OTL.txt
OTL logfile created on: 5/1/2013 AM 7:31:31 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001004 | Country: Singapore | Language: ZHI | Date Format: d/M/yyyy
1015.17 Mb Total Physical Memory | 389.37 Mb Available Physical Memory | 38.35% Memory free
2.38 Gb Paging File | 1.77 Gb Available in Paging File | 74.33% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.99 Gb Total Space | 2.91 Gb Free Space | 7.27% Space Free | Partition Type: NTFS
Drive D: | 34.50 Gb Total Space | 33.30 Gb Free Space | 96.51% Space Free | Partition Type: NTFS
Drive E: | 7.47 Gb Total Space | 7.47 Gb Free Space | 99.90% Space Free | Partition Type: FAT32
Computer Name: TSTIOH5353 | User Name: TANST | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/01/05 07:23:06 | 000,602,112 | —- | M] (OldTimer Tools) – E:\OTL.exe
PRC - [2012/08/16 21:22:30 | 000,348,664 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012/05/09 00:24:20 | 000,086,224 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012/05/09 00:24:14 | 000,080,336 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012/05/09 00:24:13 | 000,110,032 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012/03/13 05:37:52 | 003,331,872 | —- | M] (Akamai Technologies, Inc) – C:\Documents and Settings\TANST\Local Settings\Application Data\Akamai\netsession_win.exe
PRC - [2012/02/10 14:32:56 | 000,208,472 | —- | M] (Emsi Software GmbH) – C:\Program Files\Online Armor\oacat.exe
PRC - [2011/12/24 17:50:18 | 000,652,872 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/12/24 17:50:16 | 000,981,680 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2011/08/12 07:38:07 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2011/06/15 17:33:20 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2010/06/27 01:09:18 | 000,167,936 | —- | M] (Applian Technologies, Inc.) – D:\Downloads\FLVSrvc.exe
PRC - [2009/09/18 18:48:28 | 000,009,216 | —- | M] (Vodafone) – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
PRC - [2008/06/30 23:18:32 | 000,303,104 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
PRC - [2008/06/04 04:43:56 | 000,098,304 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\EeePC\ACPI\AsTray.exe
PRC - [2008/06/04 03:34:38 | 000,479,232 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
PRC - [2008/05/21 16:56:24 | 000,094,208 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\EeePC\ACPI\AsEPCMon.exe
PRC - [2008/04/14 20:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/01/05 10:48:52 | 000,112,152 | R— | M] (InterVideo) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
========== Modules (No Company Name) ==========
MOD - [2012/11/15 12:01:06 | 000,998,400 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\d8ca3b9fefcda19eeecd55c239f504ba\System.Management.ni.dll
MOD - [2012/11/15 11:57:45 | 000,212,992 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\31b7eef43a23e7c6e93594be583f3d08\System.ServiceProcess.ni.dll
MOD - [2012/11/15 11:56:50 | 000,679,936 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\e564bacf8526a85451e0eaaf5b1137bb\System.Security.ni.dll
MOD - [2012/11/15 11:56:41 | 000,971,264 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\41cac4885974d07de06f0b4fec9883f0\System.Configuration.ni.dll
MOD - [2012/11/15 11:54:03 | 003,391,488 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_381f5ee3\mscorlib.dll
MOD - [2012/11/15 11:53:41 | 002,088,960 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_06ab646a\system.xml.dll
MOD - [2012/11/15 00:17:33 | 005,450,752 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll
MOD - [2012/11/15 00:09:48 | 007,977,472 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll
MOD - [2012/11/15 00:09:12 | 011,492,352 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll
MOD - [2012/05/09 00:24:20 | 000,398,288 | —- | M] () – C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2011/11/01 23:26:32 | 000,087,912 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/11/01 23:26:12 | 001,242,472 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/06/06 12:55:36 | 000,300,032 | —- | M] () – C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS
MOD - [2008/06/27 13:43:10 | 001,339,392 | —- | M] () – c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2008/06/27 13:43:06 | 000,299,008 | —- | M] () – c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - [2012/11/13 10:29:19 | 004,539,712 | —- | M] () [Auto | Running] – c:\program files\common files\akamai/netsession_win_ce5ba24.dll – (Akamai)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/05/09 00:24:20 | 000,086,224 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2012/05/09 00:24:13 | 000,110,032 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2012/04/15 02:16:10 | 000,253,088 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/02/10 14:33:00 | 004,369,208 | —- | M] (Emsi Software GmbH) [On_Demand | Stopped] – C:\Program Files\Online Armor\oasrv.exe – (SvcOnlineArmor)
SRV - [2012/02/10 14:32:56 | 000,208,472 | —- | M] (Emsi Software GmbH) [Auto | Running] – C:\Program Files\Online Armor\oacat.exe – (OAcat)
