This one is from OTL.txt
OTL logfile created on: 2010-04-20 오후 10:09:38 - Run 1
OTL by OldTimer - Version 3.2.1.2 Folder = c:\Users\Westwood206\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000412 | Country: Korea | Language: KOR | Date Format: yyyy-MM-dd
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 0.35 Gb Free Space | 0.72% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 5.97 Gb Free Space | 61.14% Space Free | Partition Type: NTFS
Unable to calculate disk information.
F: Drive not present or media not loaded
Drive G: | 232.88 Gb Total Space | 47.27 Gb Free Space | 20.30% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
Drive I: | 999.63 Mb Total Space | 116.66 Mb Free Space | 11.67% Space Free | Partition Type: FAT
Drive L: | 74.36 Gb Total Space | 1.79 Gb Free Space | 2.41% Space Free | Partition Type: FAT32
Computer Name: WESTWOOD206-PC
Current User Name: Westwood206
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010-04-18 16:25:56 | 000,562,176 | ---- | M] (OldTimer Tools) -- c:\Users\Westwood206\Downloads\OTL.exe
PRC - [2010-04-15 19:22:44 | 002,618,752 | ---- | M] (Daum Communications Corp.) -- C:\Program Files\Daum\Cleaner\DaumCleaner.exe
PRC - [2010-04-15 19:22:44 | 000,157,056 | ---- | M] (Daum Communications Corp.) -- C:\Program Files\Daum\Cleaner\DaumCleanerService.exe
PRC - [2010-01-20 23:22:44 | 000,792,440 | ---- | M] (ESTsoft Corp) -- C:\Program Files\ESTsoft\ALYac\AYAgent.aye
PRC - [2010-01-14 15:44:26 | 000,886,648 | ---- | M] (ESTsoft Corp) -- C:\Program Files\ESTsoft\ALYac\AYServiceNT.aye
PRC - [2009-10-08 13:13:52 | 000,818,288 | ---- | M] (The Weather Channel Interactive, Inc.) -- C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
PRC - [2009-02-06 18:07:48 | 000,027,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008-10-28 23:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008-10-10 20:40:00 | 000,036,864 | ---- | M] () -- C:\Program Files\safe fence\sfencertsvc.exe
PRC - [2008-06-15 00:50:46 | 000,069,632 | ---- | M] (SoftRun Inc.) -- C:\Users\Public\SoftRun\NoPhishing\NPM.exe
PRC - [2008-06-12 22:17:01 | 000,042,168 | ---- | M] (Antony Lewis) -- C:\Program Files\WordWeb\wweb32.exe
PRC - [2008-06-02 19:50:34 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008-06-02 19:50:32 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008-01-28 18:23:21 | 000,199,368 | ---- | M] (AhnLab, Inc.) -- C:\Program Files\AhnLab\Smart Update Utility\AhnSD.exe
PRC - [2008-01-19 00:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008-01-19 00:33:35 | 001,143,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wercon.exe
PRC - [2007-10-10 18:45:34 | 000,111,288 | ---- | M] (NHN Corp.) -- C:\Program Files\Naver\NaverCommon\NaverAdminAPISvc.exe
PRC - [2007-09-14 18:12:20 | 000,049,152 | ---- | M] () -- C:\Users\Public\SoftRun\NoPhishing\NPNTService.exe
PRC - [2007-07-12 13:28:48 | 000,016,384 | ---- | M] ((주)싸이퍼로지스) -- C:\Windows\System32\PSCenter.exe
========== Modules (SafeList) ========== MOD - [2010-04-18 16:25:56 | 000,562,176 | ---- | M] (OldTimer Tools) -- c:\Users\Westwood206\Downloads\OTL.exe
MOD - [2008-01-19 00:34:41 | 000,545,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IME\imekr8\imkrtip.dll
MOD - [2008-01-19 00:34:41 | 000,113,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IME\imekr8\imkrapi.dll
MOD - [2008-01-19 00:34:40 | 000,363,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IME\shared\IMETIP.DLL
MOD - [2008-01-19 00:34:40 | 000,126,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IME\shared\IMJKAPI.DLL
MOD - [2008-01-19 00:26:34 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- -- (Steam Client Service)
SRV - [2010-04-15 19:22:44 | 000,157,056 | ---- | M] (Daum Communications Corp.) [On_Demand | Running] -- C:\Program Files\Daum\Cleaner\DaumCleanerService.exe -- (DaumCleanerService)
SRV - [2010-03-15 12:50:36 | 001,142,224 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2010-03-11 12:09:22 | 000,366,840 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2010-01-19 08:51:42 | 003,845,388 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2010-01-14 15:44:26 | 000,886,648 | ---- | M] (ESTsoft Corp) [Auto | Running] -- C:\Program Files\ESTsoft\ALYac\AYServiceNT.aye -- (ALYac_PZSrv)
SRV - [2009-08-24 05:16:12 | 000,378,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2008-10-10 20:40:00 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\Program Files\safe fence\sfencertsvc.exe -- (SafefenceRtSvc)
SRV - [2008-07-24 14:12:10 | 000,045,072 | ---- | M] () [Auto | Running] -- C:\Program Files\Freechal\PlusBar\pbsv.dll -- (pbsv)
SRV - [2008-06-02 19:50:34 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2008-01-19 00:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007-10-10 18:45:34 | 000,111,288 | ---- | M] (NHN Corp.) [Auto | Running] -- C:\Program Files\Naver\NaverCommon\NaverAdminAPISvc.exe -- (Naver Updater)
