nicolo
Topic Starter
My accounts were compromised not too long ago on a website. I am wondering whether or not I have been infected with some type of malware? Perhaps something is lurking and broadcasting my private information?
Here are the results of the OTL scan:
OTL logfile created on: 4/22/2012 7:04:17 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = H:\antimalware
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 55.85% Memory free
6.00 Gb Paging File | 4.63 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 58.50 Gb Total Space | 7.27 Gb Free Space | 12.42% Space Free | Partition Type: NTFS
Drive D: | 106.67 Gb Total Space | 105.08 Gb Free Space | 98.51% Space Free | Partition Type: NTFS
Drive E: | 67.61 Gb Total Space | 66.05 Gb Free Space | 97.68% Space Free | Partition Type: NTFS
Drive G: | 90.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.78 Gb Total Space | 0.14 Gb Free Space | 3.62% Space Free | Partition Type: FAT32
Computer Name: INI-PC | User Name: Ini | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - H:\antimalware\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - G:\WINDOWS\IronKey.exe (IronKey, Inc.)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
PRC - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\HControl.exe (ASUS)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
PRC - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - G:\WINDOWS\zlib1.dll ()
MOD - G:\WINDOWS\ikvip.dll ()
MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll ()
MOD - C:\Program Files\SpywareGuard\sgmain.exe ()
MOD - C:\Program Files\SpywareGuard\sgbhp.exe ()
MOD - C:\Program Files\SpywareGuard\dlprotect.dll ()
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (BITCOMET_HELPER_SERVICE) – C:\Program Files\BitComet\tools\BitCometService.exe (www.BitComet.com)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ASLDRService) – C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)
SRV - (ATKGFNEXSrv) – C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
========== Driver Services (SafeList) ==========
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (cmdGuard) – C:\Windows\System32\drivers\cmdGuard.sys (COMODO)
DRV - (inspect) – C:\Windows\System32\drivers\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\Windows\System32\drivers\cmdhlp.sys (COMODO)
DRV - (AVerFx2hbtv) – C:\Windows\System32\drivers\AVerFx2hbtv.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV - (smserial) – C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (netw5v32) Intel® – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (MTsensor) – C:\Windows\System32\drivers\ATKACPI.sys (ASUS)
DRV - (netr28u) – C:\Windows\System32\drivers\netr28u.sys (Ralink Technology Corp.)
DRV - (ASMMAP) – C:\Program Files\ATKGFNEX\ASMMAP.sys ()
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&am;…000001561524eae
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F1 39 FC B3 F6 38 CB 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = playbryte/search/redirect/?type=default&user;_id=ff21076b-39b0-4b88-ba9f-5f1dca62f0e7&query;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://mail.google.com/mail/?shva=1#inbox"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: [removed]:0.2.4.1
FF - prefs.js..extensions.enabledItems: vshareus@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: [removed]:1.11
FF - prefs.js..extensions.enabledItems: {86095750-AD15-46d8-BF32-C0789F7E6A32}:1.0.75
FF - prefs.js..extensions.enabledItems: [removed]:3.11.3.15590
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@qq.com/QzoneMusic: C:\Program Files\Tencent\QQMusic\npQzoneMusic.dll (Tencent)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ini\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ini\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/22 18:59:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/05 02:08:43 | 000,000,000 | —D | M]
[2010/07/09 21:58:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Ini\AppData\Roaming\Mozilla\Extensions
[2012/03/05 02:08:43 | 000,000,000 | —D | M] (No name found) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions
[2012/03/05 02:08:44 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2012/01/02 02:41:07 | 000,000,000 | —D | M] (Browse For Change) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2012/01/02 09:59:33 | 000,000,000 | —D | M] (Babylon) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2011/07/27 07:22:55 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2012/01/02 02:41:28 | 000,000,000 | —D | M] (PlayBryte) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2012/01/02 02:40:39 | 000,000,000 | —D | M] (Yontoo) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2010/12/22 17:32:22 | 000,000,000 | —D | M] ("AutocompletePro - Your handy search suggestions tool") – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2011/12/20 22:50:21 | 000,000,000 | —D | M] (Ask Toolbar) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2010/10/16 20:17:41 | 000,000,000 | —D | M] (vShare Plugin) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\vshareus@toolbar
[2012/01/25 19:14:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/09 22:11:04 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
() (No name found) – C:\USERS\INI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EMEA68UB.DEFAULT\EXTENSIONS\{86095750-AD15-46D8-BF32-C0789F7E6A32}.XPI
[2012/04/22 18:59:50 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/03 02:59:20 | 000,917,816 | —- | M] (BitComet) – C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2011/03/18 15:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 15:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/09/10 02:19:24 | 000,305,152 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npuuseep.dll
[2012/04/22 18:59:48 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/22 18:59:48 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: 56ICANPlugin (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\igcnieghjaijfgekdbamdgbaicckhelo\1.0.0.1_0\np56icanplugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: BitCometAgent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: npruntime scriptable example plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npuuseep.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: QQMusic (Enabled) = C:\Program Files\Tencent\QQMusic\npQzoneMusic.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Ini\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Windows\system32\TVUAx\npTVUAx.dll
CHR - Extension: PlayBryte = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\akbkdomfdgaijlahpfcnhaifemjfdfnh\1.0_0\
CHR - Extension: YouTube = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AutocompletePro plugin for chrome = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.0_1\