SRV - [2011/12/24 17:50:18 | 000,652,872 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2011/08/12 07:38:07 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore.exe – (!SASCORE)
SRV - [2011/07/07 19:31:08 | 000,195,336 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/06/15 17:33:20 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\BingBar\SeaPort.EXE – (BBUpdate)
SRV - [2011/02/15 04:23:00 | 004,014,224 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\system32\GameMon.des – (npggsvc)
SRV - [2009/09/18 18:48:28 | 000,009,216 | —- | M] (Vodafone) [Auto | Running] – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe – (VMCService)
SRV - [2007/01/05 10:48:52 | 000,112,152 | R— | M] (InterVideo) [Auto | Running] – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe – (IviRegMgr)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (pcidump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\EagleNT.sys – (EagleNT)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\br3gmdm.sys – (br3gmdm)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\BCM42RLY.SYS – (BCM42RLY)
DRV - [2013/01/05 07:27:24 | 000,040,776 | —- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mbamswissarmy.sys – (MBAMSwissArmy)
DRV - [2012/05/09 00:24:20 | 000,137,928 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avipbb.sys – (avipbb)
DRV - [2012/05/09 00:24:20 | 000,083,392 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\avgntflt.sys – (avgntflt)
DRV - [2012/02/10 14:33:38 | 000,042,152 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\oahlp32.sys – (oahlpXX)
DRV - [2012/02/10 14:33:14 | 000,029,464 | —- | M] (Emsisoft) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\OAnet.sys – (OAnet)
DRV - [2012/02/10 14:33:14 | 000,025,192 | —- | M] (Emsisoft) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\OAmon.sys – (OAmon)
DRV - [2012/02/10 14:33:12 | 000,205,864 | —- | M] () [File_System | System | Running] – C:\WINDOWS\system32\drivers\OADriver.sys – (OADevice)
DRV - [2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2011/09/15 23:55:04 | 000,036,000 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avkmgr.sys – (avkmgr)
DRV - [2011/07/23 00:27:02 | 000,012,880 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2011/07/13 05:55:22 | 000,067,664 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/06/17 15:14:27 | 000,028,520 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ssmdrv.sys – (ssmdrv)
DRV - [2009/10/13 17:50:00 | 000,133,632 | —- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Mkd2kfNT.sys – (Mkd2kfNt)
DRV - [2009/08/05 22:48:42 | 000,054,752 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys – (fssfltr)
DRV - [2009/07/23 12:57:22 | 000,112,640 | R— | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ewusbnet.sys – (ewusbnet)
DRV - [2009/07/23 12:57:22 | 000,102,528 | R— | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ewusbmdm.sys – (hwdatacard)
DRV - [2009/07/23 12:57:22 | 000,100,480 | R— | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ewusbfake.sys – (hwusbfake)
DRV - [2009/07/13 17:37:00 | 000,079,360 | —- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Mkd2Nadr.sys – (Mkd2Nadr)
DRV - [2008/11/12 13:50:52 | 000,110,080 | R— | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ZTEusbnet.sys – (ZTEusbnet)
DRV - [2008/11/12 13:50:52 | 000,105,344 | R— | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ZTEusbnmea.sys – (ZTEusbnmea)
DRV - [2008/11/12 13:50:52 | 000,104,960 | R— | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\zteusbvoice.sys – (ZTEusbvoice)
DRV - [2008/11/12 13:50:52 | 000,104,960 | R— | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ZTEusbser6k.sys – (ZTEusbser6k)
DRV - [2008/11/12 13:50:52 | 000,104,960 | R— | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys – (ZTEusbmdm6k)
DRV - [2008/11/12 13:50:52 | 000,007,680 | R— | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\massfilter.sys – (massfilter)
DRV - [2008/07/16 18:52:00 | 004,747,776 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService)
DRV - [2008/04/15 11:14:02 | 000,990,632 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\btkrnl.sys – (BTKRNL)
DRV - [2008/04/15 11:13:58 | 000,534,440 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btaudio.sys – (btaudio)
DRV - [2008/04/14 20:00:00 | 000,012,160 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\fsvga.sys – (FsVga)
DRV - [2008/03/29 08:38:16 | 000,625,024 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rt2860.sys – (RT80x86)
DRV - [2008/03/27 17:18:12 | 000,047,272 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\btwusb.sys – (BTWUSB)
DRV - [2008/03/11 19:37:00 | 000,036,864 | R— | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2008/03/10 18:18:42 | 000,057,384 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btwhid.sys – (btwhid)
DRV - [2008/02/04 17:57:44 | 000,037,160 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\btport.sys – (BTDriver)