SRV - [2007-09-14 18:12:20 | 000,049,152 | ---- | M] () [Auto | Running] -- C:\Users\Public\SoftRun\NoPhishing\NPNTService.exe -- (NoPhishing)
SRV - [2007-07-12 13:28:48 | 000,016,384 | ---- | M] ((주)싸이퍼로지스) [Auto | Running] -- C:\Windows\System32\PSCenter.exe -- (PCsafer Online Monitoring Center)
SRV - [2007-01-25 10:31:34 | 000,093,048 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
========== Driver Services (SafeList) ========== DRV - [2010-04-12 11:26:58 | 000,019,384 | ---- | M] (SoftForum Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\JRSKD24.sys -- (JRSKD24)
DRV - [2010-04-12 11:26:58 | 000,012,728 | ---- | M] (SoftForum Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\JRSUKD25.SYS -- (JRSUKD25)
DRV - [2010-03-10 11:36:36 | 000,217,032 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2010-03-02 18:08:07 | 000,175,872 | ---- | M] (SoftCamp) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\scskusbs.sys -- (scskusbs)
DRV - [2010-03-02 18:08:07 | 000,018,184 | ---- | M] (SoftCamp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\scskusbf.sys -- (scskusbf)
DRV - [2009-12-20 23:14:00 | 000,121,504 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\AhnLab\ASP\MyFirewall 4.0\mfipsent.sys -- (MfIPSEnt)
DRV - [2009-12-20 23:14:00 | 000,101,336 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\AhnLab\ASP\MyFirewall 4.0\mffwent.sys -- (MfFWEnt)
DRV - [2009-12-18 01:27:00 | 000,087,648 | ---- | M] (AhnLab, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\AmonTDLh.sys -- (AMonTDLH)
DRV - [2009-12-07 03:31:38 | 000,015,104 | ---- | M] ((c)NOWCOM) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\nowmemdf.sys -- (NOWMEMDF)
DRV - [2009-07-20 18:13:00 | 000,019,616 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CdmDrvNt.sys -- (CdmDrvNt)
DRV - [2009-05-14 18:10:42 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009-03-08 01:37:00 | 007,745,696 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008-12-18 20:57:44 | 000,024,312 | ---- | M] (ESTsoft Corp) [Kernel | On_Demand | Stopped] -- C:\Program Files\ESTsoft\ALYac\AYDrvSP.sys -- (AYDrvSP_ALYAC)
DRV - [2008-12-13 16:47:39 | 000,006,784 | ---- | M] (SoftForum Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\JRSUKD24.sys -- (JRSUKD24)
DRV - [2008-10-22 16:05:08 | 000,432,128 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rtl8192u.sys -- (RTL8192U)
DRV - [2008-10-18 01:32:00 | 000,131,072 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Mkd2kfNT.sys -- (Mkd2kfNt)
DRV - [2008-10-18 01:32:00 | 000,079,104 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Mkd2Nadr.sys -- (Mkd2Nadr)
DRV - [2008-09-26 14:06:40 | 000,020,424 | ---- | M] (ESTsoft Corp) [Kernel | On_Demand | Running] -- C:\Program Files\ESTsoft\ALYac\AYDrvNT.sys -- (AYDrvNT_ALYAC)
DRV - [2008-09-09 18:06:44 | 002,167,128 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008-06-02 19:49:48 | 000,305,688 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\iastor.sys -- (iaStor)
DRV - [2008-05-08 05:05:18 | 000,266,752 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSXHWBS2.sys -- (HSXHWBS2)
DRV - [2008-05-08 05:04:16 | 000,661,504 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSX_CNXT.sys -- (winachsf)
DRV - [2008-05-08 05:03:18 | 000,980,992 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSX_DP.sys -- (HSF_DP)
DRV - [2008-04-20 22:01:12 | 000,058,752 | ---- | M] (NHN) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NSavFlt.sys -- (NSavFlt)
DRV - [2008-01-18 22:53:23 | 000,073,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2007-10-18 07:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007-04-13 05:56:48 | 000,279,680 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vvftav.sys -- (vvftav)
DRV - [2007-04-13 05:56:46 | 000,100,096 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmcam326av.sys -- (vmcam326av)
DRV - [2007-01-25 10:31:34 | 000,042,000 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\npf.sys -- (NPF)
DRV - [2006-11-02 02:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2006-11-02 02:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2006-11-02 02:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2006-11-02 02:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2006-11-02 02:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2006-11-02 02:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2006-11-02 02:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2006-11-02 02:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2006-11-02 02:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2006-11-02 02:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006-11-02 02:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006-11-02 02:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2006-11-02 02:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2006-11-02 02:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006-11-02 02:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006-11-02 02:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2006-11-02 02:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2006-11-02 02:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006-11-02 02:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2006-11-02 02:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2006-11-02 02:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2)