CHR - Extension: Browse For Change = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkappjlcaehkpnjgompookobajdjkkfm\1.0_0\
CHR - Extension: 56icanplugin = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\igcnieghjaijfgekdbamdgbaicckhelo\1.0.0.1_0\
CHR - Extension: Yontoo = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\
CHR - Extension: Gmail = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (no name) - {06C7AD57-B655-418D-9AB8-9526A6D2E052} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [iBryte browseforchange Desktop] C:\Program Files\iBryte\browseforchange\ibrytedesktop.exe File not found
O4 - HKLM..\Run: [iBryte playbryte Desktop] C:\Program Files\iBryte\playbryte\ibrytedesktop.exe File not found
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKCU..\Run: [eMuleAutoStart] C:\Program Files\easyMule\eMule.exe -AutoStart File not found
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Epson all-in-one Registration.lnk = File not found
O4 - Startup: C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: &使用BitComet下載 - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &使用BitComet下載全部連結 - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlcdnet.asus.com/pub/ASUS/misc/dlm-…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{57B3753B-2457-4488-A559-ACAC8A1E45BE}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CAE96C25-6A77-4807-A3AB-8730E398450F}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE17E30D-C3B6-4F35-AA76-C57780891970}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/11/13 17:58:46 | 000,000,074 | R— | M] () - G:\AUTORUN.INF – [ CDFS ]
O32 - Unable to obtain root file information for disk H:\
O33 - MountPoints2\{cc134bba-8cc5-11e1-b1b6-90e6ba69a22d}\Shell - "" = AutoRun
O33 - MountPoints2\{cc134bba-8cc5-11e1-b1b6-90e6ba69a22d}\Shell\AutoRun\command - "" = G:\IronKey.exe – [2010/11/13 17:58:46 | 000,341,336 | R— | M] (IronKey Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: wave1 - C:\Windows\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave2 - C:\Windows\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/04/17 18:51:09 | 000,000,000 | —D | C] – C:\Users\Ini\Desktop\Originals
[2012/04/13 03:07:57 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/04/13 03:07:55 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/04/13 03:07:54 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/04/13 03:07:53 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/04/13 03:07:53 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/04/13 03:07:51 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/04/13 03:07:29 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/04/13 03:00:54 | 003,958,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/04/13 03:00:52 | 003,902,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/04/12 00:23:18 | 000,000,000 | —D | C] – C:\Users\Ini\Desktop\pic
[2012/03/28 07:11:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP560 series
========== Files - Modified Within 30 Days ==========
[2012/04/22 19:04:36 | 000,014,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 19:04:36 | 000,014,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 19:03:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000UA.job
[2012/04/22 18:57:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/22 18:56:57 | 2415,321,088 | -HS- | M] () – C:\hiberfil.sys
[2012/04/22 18:31:43 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/22 18:31:09 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/22 18:31:09 | 000,386,040 | —- | M] () – C:\Windows\System32\prfh0404.dat
[2012/04/22 18:31:09 | 000,369,938 | —- | M] () – C:\Windows\System32\prfh0804.dat
[2012/04/22 18:31:09 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/22 18:31:09 | 000,104,382 | —- | M] () – C:\Windows\System32\prfc0804.dat
[2012/04/22 18:31:09 | 000,099,468 | —- | M] () – C:\Windows\System32\prfc0404.dat
[2012/04/22 00:44:42 | 000,000,470 | —- | M] () – C:\Users\Ini\AppData\Roaming\Poladroid prefs.plist
[2012/04/22 00:44:20 | 000,233,733 | —- | M] () – C:\Users\Ini\Desktop\4537087038_ab8b3fb923_z.jpg
[2012/04/22 00:42:41 | 000,056,320 | -H– | M] () – C:\Users\Ini\Desktop\photothumb.db
[2012/04/22 00:39:47 | 000,161,454 | —- | M] () – C:\Users\Ini\Desktop\5688969793_d0f51e5f60_z.jpg
[2012/04/22 00:36:53 | 000,238,719 | —- | M] () – C:\Users\Ini\Desktop\IMG_0679.JPG
[2012/04/22 00:36:01 | 000,218,958 | —- | M] () – C:\Users\Ini\Desktop\IMG_0674.JPG
[2012/04/22 00:33:55 | 000,218,362 | —- | M] () – C:\Users\Ini\Desktop\IMG_0575.JPG
[2012/04/20 13:03:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000Core.job
[2012/04/12 22:43:14 | 000,002,385 | —- | M] () – C:\Users\Ini\Desktop\Google Chrome.lnk
[2012/04/04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
========== Files Created - No Company Name ==========
[2012/04/22 00:40:49 | 000,233,733 | —- | C] () – C:\Users\Ini\Desktop\4537087038_ab8b3fb923_z.jpg
[2012/04/22 00:39:46 | 000,161,454 | —- | C] () – C:\Users\Ini\Desktop\5688969793_d0f51e5f60_z.jpg
[2012/04/22 00:31:57 | 000,238,719 | —- | C] () – C:\Users\Ini\Desktop\IMG_0679.JPG
[2012/04/22 00:31:52 | 000,218,958 | —- | C] () – C:\Users\Ini\Desktop\IMG_0674.JPG
[2012/04/22 00:31:30 | 000,218,362 | —- | C] () – C:\Users\Ini\Desktop\IMG_0575.JPG
[2011/12/09 13:51:01 | 000,087,552 | —- | C] () – C:\Windows\System32\cpwmon2k.dll
[2011/11/30 21:53:45 | 000,013,931 | —- | C] () – C:\Windows\System32\RaCoInst.dat
[2010/11/19 01:15:41 | 000,000,470 | —- | C] () – C:\Users\Ini\AppData\Roaming\Poladroid prefs.plist
[2010/07/13 00:21:09 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/07/11 13:19:05 | 000,073,220 | —- | C] () – C:\Windows\System32\EPPICPrinterDB.dat
[2010/07/11 13:19:05 | 000,031,053 | —- | C] () – C:\Windows\System32\EPPICPattern131.dat
[2010/07/11 13:19:05 | 000,029,114 | —- | C] () – C:\Windows\System32\EPPICPattern1.dat
[2010/07/11 13:19:05 | 000,027,417 | —- | C] () – C:\Windows\System32\EPPICPattern121.dat
[2010/07/11 13:19:05 | 000,021,021 | —- | C] () – C:\Windows\System32\EPPICPattern3.dat
[2010/07/11 13:19:05 | 000,015,670 | —- | C] () – C:\Windows\System32\EPPICPattern5.dat
[2010/07/11 13:19:05 | 000,013,280 | —- | C] () – C:\Windows\System32\EPPICPattern2.dat
[2010/07/11 13:19:05 | 000,010,673 | —- | C] () – C:\Windows\System32\EPPICPattern4.dat
[2010/07/11 13:19:05 | 000,004,943 | —- | C] () – C:\Windows\System32\EPPICPattern6.dat
[2010/07/11 13:19:05 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_PT.dat
[2010/07/11 13:19:05 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_BP.dat
[2010/07/11 13:19:05 | 000,001,137 | —- | C] () – C:\Windows\System32\EPPICPresetData_ES.dat