DRV - [2007/09/20 11:59:14 | 000,156,392 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btwdndis.sys – (BTWDNDIS)
DRV - [2007/07/27 11:00:38 | 000,011,264 | —- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASUSACPI.SYS – (AsusACPI)
DRV - [2005/10/17 18:50:06 | 000,245,376 | —- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rt2500usb.sys – (WUSB54GPV4SRV)
DRV - [2001/08/17 13:53:42 | 000,004,992 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\loop.sys – (msloop)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" =
http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKLM\..\SearchScopes\{EF29B942-7046-4591-A9AC-93E18E0A4108}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\..\SearchScopes,defaultscope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\..\SearchScopes,defaultscope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-19\..\SearchScopes,defaultscope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKU\S-1-5-20\..\SearchScopes,defaultscope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\..\SearchScopes\{22F1500C-D8B7-46F8-B4AE-45D2CCC0F410}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…1I7AMSA_enSG327
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" =
http://search.avg.com/route/?d=$instd…y=&ychte;=sg
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\..\SearchScopes\{EF29B942-7046-4591-A9AC-93E18E0A4108}: "URL" =
http://www.google.com/search?q={searchTerm…;rlz=1I7AMSA_en
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "鐧惧害"
FF - prefs.js..browser.startup.homepage: "about:cehome"
FF - prefs.js..extensions.enabledAddons: [removed]:1.1
FF - prefs.js..extensions.enabledAddons: [removed]:0.8.8
FF - prefs.js..extensions.enabledAddons: [removed]:0.6.1
FF - prefs.js..extensions.enabledAddons: [removed]:5.0.2
FF - prefs.js..extensions.enabledAddons: [removed]:0.7
FF - prefs.js..extensions.enabledAddons: [removed]:0.10
FF - prefs.js..extensions.enabledAddons: [removed]:0.8
FF - prefs.js..extensions.enabledAddons: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}:1.0
FF - prefs.js..extensions.enabledAddons: [removed]:1.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll ()
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npaosmgr.1: C:\Program Files\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 23:52:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/11 03:31:20 | 000,000,000 | —D | M]
[2009/03/15 18:59:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Extensions
[2013/01/05 03:56:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions
[2009/11/18 10:13:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/13 16:25:37 | 000,000,000 | —D | M] (MessengerPlusLive TB Community Toolbar) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\{d8fb4583-db9d-4c7b-85be-294c13a3e5c4}
[2011/10/27 04:31:44 | 000,000,000 | —D | M] (Firefox Home Page) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/10/27 04:31:46 | 000,000,000 | —D | M] (Addons Manager) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/10/27 04:31:49 | 000,000,000 | —D | M] (App Center) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/01/15 04:57:06 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\vshare@toolbar
[2011/10/27 04:31:49 | 000,132,403 | —- | M] () (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/10/27 04:31:49 | 000,001,254 | —- | M] () (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/10/27 04:31:50 | 000,040,256 | —- | M] () (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/10/27 04:31:50 | 000,023,576 | —- | M] () (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/01/15 04:58:18 | 000,001,583 | —- | M] () – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\searchplugins\web-search.xml
[2012/04/14 22:48:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/26 00:01:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/06 03:26:26 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/04/14 22:48:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2010/01/19 17:12:12 | 000,000,000 | —D | M] (flashget3 Extension) – C:\Program Files\Mozilla Firefox\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\TANST\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\WUCNPVQZ.DEFAULT\EXTENSIONS\[removed]
[2012/04/14 22:47:57 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/11/05 15:10:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/06/12 02:05:14 | 000,253,952 | —- | M] () – C:\Program Files\mozilla firefox\components\CheckTudouVa.dll
[2012/04/14 22:47:56 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/05 11:44:20 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/11/05 11:32:18 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/05 11:44:20 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/11/05 11:44:20 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/05 11:44:20 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8153_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: AhnLab Online Security (Enabled) = C:\Program Files\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dll