DRV - [2006-11-02 02:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2006-11-02 02:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2006-11-02 02:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006-11-02 02:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006-11-02 02:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2006-11-02 02:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006-11-02 02:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2006-11-02 02:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006-11-02 02:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006-11-02 02:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006-11-02 02:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2006-11-02 02:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2006-11-02 02:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2006-11-02 02:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2006-11-02 01:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006-11-02 01:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006-11-02 01:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006-11-02 01:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006-11-02 01:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006-11-02 01:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006-11-02 00:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006-11-02 00:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2005-06-24 17:36:16 | 000,039,036 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2005-05-26 10:01:36 | 000,038,144 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2005-05-26 10:01:18 | 000,021,344 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.daum.net/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {99E00A4C-D35E-11DD-BA95-9B6A56D89593}:2.2
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-04-03 07:02:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-04-03 07:02:11 | 000,000,000 | ---D | M]
[2009-10-02 21:49:18 | 000,000,000 | ---D | M] -- C:\Users\Westwood206\AppData\Roaming\Mozilla\Extensions
[2010-04-20 21:06:08 | 000,000,000 | ---D | M] -- C:\Users\Westwood206\AppData\Roaming\Mozilla\Firefox\Profiles\rv60i80m.default\extensions
[2009-10-03 10:00:14 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Westwood206\AppData\Roaming\Mozilla\Firefox\Profiles\rv60i80m.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010-04-12 01:38:15 | 000,000,000 | ---D | M] (ooVoo Toolbar) -- C:\Users\Westwood206\AppData\Roaming\Mozilla\Firefox\Profiles\rv60i80m.default\extensions\{99E00A4C-D35E-11DD-BA95-9B6A56D89593}
[2009-10-02 21:49:02 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008-11-18 06:04:58 | 000,189,952 | ---- | M] ((주) 그래텍) -- C:\Program Files\Mozilla Firefox\plugins\NPGomtvx_nie.dll
[2009-10-31 23:23:20 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
O1 HOSTS File: ([2006-09-18 14:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Updater For ooVoo Toolbar) - {442AE524-EBA5-4b17-82F3-888D68BC999A} - C:\Program Files\oovootb\auxi\oovooAu.dll (Visicom Media)
O2 - BHO: (Click-to-Call BHO) - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll (Microsoft Corporation)
O2 - BHO: (ooVoo Toolbar) - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll ()
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O3 - HKLM\..\Toolbar: (The Weather Channel Toolbar) - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\Windows\System32\TwcToolbarIe7.dll ()
O3 - HKLM\..\Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - No CLSID value found.
O3 - HKLM\..\Toolbar: (ooVoo Toolbar) - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {638886B2-CF33-4EA0-AFF8-DC8E504500CB} - No CLSID value found.
O4 - HKLM..\Run: [AHNSD] C:\Program Files\AhnLab\Smart Update Utility\AhnSD.exe (AhnLab, Inc.)
O4 - HKLM..\Run: [ALYac] C:\Program Files\ESTsoft\ALYac\AYUpdate.exe (ESTsoft Corp)
O4 - HKLM..\Run: [ClubBox] File not found
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [imekrmig7.0] C:\Program Files\Common Files\Microsoft Shared\IME\IMKR7\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [Pdbox28] File not found
O4 - HKLM..\Run: [Rainbow] File not found
O4 - HKLM..\Run: [showupdate] C:\Program Files\donkeyplus\show\update.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DaumCleaner] C:\Program Files\Daum\Cleaner\DaumCleaner.exe (Daum Communications Corp.)