[2010/07/11 13:19:05 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_FR.dat
[2010/07/11 13:19:05 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_CF.dat
[2010/07/11 13:19:05 | 000,001,104 | —- | C] () – C:\Windows\System32\EPPICPresetData_EN.dat
[2010/07/11 13:19:05 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2010/07/11 13:17:03 | 000,000,044 | —- | C] () – C:\Windows\EPNX410.ini
[2010/07/09 22:34:31 | 000,386,040 | —- | C] () – C:\Windows\System32\prfh0404.dat
[2010/07/09 22:34:31 | 000,369,938 | —- | C] () – C:\Windows\System32\prfh0804.dat
[2010/07/09 22:34:31 | 000,117,840 | —- | C] () – C:\Windows\System32\prfi0404.dat
[2010/07/09 22:34:31 | 000,111,310 | —- | C] () – C:\Windows\System32\prfi0804.dat
[2010/07/09 22:34:31 | 000,104,382 | —- | C] () – C:\Windows\System32\prfc0804.dat
[2010/07/09 22:34:31 | 000,099,468 | —- | C] () – C:\Windows\System32\prfc0404.dat
[2010/07/09 22:34:31 | 000,031,548 | —- | C] () – C:\Windows\System32\prfd0804.dat
[2010/07/09 22:34:31 | 000,031,548 | —- | C] () – C:\Windows\System32\prfd0404.dat
[2010/07/09 21:58:06 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/07/09 21:30:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/07/09 21:30:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/07/09 21:30:12 | 000,650,752 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/07/09 21:30:12 | 000,240,640 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/07/09 21:30:11 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/07/09 21:00:08 | 000,000,017 | —- | C] () – C:\Users\Ini\AppData\Local\resmon.resmoncfg
========== LOP Check ==========
[2010/07/27 00:02:57 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\acccore
[2011/03/24 05:23:11 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Amazon
[2012/01/02 02:39:59 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Babylon
[2012/03/14 12:51:04 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\BitComet
[2010/11/04 22:20:42 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\EPSON
[2010/12/02 08:09:07 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\ICAClient
[2012/01/02 02:49:26 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\InfraRecorder
[2011/04/21 17:17:22 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\KKman
[2010/07/11 13:30:05 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Leadertech
[2011/03/20 00:30:20 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Maxthon2
[2012/04/21 02:12:20 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\MxBoost
[2010/09/20 03:54:41 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\PCMan
[2010/07/09 20:36:31 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\PeaZip
[2011/05/26 23:19:04 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\PhotoScape
[2010/10/15 14:45:11 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\QQMusicUpdate
[2011/10/22 09:22:58 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\reading.udn.com
[2010/08/31 21:55:21 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\StreamTorrent
[2011/12/21 10:05:57 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\TeamViewer
[2011/03/23 23:02:15 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Tencent
[2011/02/12 01:32:05 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Trillian
[2011/04/21 17:16:49 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\uTorrent
[2012/03/26 23:17:11 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/04/22 18:56:57 | 2415,321,088 | -HS- | M] () – C:\hiberfil.sys
[2010/07/27 00:02:45 | 000,000,694 | -H– | M] () – C:\IPH.PH
[2012/04/22 18:57:03 | 3220,430,848 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/04/24 06:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPDA0.DLL
[2010/04/24 06:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPPA0.DLL
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/13 21:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/09/06 16:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/02 23:56:52 | 000,000,221 | -HS- | M] () – C:\Users\Ini\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/02/19 05:15:29 | 002,245,264 | —- | M] () – C:\Users\Ini\Desktop\PPLiveLiteCompleteSetup.exe
[2009/07/13 05:04:46 | 005,132,288 | —- | M] () – C:\Users\Ini\Desktop\prime95.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-04-20 14:36:06
========== Files - Unicode (All) ==========
[2011/10/22 09:22:47 | 000,000,320 | —- | M] ()(C:\Users\Ini\Desktop\udn ?????.appref-ms) – C:\Users\Ini\Desktop\udn 數位閱讀網.appref-ms
[2011/10/22 09:22:47 | 000,000,320 | —- | C] ()(C:\Users\Ini\Desktop\udn ?????.appref-ms) – C:\Users\Ini\Desktop\udn 數位閱讀網.appref-ms
[2011/01/21 02:20:06 | 000,010,390 | —- | M] ()(C:\Users\Ini\Documents\???.docx) – C:\Users\Ini\Documents\蜘蛛俠.docx
[2011/01/21 02:20:05 | 000,010,390 | —- | C] ()(C:\Users\Ini\Documents\???.docx) – C:\Users\Ini\Documents\蜘蛛俠.docx
[2010/12/19 18:27:08 | 000,051,972 | —- | M] ()(C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!.htm) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!.htm
[2010/12/19 18:27:07 | 000,000,000 | —D | M](C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!_files) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!_files
[2010/12/19 18:27:07 | 000,000,000 | —D | C](C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!_files) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!_files
[2010/12/19 18:27:06 | 000,051,972 | —- | C] ()(C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!.htm) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!.htm
[2010/10/15 14:44:32 | 000,001,097 | —- | M] ()(C:\Users\Public\Desktop\QQ??.lnk) – C:\Users\Public\Desktop\QQ音乐.lnk
[2010/10/15 14:44:32 | 000,001,097 | —- | C] ()(C:\Users\Public\Desktop\QQ??.lnk) – C:\Users\Public\Desktop\QQ音乐.lnk
(C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????) – C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\聯合線上
< End of report >
——————— Extras below —————————————
OTL Extras logfile created on: 4/22/2012 7:04:17 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = H:\antimalware
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 55.85% Memory free
6.00 Gb Paging File | 4.63 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 58.50 Gb Total Space | 7.27 Gb Free Space | 12.42% Space Free | Partition Type: NTFS
Drive D: | 106.67 Gb Total Space | 105.08 Gb Free Space | 98.51% Space Free | Partition Type: NTFS
Drive E: | 67.61 Gb Total Space | 66.05 Gb Free Space | 97.68% Space Free | Partition Type: NTFS
Drive G: | 90.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.78 Gb Total Space | 0.14 Gb Free Space | 3.62% Space Free | Partition Type: FAT32
Computer Name: INI-PC | User Name: Ini | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PeaZip] – Reg Error: Value error.
