/01/19 10:16:01 | 000,016,384 | ---- | C] ()(C:\Documents and Settings\Jean\My Documents\LAX SAV ?? ??.xls) -- C:\Documents and Settings\Jean\My Documents\LAX SAV 해상 운임.xls
[2010/12/17 12:00:06 | 000,273,408 | ---- | M] ()(C:\Documents and Settings\Jean\My Documents\??? ?? ???.doc) -- C:\Documents and Settings\Jean\My Documents\거래처 주소 레이블.doc
[2010/12/14 18:10:03 | 000,273,408 | ---- | C] ()(C:\Documents and Settings\Jean\My Documents\??? ?? ???.doc) -- C:\Documents and Settings\Jean\My Documents\거래처 주소 레이블.doc
[2010/11/09 13:09:11 | 000,015,697 | ---- | M] ()(C:\Documents and Settings\Jean\My Documents\??? INV ???? ?? LIST.pdf) -- C:\Documents and Settings\Jean\My Documents\통관시 INV 더할것과 뺄것 LIST.pdf
[2010/11/09 13:09:11 | 000,015,697 | ---- | C] ()(C:\Documents and Settings\Jean\My Documents\??? INV ???? ?? LIST.pdf) -- C:\Documents and Settings\Jean\My Documents\통관시 INV 더할것과 뺄것 LIST.pdf
[2010/11/02 17:13:46 | 000,039,936 | ---- | M] ()(C:\Documents and Settings\Jean\My Documents\??? ??.doc) -- C:\Documents and Settings\Jean\My Documents\조정훈 주소.doc
[2010/11/02 17:13:46 | 000,039,936 | ---- | C] ()(C:\Documents and Settings\Jean\My Documents\??? ??.doc) -- C:\Documents and Settings\Jean\My Documents\조정훈 주소.doc
(C:\Documents and Settings\All Users\Start Menu\Programs\Google ????) -- C:\Documents and Settings\All Users\Start Menu\Programs\Google 업데이터
(C:\Documents and Settings\All Users\Start Menu\Programs\??????) -- C:\Documents and Settings\All Users\Start Menu\Programs\이스트소프트
< End of report >