O4 - HKCU..\Run: [donkeymp3] C:\Program Files\donkeymp3\update_check.exe (당나귀p2p)
O4 - HKCU..\Run: [donkeyp2p] C:\Program Files\donkeyp2p\update_check.exe (당나귀p2p)
O4 - HKCU..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [UmileEncoder] C:\ProgramData\Umile\UmileEncoder\LiveUpdator\zUpdator.exe ( )
O4 - Startup: C:\Users\Westwood206\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe (Antony Lewis)
O9 - Extra Button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Value error. File not found
O9 - Extra Button: HP 클립북 - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP 스마트 선택 - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: 사쿠라캐쉬 - {B9F6E34F-369A-443F-BBB6-E610771F619E} - Reg Error: Key error. File not found
O9 - Extra Button: Download YouTube video - {be473d99-52cc-45c8-a04e-6b093a607766} - C:\Program Files\YouTube Clip Extractor\ClipExtractor.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKCU\..Trusted Domains: arumin.co.kr ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: arumin.co.kr ([]추가동의일 is out of zone range - 20081228)
O15 - HKCU\..Trusted Domains: cyworld.com ([cyxso] http in Trusted sites)
O15 - HKCU\..Trusted Domains: cyworld.com ([minihp] http in Trusted sites)
O15 - HKCU\..Trusted Domains: cyworld.com ([www] * in Trusted sites)
O15 - HKCU\..Trusted Domains: cyworld.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: freechal.com ([2war] http in Trusted sites)
O15 - HKCU\..Trusted Domains: lgcard.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: lgcard.com ([]추가동의일 is out of zone range - 20081228)
O15 - HKCU\..Trusted Domains: mafiaonline.kr ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: nate.com ([br] http in Trusted sites)
O15 - HKCU\..Trusted Domains: naver.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: netmarble.net ([suddenattack] http in Trusted sites)
O15 - HKCU\..Trusted Domains: sayclub.com ([pmang] http in Trusted sites)
O15 - HKCU\..Trusted Domains: shinhan.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: shinhan.com ([]추가동의일 is out of zone range - 20081228)
O15 - HKCU\..Trusted Domains: shinhancard.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: shinhancard.com ([]추가동의일 is out of zone range - 20081228)
O15 - HKCU\..Trusted Domains: teacher.co.kr ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: unitel.co.kr ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: weppy.com ([]* in Trusted sites)
O16 - DPF: {0349EF81-B9C1-4B97-86F7-7B931D0E2532} http://sticube.clubbox.co.kr/sticubeupdate/cab/NowStarter2.cab (NowStarter2 Control)
O16 - DPF: {0CBF7EDC-17EC-442C-8AE9-5E804707B6CA} http://dist.cdnetworks.co.kr/cdndist/neffy/Neffy.cab (NeffyClient Class)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} https://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB (Tpwin Control)
O16 - DPF: {25794D3C-E2F0-40B8-9C11-F38DC1908633} http://activexdown.paran.com/paranactivex/data/uploadlauncher.cab (Maildropfile Control)
O16 - DPF: {39461460-2552-4D51-A062-3AB6A7B902E9} http://img.shinhan.com/shttp/install/down/INIS70.cab (INISAFE Updater Control)
O16 - DPF: {39FC0CF9-86F3-4502-B773-D16706EDEC83} http://img.shinhan.com/rib/common/keyStroke/SoftCamp/403125/SCSK4_VISTA.cab (SCSK Control)
O16 - DPF: {3B56E5F0-7B20-48BF-B439-A995BE5191EF} http://pib.wooribank.com/com/common/SessionControl.cab (SessionControl Control)
O16 - DPF: {4875D0C5-5FE1-4488-8BB8-5A7D0ECDF93B} http://mail.nate.com/bigmail/NateFilebox.cab (Nate Filebox Control)
O16 - DPF: {4AEA51B9-CD5D-4555-81C0-642ACF1E16B9} http://www.cityracer.co.kr/gamestart/HydiLauncher.cab (Hydi Game Launcher)
O16 - DPF: {5267557D-D090-44EA-BCAA-8576A24810C5} http://download.netmarble.net/web/6N/pccheck/SystemInformerCJI1004.cab (SysInfoCJI Class)
O16 - DPF: {62076E39-043C-4A5A-BF17-D8A2128ACD93} http://pib.wooribank.com/com/installer/interezen/WRebw.cab (WRebw Module)
O16 - DPF: {66413DC2-F891-40BC-822D-B7EEC8ADC281} http://img.shinhan.com/rib/common/ProWorksGrid_78.cab (ProWorksGrid Control)
O16 - DPF: {6CE20149-ABE3-462E-A1B4-5B549971AA38} http://ck.softforum.co.kr/CKKeyPro/wooribank/CKKeyPro3017_32k.cab (XecureCKKB Class)
O16 - DPF: {7B1BB066-7BBB-11D4-A34E-0000F01A209C} http://login.unitel.co.kr/iplug/lmgr2130.cab (UniAuth Class)