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iBryte\browseforchange\ibrytedesktop.exe" = C:\Program Files\iBryte\browseforchange\ibrytedesktop.exe:*:Enabled:iBryteDesktop
"C:\Program Files\iBryte\playbryte\ibrytedesktop.exe" = C:\Program Files\iBryte\playbryte\ibrytedesktop.exe:*:Enabled:iBryteDesktop
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp version 0.99.8
"{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}" = Windows Media Center Add-in for Silverlight
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series" = Canon MP560 series MP Drivers
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 29
"{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}" = Ralink RT2870 Wireless LAN Card
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1" = PeaZip 3.2.1
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{AC76BA86-7AD7-2447-0000-900000000003}" = Chinese Simplified Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C0B165DC-F037-483F-B1C9-D89D91529CEB}" = Citrix XenApp Web Plugin
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CAEAD1E4-A15F-4249-A1B6-9D42080C7361}" = Adobe Photoshop Lightroom 3.4
"{CC6B1BB4-4E06-4A5B-A166-B371B551324B}" = COMODO Internet Security
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
"{D7E04009-B191-4E9D-9D2D-1BBE57BD8A42}" = VistaFeaturePack
"{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}" = Windows Media Center Add-in for Flash
"{E34ACF2A-38BA-3348-90F6-B76A34647AB0}" = Microsoft .NET Framework 4 Client Profile CHT Language Pack
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E8FF78D0-4D1C-4B2D-AC80-670F135F5461}" = Poladroid
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AutocompletePro3_is1" = AutocompletePro
"avast" = avast! Free Antivirus
"BitComet" = BitComet(比特彗星) 1.31
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"CutePDF Writer Installation" = CutePDF Writer 2.8
"ENTERPRISE" = Microsoft Office Enterprise 2007
"iBryte_browseforchange" = Browse For Change
"ImgBurn" = ImgBurn
"InfraRecorder" = InfraRecorder
"InstallShield_{D7E04009-B191-4E9D-9D2D-1BBE57BD8A42}" = VistaFeaturePack
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.1.0 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Maxthon2" = Maxthon2
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CHT Language Pack" = Microsoft .NET Framework 4 Client Profile 繁體中文語言套件
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoScape" = PhotoScape
"QQMusic" = QQ音乐 2010
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"SpywareBlaster_is1" = SpywareBlaster 4.3
"SpywareGuard_is1" = SpywareGuard v2.2
"StreamTorrent 1.0" = StreamTorrent 1.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.2
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinLiveSuite_Wave3" = Windows Live Essentials
"Xvid Video Codec 1.3.1" = Xvid Video Codec
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"7e71a2cfde898e63" = udn 數位閱讀網
"Amazon Kindle For PC" = Amazon Kindle For PC
"blinkx beat" = blinkx beat
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/12/2012 12:43:08 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 472: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/12/2012 12:43:08 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 480: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/12/2012 12:43:08 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 488: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/16/2012 9:00:42 AM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 472: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/16/2012 9:00:42 AM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 480: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/16/2012 9:00:42 AM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 488: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/17/2012 10:21:22 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 296: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/17/2012 10:21:22 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 428: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/17/2012 10:21:22 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 432: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/18/2012 1:49:54 PM | Computer Name = Ini-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7600.16915,
time stamp: 0x4ec49caf Exception code: 0xc0000005 Fault offset: 0x00055401 Faulting
process id: 0x1720 Faulting application start time: 0x01cd1d8ba6a3da17 Faulting application
path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: e75f94d8-897e-11e1-b21d-90e6ba69a22d
[ Media Center Events ]
Error - 2/6/2012 5:30:12 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:30:12 PM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:31:15 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:30:54 PM - Failed to retrieve ClientUpdate (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:31:57 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:31:36 PM - Failed to retrieve NetTV (Error: Unable to connect to
the remote server)
Error - 2/6/2012 5:32:40 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:32:18 PM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:33:22 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:33:01 PM - Failed to retrieve SportsSchedule (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:34:04 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:33:43 PM - Failed to retrieve SportsV2 (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:34:46 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:34:25 PM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:35:22 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:35:07 PM - Failed to retrieve EpgListings (Error: Unable to connect
to the remote server)
Error - 4/8/2012 8:17:03 AM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 8:16:44 AM - Error connecting to the internet. 8:16:44 AM - Unable
to contact server..
Error - 4/18/2012 12:43:16 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 12:42:55 PM - Failed to retrieve SportsSchedule (Error: Unable to
connect to the remote server)
[ OSession Events ]
Error - 11/24/2010 12:40:45 AM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/14/2011 3:46:23 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/26/2011 2:45:31 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/31/2011 10:27:57 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/31/2011 10:30:56 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 4/7/2012 11:56:01 PM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 4/10/2012 12:05:01 PM | Computer Name = Ini-PC | Source = DCOM | ID = 10016
Description =
Error - 4/13/2012 3:08:38 AM | Computer Name = Ini-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Search service to connect.
Error - 4/13/2012 3:08:38 AM | Computer Name = Ini-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053
Error - 4/13/2012 11:50:29 AM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 4/14/2012 12:08:54 PM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 4/17/2012 8:45:42 PM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 4/18/2012 2:09:56 PM | Computer Name = Ini-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 20.
Error - 4/18/2012 2:09:56 PM | Computer Name = Ini-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 20.