CHR - plugin: AhnLab MyKeyDefense 2.5 (Enabled) = C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: AdBlock = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.30_0\
CHR - Extension: Click to call with Skype = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8153_0\
O1 HOSTS File: ([2011/10/25 08:15:38 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [egui] "egui.exe" /hide /waitservice File not found
O4 - HKLM..\Run: [Freecorder FLV Service] D:\downloads\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [QuickTime Plugin Install] C:\Program Files\QuickTime\Plugins\DeleteMe1.exe ()
O4 - HKU\S-1-5-21-2228970593-2351082760-789675871-1007..\Run: [Akamai NetSession Interface] C:\Documents and Settings\TANST\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Otaku Mascot.lnk = C:\Documents and Settings\DAISYTAY\My Documents\Mascot.exe (Accursed Toys, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SuperHybridEngine.lnk = C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
O4 - Startup: C:\Documents and Settings\DAISYTAY\Start Menu\Programs\Startup\IMVU.lnk = File not found
O4 - Startup: C:\Documents and Settings\DAISYTAY\Start Menu\Programs\Startup\启动飞速土豆.lnk = File not found
O4 - Startup: C:\Documents and Settings\DAISYTAY\Start Menu\Programs\Startup\风行.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &使用快车(FlashGet)下载 - C:\Program Files\FlashGet\jc_link.htm File not found
O8 - Extra context menu item: &使用快车(FlashGet)下载全部链接 - C:\Program Files\FlashGet\jc_all.htm File not found
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-2228970593-2351082760-789675871-1007\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C}
http://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab (NeffyLauncherCtl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{282EEB5D-959D-429E-B2C2-8C988CE08D4C}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E9E0E7F-8273-4BC1-BB14-7AE6A6A06CAE}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\KuGoo - No CLSID value found
O18 - Protocol\Handler\KuGoo3 - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsi Software GmbH)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/27 13:28:13 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2013/01/05 07:27:24 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2013/01/05 03:37:40 | 000,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2013/01/05 03:37:31 | 000,000,000 | —D | C] – C:\JRT
[2012/12/11 22:35:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[6 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/01/05 07:49:22 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/05 07:27:24 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2013/01/05 07:26:51 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/05 07:26:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/05 03:59:23 | 000,000,632 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1007UA.job
[2013/01/05 03:22:19 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/04 00:16:15 | 000,000,536 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/01/04 00:08:16 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/04 00:02:20 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Otaku Mascot.lnk
[2013/01/02 22:59:00 | 000,000,580 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1007Core.job
[2013/01/02 22:16:52 | 000,002,557 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Vodafone Mobile Connect.lnk
[2013/01/01 22:59:30 | 000,001,748 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Otaku Mascot.lnk
[2012/12/23 02:49:01 | 003,608,760 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/12/18 01:26:26 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/12/16 20:23:59 | 000,290,560 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\dllcache\atmfd.dll
[2012/12/16 20:23:59 | 000,290,560 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\atmfd.dll
[6 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/01/04 00:08:16 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/17 14:15:41 | 000,205,864 | —- | C] () – C:\WINDOWS\System32\drivers\OADriver.sys
[2012/04/17 14:15:41 | 000,042,152 | —- | C] () – C:\WINDOWS\System32\drivers\oahlp32.sys
[2012/02/19 16:11:42 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/24 19:53:19 | 000,000,272 | —- | C] () – C:\WINDOWS\reimage.ini
[2011/10/24 01:07:51 | 000,202,994 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\census.cache
[2011/10/24 01:07:30 | 000,200,468 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\ars.cache
[2011/10/23 21:49:59 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/09/02 03:56:57 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2011/07/17 16:49:26 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2011/05/28 22:18:53 | 000,000,036 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\housecall.guid.cache
[2011/04/29 21:47:42 | 000,011,304 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\615xt1y66r2c8inn7n8d851
[2011/03/14 00:33:56 | 000,000,200 | —- | C] () – C:\WINDOWS\System32\msexcr.ini