O16 - DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} http://download.softforum.co.kr/Published/XecureWeb/v7.2.2.8/xw_install.cab (XecureWeb 4.0 Client Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} https://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8DC067B8-911D-473A-90F1-1171B887CDE0} http://pann.nate.com/html/editor/CyPictureU.cab?20090430 (CyImage Class)
O16 - DPF: {93C449FA-ECFB-402F-A8C7-37E4F8D60E49} http://dl.pmang.com/common/pmangctl/pmangax.cab (Pmang Login Control)
O16 - DPF: {970E1B88-8AC1-4E31-86D6-BFA769CEF7A6} http://www.ebse.co.kr/ebs/ActiveX/eGEBS_vista.cab (eGSignPlus For_EBS Class)
O16 - DPF: {971A5328-1926-4ED6-B899-6C01338D4B32} http://2war.freechal.com/Activex/Norazo2_40.cab (DCLinker Class)
O16 - DPF: {9EA96532-D7EA-4C49-BFED-A2C607BDDF02} http://login.unitel.co.kr/iplug/download_mail.cab (FileBox File Transfer Class)
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab (BatchDownloader Class)
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} http://download.netmarble.net/kdefence/kdf8305.cab (Kdfense8 Control)
O16 - DPF: {A7512E45-3E11-4145-B1AE-6E06B397145D} http://www.ebse.co.kr/ebs/ActiveX/MagicControllerVista2.cab (MagicControllerVista2 Control)
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} http://id.hangame.com/common/HanSetup1020.cab (HanSetupCtrl1010 Class)
O16 - DPF: {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA} http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_14-windows-i586.cab (Java Plug-in 1.5.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CB5C683C-416A-4701-B018-0F1B21D64D6B} http://cyimg7.cyworld.com/cymusic/package/skcinst.cab (SKCInst1 Class)
O16 - DPF: {D912AABC-6CB0-416F-85B6-CABBB86FD558} https://plugin.inicis.com/wallet60/INIwallet60_vista.cab (INIwallet60 Control)
O16 - DPF: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} http://www.clubbox.co.kr/neo.fld/MultiUpload.cab (MultiUpload Control)
O16 - DPF: {FE342FC7-4374-4EBE-86DB-D73AE861F779} http://file.naver.com/activex/test/NaverAXGuide.cab (NaverAXGuide Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 64.105.132.250 64.105.132.252 192.168.2.1
O18 - Protocol\Handler\s-http {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - C:\Program Files\INITECH\SHTTP\InitechSHTTPInterface.10118.dll ((c) INITECH)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Westwood206\Desktop\aran\VIOLIN-1.jpg
O24 - Desktop BackupWallPaper: C:\Users\Westwood206\Desktop\aran\VIOLIN-1.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009-12-10 15:06:18 | 000,000,059 | RHS- | M] () - L:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{91ceab03-337b-11dd-878f-001d60d18b03}\Shell\AutoRun\command - "" = nqdymj.exe
O33 - MountPoints2\{91ceab03-337b-11dd-878f-001d60d18b03}\Shell\open\Command - "" = nqdymj.exe
O33 - MountPoints2\{a5c68f59-6666-11de-9cba-001d60d18b03}\Shell\AutoRun\command - "" = F:\abcgtvcq.cmd -- File not found
O33 - MountPoints2\{a5c68f59-6666-11de-9cba-001d60d18b03}\Shell\open\Command - "" = F:\abcgtvcq.cmd -- File not found
O33 - MountPoints2\{c137804b-56e6-11de-a1b0-001d60d18b03}\Shell - "" = AutoRun
O33 - MountPoints2\{c137804b-56e6-11de-a1b0-001d60d18b03}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010-04-19 18:17:12 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010-04-18 12:28:00 | 000,000,000 | ---D | C] -- C:\Users\Westwood206\AppData\Local\svvnbhlay
[2010-04-17 17:36:30 | 000,000,000 | ---D | C] -- C:\Users\Westwood206\AppData\Local\Daum
[2010-04-17 11:55:21 | 000,000,000 | ---D | C] -- C:\Users\Westwood206\AppData\Roaming\Malwarebytes
[2010-04-17 11:55:16 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010-04-17 11:55:14 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010-04-17 11:55:14 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010-04-17 11:55:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010-04-17 11:15:23 | 000,233,136 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2010-04-17 11:15:23 | 000,100,136 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2010-04-17 11:15:21 | 000,217,032 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2010-04-17 11:15:21 | 000,088,040 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2010-04-17 11:15:19 | 000,070,408 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2010-04-17 11:15:15 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010-04-17 11:15:15 | 000,000,000 | ---D | C] -- C:\Users\Westwood206\AppData\Roaming\PC Tools