Error - 4/20/2012 11:35:31 AM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
< End of report >
Here are the results of the OTL scan:
OTL logfile created on: 4/22/2012 7:04:17 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = H:\antimalware
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 55.85% Memory free
6.00 Gb Paging File | 4.63 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 58.50 Gb Total Space | 7.27 Gb Free Space | 12.42% Space Free | Partition Type: NTFS
Drive D: | 106.67 Gb Total Space | 105.08 Gb Free Space | 98.51% Space Free | Partition Type: NTFS
Drive E: | 67.61 Gb Total Space | 66.05 Gb Free Space | 97.68% Space Free | Partition Type: NTFS
Drive G: | 90.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.78 Gb Total Space | 0.14 Gb Free Space | 3.62% Space Free | Partition Type: FAT32
Computer Name: INI-PC | User Name: Ini | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - H:\antimalware\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - G:\WINDOWS\IronKey.exe (IronKey, Inc.)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
PRC - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\HControl.exe (ASUS)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
PRC - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - G:\WINDOWS\zlib1.dll ()
MOD - G:\WINDOWS\ikvip.dll ()
MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll ()
MOD - C:\Program Files\SpywareGuard\sgmain.exe ()
MOD - C:\Program Files\SpywareGuard\sgbhp.exe ()
MOD - C:\Program Files\SpywareGuard\dlprotect.dll ()
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (BITCOMET_HELPER_SERVICE) – C:\Program Files\BitComet\tools\BitCometService.exe (www.BitComet.com)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ASLDRService) – C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)
SRV - (ATKGFNEXSrv) – C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
========== Driver Services (SafeList) ==========
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (cmdGuard) – C:\Windows\System32\drivers\cmdGuard.sys (COMODO)
DRV - (inspect) – C:\Windows\System32\drivers\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\Windows\System32\drivers\cmdhlp.sys (COMODO)
DRV - (AVerFx2hbtv) – C:\Windows\System32\drivers\AVerFx2hbtv.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV - (smserial) – C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (netw5v32) Intel® – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (MTsensor) – C:\Windows\System32\drivers\ATKACPI.sys (ASUS)
DRV - (netr28u) – C:\Windows\System32\drivers\netr28u.sys (Ralink Technology Corp.)
DRV - (ASMMAP) – C:\Program Files\ATKGFNEX\ASMMAP.sys ()
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&am;…000001561524eae
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F1 39 FC B3 F6 38 CB 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = playbryte/search/redirect/?type=default&user;_id=ff21076b-39b0-4b88-ba9f-5f1dca62f0e7&query;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://mail.google.com/mail/?shva=1#inbox"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: [removed]:0.2.4.1
FF - prefs.js..extensions.enabledItems: vshareus@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: [removed]:1.11
FF - prefs.js..extensions.enabledItems: {86095750-AD15-46d8-BF32-C0789F7E6A32}:1.0.75
FF - prefs.js..extensions.enabledItems: [removed]:3.11.3.15590
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@qq.com/QzoneMusic: C:\Program Files\Tencent\QQMusic\npQzoneMusic.dll (Tencent)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ini\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ini\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/22 18:59:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/05 02:08:43 | 000,000,000 | —D | M]
[2010/07/09 21:58:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Ini\AppData\Roaming\Mozilla\Extensions
[2012/03/05 02:08:43 | 000,000,000 | —D | M] (No name found) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions
[2012/03/05 02:08:44 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2012/01/02 02:41:07 | 000,000,000 | —D | M] (Browse For Change) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2012/01/02 09:59:33 | 000,000,000 | —D | M] (Babylon) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2011/07/27 07:22:55 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2012/01/02 02:41:28 | 000,000,000 | —D | M] (PlayBryte) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2012/01/02 02:40:39 | 000,000,000 | —D | M] (Yontoo) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2010/12/22 17:32:22 | 000,000,000 | —D | M] ("AutocompletePro - Your handy search suggestions tool") – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2011/12/20 22:50:21 | 000,000,000 | —D | M] (Ask Toolbar) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2010/10/16 20:17:41 | 000,000,000 | —D | M] (vShare Plugin) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\vshareus@toolbar
[2012/01/25 19:14:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/09 22:11:04 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
() (No name found) – C:\USERS\INI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EMEA68UB.DEFAULT\EXTENSIONS\{86095750-AD15-46D8-BF32-C0789F7E6A32}.XPI
[2012/04/22 18:59:50 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/03 02:59:20 | 000,917,816 | —- | M] (BitComet) – C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2011/03/18 15:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 15:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/09/10 02:19:24 | 000,305,152 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npuuseep.dll
[2012/04/22 18:59:48 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/22 18:59:48 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: 56ICANPlugin (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\igcnieghjaijfgekdbamdgbaicckhelo\1.0.0.1_0\np56icanplugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: BitCometAgent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: npruntime scriptable example plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npuuseep.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: QQMusic (Enabled) = C:\Program Files\Tencent\QQMusic\npQzoneMusic.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Ini\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Windows\system32\TVUAx\npTVUAx.dll
CHR - Extension: PlayBryte = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\akbkdomfdgaijlahpfcnhaifemjfdfnh\1.0_0\
CHR - Extension: YouTube = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AutocompletePro plugin for chrome = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.0_1\