[2010-04-17 11:15:15 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2010-04-17 11:15:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010-04-15 20:51:26 | 000,000,000 | ---D | C] -- C:\Users\Westwood206\AppData\Local\qrvdgooxx
[2010-04-14 08:53:00 | 003,598,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010-04-14 08:52:59 | 003,545,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2010-04-14 08:52:59 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2010-04-14 08:52:58 | 000,062,464 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\l3codeca.acm
[2010-04-12 01:38:15 | 000,000,000 | ---D | C] -- C:\ProgramData\EmailNotifier
[2010-04-12 01:38:12 | 000,000,000 | ---D | C] -- C:\Program Files\oovootb
[2010-04-12 01:38:08 | 000,000,000 | ---D | C] -- C:\Program Files\ooVoo
[2010-04-11 14:39:53 | 000,000,000 | ---D | C] -- C:\Users\Westwood206\AppData\Roaming\Mini Search
[2010-04-07 13:14:46 | 000,652,416 | ---- | C] ((c) Nowcom) -- C:\Windows\System32\NowUpdate.exe
[2010-03-31 22:53:25 | 000,418,312 | ---- | C] (서치링크) -- C:\Windows\System32\clubbox_buddysearch.exe
[2010-03-30 21:38:39 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2010-03-30 21:38:38 | 001,383,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2010-03-30 21:38:38 | 000,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2010-03-30 21:38:38 | 000,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2010-03-30 21:38:38 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2010-03-30 21:38:38 | 000,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010-03-30 21:38:38 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2010-03-30 21:38:38 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010-03-30 21:38:38 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll
[2010-03-30 21:38:38 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010-03-30 21:38:38 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2010-03-25 20:16:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Software Update Utility
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[10 C:\Users\Westwood206\Desktop\*.tmp files -> C:\Users\Westwood206\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Westwood206\*.tmp files -> C:\Users\Westwood206\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010-04-20 22:10:49 | 006,029,312 | -HS- | M] () -- C:\Users\Westwood206\NTUSER.DAT
[2010-04-20 21:27:25 | 000,694,964 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010-04-20 21:27:25 | 000,589,884 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010-04-20 21:27:25 | 000,101,896 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010-04-20 21:23:00 | 000,000,686 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3000271694-3872876465-734515343-1001UA.job
[2010-04-20 21:23:00 | 000,000,634 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3000271694-3872876465-734515343-1001Core.job
[2010-04-20 21:15:00 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010-04-20 21:15:00 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010-04-20 19:15:18 | 000,000,430 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{F0A26B0C-58A1-443C-8A99-DA4BD0F7C970}.job
[2010-04-20 19:14:50 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010-04-20 19:14:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010-04-20 01:35:20 | 000,524,288 | -HS- | M] () -- C:\Users\Westwood206\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2010-04-20 01:35:20 | 000,065,536 | -HS- | M] () -- C:\Users\Westwood206\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010-04-20 01:34:40 | 003,904,046 | -H-- | M] () -- C:\Users\Westwood206\AppData\Local\IconCache.db
[2010-04-19 18:24:36 | 000,002,032 | ---- | M] () -- C:\Users\Westwood206\AppData\Local\d3d9caps.dat
[2010-04-18 16:34:23 | 000,205,824 | ---- | M] () -- C:\Users\Westwood206\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-04-12 20:16:55 | 000,000,098 | ---- | M] () -- C:\Windows\System32\fscflist.ini
[2010-04-12 19:55:57 | 000,000,079 | ---- | M] () -- C:\Windows\System32\fscagent.ini
[2010-04-12 19:53:55 | 000,000,000 | ---- | M] () -- C:\Windows\System32\PDBOXGame.html
[2010-04-12 11:26:58 | 000,019,384 | ---- | M] (SoftForum Corporation) -- C:\Windows\System32\JRSKD24.sys
[2010-04-12 11:26:58 | 000,012,728 | ---- | M] (SoftForum Corporation) -- C:\Windows\System32\JRSUKD25.SYS