CHR - Extension: Browse For Change = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkappjlcaehkpnjgompookobajdjkkfm\1.0_0\
CHR - Extension: 56icanplugin = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\igcnieghjaijfgekdbamdgbaicckhelo\1.0.0.1_0\
CHR - Extension: Yontoo = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\
CHR - Extension: Gmail = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (no name) - {06C7AD57-B655-418D-9AB8-9526A6D2E052} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [iBryte browseforchange Desktop] C:\Program Files\iBryte\browseforchange\ibrytedesktop.exe File not found
O4 - HKLM..\Run: [iBryte playbryte Desktop] C:\Program Files\iBryte\playbryte\ibrytedesktop.exe File not found
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKCU..\Run: [eMuleAutoStart] C:\Program Files\easyMule\eMule.exe -AutoStart File not found
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Epson all-in-one Registration.lnk = File not found
O4 - Startup: C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: &使用BitComet下載 - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &使用BitComet下載全部連結 - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlcdnet.asus.com/pub/ASUS/misc/dlm-…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{57B3753B-2457-4488-A559-ACAC8A1E45BE}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CAE96C25-6A77-4807-A3AB-8730E398450F}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE17E30D-C3B6-4F35-AA76-C57780891970}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/11/13 17:58:46 | 000,000,074 | R— | M] () - G:\AUTORUN.INF – [ CDFS ]
O32 - Unable to obtain root file information for disk H:\
O33 - MountPoints2\{cc134bba-8cc5-11e1-b1b6-90e6ba69a22d}\Shell - "" = AutoRun
O33 - MountPoints2\{cc134bba-8cc5-11e1-b1b6-90e6ba69a22d}\Shell\AutoRun\command - "" = G:\IronKey.exe – [2010/11/13 17:58:46 | 000,341,336 | R— | M] (IronKey Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: wave1 - C:\Windows\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave2 - C:\Windows\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/04/17 18:51:09 | 000,000,000 | —D | C] – C:\Users\Ini\Desktop\Originals
[2012/04/13 03:07:57 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/04/13 03:07:55 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/04/13 03:07:54 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/04/13 03:07:53 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/04/13 03:07:53 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/04/13 03:07:51 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/04/13 03:07:29 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/04/13 03:00:54 | 003,958,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/04/13 03:00:52 | 003,902,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/04/12 00:23:18 | 000,000,000 | —D | C] – C:\Users\Ini\Desktop\pic
[2012/03/28 07:11:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP560 series
========== Files - Modified Within 30 Days ==========
[2012/04/22 19:04:36 | 000,014,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 19:04:36 | 000,014,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 19:03:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000UA.job
[2012/04/22 18:57:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/22 18:56:57 | 2415,321,088 | -HS- | M] () – C:\hiberfil.sys
[2012/04/22 18:31:43 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/22 18:31:09 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/22 18:31:09 | 000,386,040 | —- | M] () – C:\Windows\System32\prfh0404.dat
[2012/04/22 18:31:09 | 000,369,938 | —- | M] () – C:\Windows\System32\prfh0804.dat
[2012/04/22 18:31:09 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/22 18:31:09 | 000,104,382 | —- | M] () – C:\Windows\System32\prfc0804.dat
[2012/04/22 18:31:09 | 000,099,468 | —- | M] () – C:\Windows\System32\prfc0404.dat
[2012/04/22 00:44:42 | 000,000,470 | —- | M] () – C:\Users\Ini\AppData\Roaming\Poladroid prefs.plist
[2012/04/22 00:44:20 | 000,233,733 | —- | M] () – C:\Users\Ini\Desktop\4537087038_ab8b3fb923_z.jpg
[2012/04/22 00:42:41 | 000,056,320 | -H– | M] () – C:\Users\Ini\Desktop\photothumb.db
[2012/04/22 00:39:47 | 000,161,454 | —- | M] () – C:\Users\Ini\Desktop\5688969793_d0f51e5f60_z.jpg
[2012/04/22 00:36:53 | 000,238,719 | —- | M] () – C:\Users\Ini\Desktop\IMG_0679.JPG
[2012/04/22 00:36:01 | 000,218,958 | —- | M] () – C:\Users\Ini\Desktop\IMG_0674.JPG
[2012/04/22 00:33:55 | 000,218,362 | —- | M] () – C:\Users\Ini\Desktop\IMG_0575.JPG
[2012/04/20 13:03:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000Core.job
[2012/04/12 22:43:14 | 000,002,385 | —- | M] () – C:\Users\Ini\Desktop\Google Chrome.lnk
[2012/04/04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
========== Files Created - No Company Name ==========
[2012/04/22 00:40:49 | 000,233,733 | —- | C] () – C:\Users\Ini\Desktop\4537087038_ab8b3fb923_z.jpg
[2012/04/22 00:39:46 | 000,161,454 | —- | C] () – C:\Users\Ini\Desktop\5688969793_d0f51e5f60_z.jpg
[2012/04/22 00:31:57 | 000,238,719 | —- | C] () – C:\Users\Ini\Desktop\IMG_0679.JPG
[2012/04/22 00:31:52 | 000,218,958 | —- | C] () – C:\Users\Ini\Desktop\IMG_0674.JPG
[2012/04/22 00:31:30 | 000,218,362 | —- | C] () – C:\Users\Ini\Desktop\IMG_0575.JPG
[2011/12/09 13:51:01 | 000,087,552 | —- | C] () – C:\Windows\System32\cpwmon2k.dll
[2011/11/30 21:53:45 | 000,013,931 | —- | C] () – C:\Windows\System32\RaCoInst.dat
[2010/11/19 01:15:41 | 000,000,470 | —- | C] () – C:\Users\Ini\AppData\Roaming\Poladroid prefs.plist
[2010/07/13 00:21:09 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/07/11 13:19:05 | 000,073,220 | —- | C] () – C:\Windows\System32\EPPICPrinterDB.dat
[2010/07/11 13:19:05 | 000,031,053 | —- | C] () – C:\Windows\System32\EPPICPattern131.dat
[2010/07/11 13:19:05 | 000,029,114 | —- | C] () – C:\Windows\System32\EPPICPattern1.dat
[2010/07/11 13:19:05 | 000,027,417 | —- | C] () – C:\Windows\System32\EPPICPattern121.dat
[2010/07/11 13:19:05 | 000,021,021 | —- | C] () – C:\Windows\System32\EPPICPattern3.dat
[2010/07/11 13:19:05 | 000,015,670 | —- | C] () – C:\Windows\System32\EPPICPattern5.dat
[2010/07/11 13:19:05 | 000,013,280 | —- | C] () – C:\Windows\System32\EPPICPattern2.dat
[2010/07/11 13:19:05 | 000,010,673 | —- | C] () – C:\Windows\System32\EPPICPattern4.dat
[2010/07/11 13:19:05 | 000,004,943 | —- | C] () – C:\Windows\System32\EPPICPattern6.dat
[2010/07/11 13:19:05 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_PT.dat
[2010/07/11 13:19:05 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_BP.dat
[2010/07/11 13:19:05 | 000,001,137 | —- | C] () – C:\Windows\System32\EPPICPresetData_ES.dat
[2010/07/11 13:19:05 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_FR.dat