[2010-04-12 01:38:08 | 000,000,549 | ---- | M] () -- C:\Users\Public\Desktop\ooVoo.lnk
[2010-04-11 20:18:07 | 000,000,162 | -H-- | M] () -- C:\Users\Westwood206\Desktop\~$quote.doc
[2010-04-07 13:14:46 | 000,652,416 | ---- | M] ((c) Nowcom) -- C:\Windows\System32\NowUpdate.exe
[2010-04-06 02:01:21 | 002,838,528 | ---- | M] (Nowcom, Co. LTD.) -- C:\Windows\System32\clubbox.exe
[2010-04-04 10:21:17 | 000,000,162 | -H-- | M] () -- C:\Users\Westwood206\Desktop\~$search 02.doc
[2010-04-04 08:19:09 | 000,000,162 | -H-- | M] () -- C:\Users\Westwood206\Desktop\~$search 01.doc
[2010-03-30 16:38:16 | 000,167,936 | ---- | M] (Nowcom Co., Ltd.) -- C:\Windows\System32\fscagent.exe
[2010-03-30 16:36:42 | 000,163,840 | ---- | M] ((주)나우콤) -- C:\Windows\System32\downengine.dll
[2010-03-30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010-03-30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010-03-26 19:46:19 | 000,000,647 | ---- | M] () -- C:\Users\Public\Desktop\Global RBF.lnk
[2010-03-25 20:16:31 | 000,000,719 | -H-- | M] () -- C:\IPH.PH
[2010-03-25 20:16:29 | 000,001,696 | ---- | M] () -- C:\Users\Public\Desktop\AIM.lnk
[2010-03-25 15:35:52 | 000,075,264 | ---- | M] () -- C:\Users\Westwood206\Desktop\inaResume.doc
[2010-03-25 15:25:17 | 000,029,184 | ---- | M] () -- C:\Users\Westwood206\Desktop\과외광고.doc
[2010-03-22 01:12:20 | 000,418,312 | ---- | M] (서치링크) -- C:\Windows\System32\clubbox_buddysearch.exe
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[10 C:\Users\Westwood206\Desktop\*.tmp files -> C:\Users\Westwood206\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Westwood206\*.tmp files -> C:\Users\Westwood206\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010-04-17 11:15:23 | 000,007,387 | ---- | C] () -- C:\Windows\System32\drivers\pctgntdi.cat
[2010-04-17 11:15:21 | 000,007,412 | ---- | C] () -- C:\Windows\System32\drivers\PCTAppEvent.cat
[2010-04-17 11:15:21 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctcore.cat
[2010-04-17 11:15:19 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctplsg.cat
[2010-04-12 01:38:08 | 000,000,549 | ---- | C] () -- C:\Users\Public\Desktop\ooVoo.lnk
[2010-04-11 20:18:07 | 000,000,162 | -H-- | C] () -- C:\Users\Westwood206\Desktop\~$quote.doc
[2010-04-04 10:21:17 | 000,000,162 | -H-- | C] () -- C:\Users\Westwood206\Desktop\~$search 02.doc
[2010-04-04 08:19:09 | 000,000,162 | -H-- | C] () -- C:\Users\Westwood206\Desktop\~$search 01.doc
[2010-03-26 19:46:19 | 000,000,647 | ---- | C] () -- C:\Users\Public\Desktop\Global RBF.lnk
[2010-03-25 15:05:07 | 000,029,184 | ---- | C] () -- C:\Users\Westwood206\Desktop\과외광고.doc
[2010-03-25 14:30:16 | 000,075,264 | ---- | C] () -- C:\Users\Westwood206\Desktop\inaResume.doc
[2009-10-08 15:23:54 | 000,921,600 | ---- | C] () -- C:\Windows\System32\vorbisenc.dll
[2009-10-08 15:23:54 | 000,237,568 | ---- | C] () -- C:\Windows\System32\OggDS.dll
[2009-10-08 15:23:54 | 000,188,416 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2009-10-08 15:23:54 | 000,045,056 | ---- | C] () -- C:\Windows\System32\Ogg.dll
[2009-09-04 01:17:55 | 000,065,536 | ---- | C] () -- C:\Windows\System32\cosa.dll
[2009-08-13 12:53:54 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2009-08-03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009-07-16 15:18:46 | 001,123,000 | ---- | C] () -- C:\Windows\System32\HanWebMsg1056.dll
[2009-07-08 19:41:38 | 000,066,920 | ---- | C] () -- C:\Windows\System32\CMListControl.dll
[2009-06-19 20:06:22 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2009-06-19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009-06-19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2009-06-19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2009-06-19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009-06-19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2009-06-19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2009-06-19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2009-06-19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2009-06-19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2009-05-14 18:10:42 | 000,717,296 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009-01-16 18:33:19 | 000,041,152 | ---- | C] () -- C:\Windows\System32\HanGamePlugin19.dll
[2008-12-25 19:10:39 | 000,000,226 | ---- | C] () -- C:\Windows\System32\WebPonent_Down.ini