[2010/07/11 13:19:05 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_CF.dat
[2010/07/11 13:19:05 | 000,001,104 | —- | C] () – C:\Windows\System32\EPPICPresetData_EN.dat
[2010/07/11 13:19:05 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2010/07/11 13:17:03 | 000,000,044 | —- | C] () – C:\Windows\EPNX410.ini
[2010/07/09 22:34:31 | 000,386,040 | —- | C] () – C:\Windows\System32\prfh0404.dat
[2010/07/09 22:34:31 | 000,369,938 | —- | C] () – C:\Windows\System32\prfh0804.dat
[2010/07/09 22:34:31 | 000,117,840 | —- | C] () – C:\Windows\System32\prfi0404.dat
[2010/07/09 22:34:31 | 000,111,310 | —- | C] () – C:\Windows\System32\prfi0804.dat
[2010/07/09 22:34:31 | 000,104,382 | —- | C] () – C:\Windows\System32\prfc0804.dat
[2010/07/09 22:34:31 | 000,099,468 | —- | C] () – C:\Windows\System32\prfc0404.dat
[2010/07/09 22:34:31 | 000,031,548 | —- | C] () – C:\Windows\System32\prfd0804.dat
[2010/07/09 22:34:31 | 000,031,548 | —- | C] () – C:\Windows\System32\prfd0404.dat
[2010/07/09 21:58:06 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/07/09 21:30:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/07/09 21:30:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/07/09 21:30:12 | 000,650,752 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/07/09 21:30:12 | 000,240,640 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/07/09 21:30:11 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/07/09 21:00:08 | 000,000,017 | —- | C] () – C:\Users\Ini\AppData\Local\resmon.resmoncfg
========== LOP Check ==========
[2010/07/27 00:02:57 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\acccore
[2011/03/24 05:23:11 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Amazon
[2012/01/02 02:39:59 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Babylon
[2012/03/14 12:51:04 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\BitComet
[2010/11/04 22:20:42 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\EPSON
[2010/12/02 08:09:07 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\ICAClient
[2012/01/02 02:49:26 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\InfraRecorder
[2011/04/21 17:17:22 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\KKman
[2010/07/11 13:30:05 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Leadertech
[2011/03/20 00:30:20 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Maxthon2
[2012/04/21 02:12:20 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\MxBoost
[2010/09/20 03:54:41 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\PCMan
[2010/07/09 20:36:31 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\PeaZip
[2011/05/26 23:19:04 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\PhotoScape
[2010/10/15 14:45:11 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\QQMusicUpdate
[2011/10/22 09:22:58 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\reading.udn.com
[2010/08/31 21:55:21 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\StreamTorrent
[2011/12/21 10:05:57 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\TeamViewer
[2011/03/23 23:02:15 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Tencent
[2011/02/12 01:32:05 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Trillian
[2011/04/21 17:16:49 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\uTorrent
[2012/03/26 23:17:11 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/04/22 18:56:57 | 2415,321,088 | -HS- | M] () – C:\hiberfil.sys
[2010/07/27 00:02:45 | 000,000,694 | -H– | M] () – C:\IPH.PH
[2012/04/22 18:57:03 | 3220,430,848 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/04/24 06:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPDA0.DLL
[2010/04/24 06:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPPA0.DLL
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/13 21:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/09/06 16:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/02 23:56:52 | 000,000,221 | -HS- | M] () – C:\Users\Ini\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/02/19 05:15:29 | 002,245,264 | —- | M] () – C:\Users\Ini\Desktop\PPLiveLiteCompleteSetup.exe
[2009/07/13 05:04:46 | 005,132,288 | —- | M] () – C:\Users\Ini\Desktop\prime95.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-04-20 14:36:06
========== Files - Unicode (All) ==========
[2011/10/22 09:22:47 | 000,000,320 | —- | M] ()(C:\Users\Ini\Desktop\udn ?????.appref-ms) – C:\Users\Ini\Desktop\udn 數位閱讀網.appref-ms
[2011/10/22 09:22:47 | 000,000,320 | —- | C] ()(C:\Users\Ini\Desktop\udn ?????.appref-ms) – C:\Users\Ini\Desktop\udn 數位閱讀網.appref-ms
[2011/01/21 02:20:06 | 000,010,390 | —- | M] ()(C:\Users\Ini\Documents\???.docx) – C:\Users\Ini\Documents\蜘蛛俠.docx
[2011/01/21 02:20:05 | 000,010,390 | —- | C] ()(C:\Users\Ini\Documents\???.docx) – C:\Users\Ini\Documents\蜘蛛俠.docx
[2010/12/19 18:27:08 | 000,051,972 | —- | M] ()(C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!.htm) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!.htm
[2010/12/19 18:27:07 | 000,000,000 | —D | M](C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!_files) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!_files
[2010/12/19 18:27:07 | 000,000,000 | —D | C](C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!_files) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!_files
[2010/12/19 18:27:06 | 000,051,972 | —- | C] ()(C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!.htm) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!.htm
[2010/10/15 14:44:32 | 000,001,097 | —- | M] ()(C:\Users\Public\Desktop\QQ??.lnk) – C:\Users\Public\Desktop\QQ音乐.lnk
[2010/10/15 14:44:32 | 000,001,097 | —- | C] ()(C:\Users\Public\Desktop\QQ??.lnk) – C:\Users\Public\Desktop\QQ音乐.lnk
(C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????) – C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\聯合線上
< End of report >
——————— Extras below —————————————
OTL Extras logfile created on: 4/22/2012 7:04:17 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = H:\antimalware
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 55.85% Memory free
6.00 Gb Paging File | 4.63 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 58.50 Gb Total Space | 7.27 Gb Free Space | 12.42% Space Free | Partition Type: NTFS
Drive D: | 106.67 Gb Total Space | 105.08 Gb Free Space | 98.51% Space Free | Partition Type: NTFS
Drive E: | 67.61 Gb Total Space | 66.05 Gb Free Space | 97.68% Space Free | Partition Type: NTFS
Drive G: | 90.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.78 Gb Total Space | 0.14 Gb Free Space | 3.62% Space Free | Partition Type: FAT32
Computer Name: INI-PC | User Name: Ini | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PeaZip] – Reg Error: Value error.