[2008-12-25 19:10:05 | 000,000,310 | ---- | C] () -- C:\Windows\XBRL.ini
[2008-12-25 19:10:05 | 000,000,250 | ---- | C] () -- C:\Windows\Kind.ini
[2008-12-11 13:27:24 | 000,424,684 | ---- | C] () -- C:\Users\Westwood206\AppData\Roaming\com.kennettnet.MusicRescue4.Profiles.plist
[2008-12-11 12:53:20 | 000,080,117 | ---- | C] () -- C:\Users\Westwood206\AppData\Roaming\com.kennettnet.MusicRescue4.plist
[2008-12-10 07:39:00 | 000,000,000 | ---- | C] () -- C:\Users\Westwood206\ntuser.dat.LOG2
[2008-11-29 09:43:13 | 000,000,098 | ---- | C] () -- C:\Windows\System32\fscflist.ini
[2008-11-29 09:43:13 | 000,000,079 | ---- | C] () -- C:\Windows\System32\fscagent.ini
[2008-11-15 14:30:54 | 000,164,352 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2008-11-15 14:30:51 | 000,755,027 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2008-11-15 14:30:50 | 000,159,839 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2008-11-15 14:30:50 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2008-11-15 14:30:49 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2008-11-15 14:30:01 | 000,000,342 | ---- | C] () -- C:\Windows\wininit.ini
[2008-11-05 22:30:03 | 000,000,592 | ---- | C] () -- C:\Users\Westwood206\PodsBlitz-0.log.0
[2008-11-02 22:36:15 | 000,327,680 | ---- | C] () -- C:\Windows\System32\TwcToolbarIe7.dll
[2008-11-02 22:36:15 | 000,098,304 | ---- | C] () -- C:\Windows\System32\TwcToolbarBho.dll
[2008-10-06 18:36:53 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008-09-23 19:19:50 | 000,227,056 | ---- | C] () -- C:\Windows\System32\MuzLyrcs.dll
[2008-09-23 19:19:50 | 000,034,544 | ---- | C] () -- C:\Windows\System32\MzWhatImListen2.dll
[2008-09-23 17:43:02 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2008-08-20 16:30:46 | 000,000,037 | ---- | C] () -- C:\Windows\System32\PCClearPlusL.dll
[2008-08-15 11:51:42 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[2008-07-14 06:02:53 | 000,000,128 | ---- | C] () -- C:\ProgramData\nsavflt.hst
[2008-07-14 06:02:53 | 000,000,039 | ---- | C] () -- C:\ProgramData\ntavflt.hst
[2008-06-21 14:13:57 | 000,013,889 | ---- | C] () -- C:\Users\Westwood206\AppData\Roaming\com.kennettnet.MusicRescue.plist
[2008-06-21 14:13:56 | 000,001,422 | ---- | C] () -- C:\Users\Westwood206\AppData\Roaming\com.kennettnet.MusicRescueProfiles.plist
[2008-06-14 12:04:11 | 000,007,966 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2008-06-09 18:30:37 | 000,000,065 | ---- | C] () -- C:\Windows\FISHUI.INI
[2008-06-08 03:57:50 | 000,205,824 | ---- | C] () -- C:\Users\Westwood206\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008-06-08 01:52:39 | 000,077,824 | ---- | C] () -- C:\Windows\System32\nod.dll
[2008-06-07 23:49:44 | 001,139,384 | ---- | C] () -- C:\Windows\System32\HanWebMsg1053.dll
[2008-06-06 18:44:08 | 000,000,883 | ---- | C] () -- C:\Windows\FOK2.ini
[2008-06-05 23:02:38 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2008-06-05 20:53:04 | 000,524,288 | -HS- | C] () -- C:\Users\Westwood206\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2008-06-05 20:53:04 | 000,524,288 | -HS- | C] () -- C:\Users\Westwood206\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2008-06-05 20:53:04 | 000,002,032 | ---- | C] () -- C:\Users\Westwood206\AppData\Local\d3d9caps.dat
[2008-06-05 20:53:04 | 000,000,020 | -HS- | C] () -- C:\Users\Westwood206\ntuser.ini
[2008-06-05 20:53:03 | 006,029,312 | -HS- | C] () -- C:\Users\Westwood206\NTUSER.DAT
[2008-06-05 20:53:03 | 000,262,144 | -H-- | C] () -- C:\Users\Westwood206\ntuser.dat.LOG1
[2008-06-05 20:53:03 | 000,065,536 | -HS- | C] () -- C:\Users\Westwood206\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2008-05-30 17:06:08 | 000,044,560 | ---- | C] () -- C:\Windows\System32\plusbar.dll
[2008-01-14 10:24:18 | 000,053,248 | ---- | C] () -- C:\Windows\System32\WebPonent_Util.dll
[2007-01-25 10:31:36 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2006-11-02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006-11-02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005-09-12 01:31:40 | 000,266,240 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2003-03-05 18:57:50 | 000,005,021 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
========== Alternate Data Streams ==========
@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:082B157D
< End of report >