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iBryte\browseforchange\ibrytedesktop.exe" = C:\Program Files\iBryte\browseforchange\ibrytedesktop.exe:*:Enabled:iBryteDesktop
"C:\Program Files\iBryte\playbryte\ibrytedesktop.exe" = C:\Program Files\iBryte\playbryte\ibrytedesktop.exe:*:Enabled:iBryteDesktop
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp version 0.99.8
"{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}" = Windows Media Center Add-in for Silverlight
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series" = Canon MP560 series MP Drivers
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 29
"{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}" = Ralink RT2870 Wireless LAN Card
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1" = PeaZip 3.2.1
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{AC76BA86-7AD7-2447-0000-900000000003}" = Chinese Simplified Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C0B165DC-F037-483F-B1C9-D89D91529CEB}" = Citrix XenApp Web Plugin
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CAEAD1E4-A15F-4249-A1B6-9D42080C7361}" = Adobe Photoshop Lightroom 3.4
"{CC6B1BB4-4E06-4A5B-A166-B371B551324B}" = COMODO Internet Security
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
"{D7E04009-B191-4E9D-9D2D-1BBE57BD8A42}" = VistaFeaturePack
"{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}" = Windows Media Center Add-in for Flash
"{E34ACF2A-38BA-3348-90F6-B76A34647AB0}" = Microsoft .NET Framework 4 Client Profile CHT Language Pack
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E8FF78D0-4D1C-4B2D-AC80-670F135F5461}" = Poladroid
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AutocompletePro3_is1" = AutocompletePro
"avast" = avast! Free Antivirus
"BitComet" = BitComet(比特彗星) 1.31
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"CutePDF Writer Installation" = CutePDF Writer 2.8
"ENTERPRISE" = Microsoft Office Enterprise 2007
"iBryte_browseforchange" = Browse For Change
"ImgBurn" = ImgBurn
"InfraRecorder" = InfraRecorder
"InstallShield_{D7E04009-B191-4E9D-9D2D-1BBE57BD8A42}" = VistaFeaturePack
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.1.0 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Maxthon2" = Maxthon2
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CHT Language Pack" = Microsoft .NET Framework 4 Client Profile 繁體中文語言套件
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoScape" = PhotoScape
"QQMusic" = QQ音乐 2010
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"SpywareBlaster_is1" = SpywareBlaster 4.3
"SpywareGuard_is1" = SpywareGuard v2.2
"StreamTorrent 1.0" = StreamTorrent 1.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.2
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinLiveSuite_Wave3" = Windows Live Essentials
"Xvid Video Codec 1.3.1" = Xvid Video Codec
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"7e71a2cfde898e63" = udn 數位閱讀網
"Amazon Kindle For PC" = Amazon Kindle For PC
"blinkx beat" = blinkx beat
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/12/2012 12:43:08 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 472: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/12/2012 12:43:08 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 480: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/12/2012 12:43:08 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 488: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/16/2012 9:00:42 AM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 472: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/16/2012 9:00:42 AM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 480: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/16/2012 9:00:42 AM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 488: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/17/2012 10:21:22 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 296: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/17/2012 10:21:22 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 428: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/17/2012 10:21:22 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 432: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/18/2012 1:49:54 PM | Computer Name = Ini-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7600.16915,
time stamp: 0x4ec49caf Exception code: 0xc0000005 Fault offset: 0x00055401 Faulting
process id: 0x1720 Faulting application start time: 0x01cd1d8ba6a3da17 Faulting application
path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: e75f94d8-897e-11e1-b21d-90e6ba69a22d
[ Media Center Events ]
Error - 2/6/2012 5:30:12 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:30:12 PM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:31:15 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:30:54 PM - Failed to retrieve ClientUpdate (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:31:57 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:31:36 PM - Failed to retrieve NetTV (Error: Unable to connect to
the remote server)
Error - 2/6/2012 5:32:40 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:32:18 PM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:33:22 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:33:01 PM - Failed to retrieve SportsSchedule (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:34:04 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:33:43 PM - Failed to retrieve SportsV2 (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:34:46 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:34:25 PM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)
Error - 2/6/2012 5:35:22 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:35:07 PM - Failed to retrieve EpgListings (Error: Unable to connect
to the remote server)
Error - 4/8/2012 8:17:03 AM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 8:16:44 AM - Error connecting to the internet. 8:16:44 AM - Unable
to contact server..
Error - 4/18/2012 12:43:16 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 12:42:55 PM - Failed to retrieve SportsSchedule (Error: Unable to
connect to the remote server)
[ OSession Events ]
Error - 11/24/2010 12:40:45 AM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/14/2011 3:46:23 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/26/2011 2:45:31 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/31/2011 10:27:57 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/31/2011 10:30:56 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 4/7/2012 11:56:01 PM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 4/10/2012 12:05:01 PM | Computer Name = Ini-PC | Source = DCOM | ID = 10016
Description =
Error - 4/13/2012 3:08:38 AM | Computer Name = Ini-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Search service to connect.
Error - 4/13/2012 3:08:38 AM | Computer Name = Ini-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053
Error - 4/13/2012 11:50:29 AM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 4/14/2012 12:08:54 PM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 4/17/2012 8:45:42 PM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 4/18/2012 2:09:56 PM | Computer Name = Ini-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 20.
Error - 4/18/2012 2:09:56 PM | Computer Name = Ini-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 20.
Error - 4/20/2012 11:35:31 AM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
< End of report >