[2011/02/04 19:32:40 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2010/08/20 22:25:34 | 000,000,306 | —- | C] () – C:\Documents and Settings\TANST\Application DataBITS.ini
[2010/06/09 08:13:16 | 000,000,366 | —- | C] () – C:\Documents and Settings\TANST\BITS.ini
[2009/08/28 15:16:16 | 000,130,238 | R— | C] () – C:\Documents and Settings\All Users\Application Data\DeviceManager.xml.rc4
[2008/09/03 10:46:52 | 000,000,128 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\fusioncache.dat
[2008/09/01 20:23:08 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
========== ZeroAccess Check ==========
[2008/06/27 13:41:12 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/06/26 16:15:29 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 20:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 20:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/04/14 20:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 20:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 20:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: SERVICES.EXE >
[2009/02/06 19:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 20:00:00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 19:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/06 19:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 19:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
< MD5 for: SVCHOST.EXE >
[2008/04/14 20:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/14 20:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 20:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2011/12/24 17:50:20 | 000,182,856 | —- | M] () MD5=B382935AB01B27D0E14F267DBF288896 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/04/14 20:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/14 20:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 20:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2011/12/24 17:50:20 | 000,182,856 | —- | M] () MD5=B382935AB01B27D0E14F267DBF288896 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 20:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 20:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 20:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /rp /s >
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: ST980811AS
Partitions: 3
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE1 - Removable media other than\tfloppy
Interface type: USB
Media Type: Removable media other than\tfloppy
Model: SanDisk Cruzer Blade USB Device
Partitions: 1
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 40.00GB
Starting Offset: 32256
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 35.00GB
Starting Offset: 42935961600
Hidden sectors: 0
DeviceID: Disk #0, Partition #2
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 39.00MB
Starting Offset: 79982622720
Hidden sectors: 0
DeviceID: Disk #1, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 7.00GB
Starting Offset: 22528
Hidden sectors: 0
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
========== Alternate Data Streams ==========
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5E1404CE
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3E009DD5
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:282C9F32
< End of report >
Extras.txt
OTL Extras logfile created on: 5/1/2013 AM 7:31:31 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001004 | Country: Singapore | Language: ZHI | Date Format: d/M/yyyy
1015.17 Mb Total Physical Memory | 389.37 Mb Available Physical Memory | 38.35% Memory free
2.38 Gb Paging File | 1.77 Gb Available in Paging File | 74.33% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.99 Gb Total Space | 2.91 Gb Free Space | 7.27% Space Free | Partition Type: NTFS
Drive D: | 34.50 Gb Total Space | 33.30 Gb Free Space | 96.51% Space Free | Partition Type: NTFS
Drive E: | 7.47 Gb Total Space | 7.47 Gb Free Space | 99.90% Space Free | Partition Type: FAT32
Computer Name: TSTIOH5353 | User Name: TANST | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_USERS\S-1-5-21-2228970593-2351082760-789675871-1007\SOFTWARE\Classes\]
.html [@ = ChromeHTML.TANST] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L"
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"56074:TCP" = 56074:TCP:*:Enabled:Pando Media Booster
"56074:UDP" = 56074:UDP:*:Enabled:Pando Media Booster
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"56074:TCP" = 56074:TCP:*:Enabled:Pando Media Booster
"56074:UDP" = 56074:UDP:*:Enabled:Pando Media Booster
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe" = C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe:*:Enabled:FlashGet3
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\KuGou\KuGou2011\KuGoo.exe" = C:\Program Files\KuGou\KuGou2011\KuGoo.exe:*:Disabled:酷狗音乐2011
"C:\Documents and Settings\DAISYTAY\My Documents\Downloads\BlackshotInstaller.exe" = C:\Documents and Settings\DAISYTAY\My Documents\Downloads\BlackshotInstaller.exe:*:Enabled:Garena Installer – ()
"D:\Games\BlackShot\BlackShot\system\BlackShot.exe" = D:\Games\BlackShot\BlackShot\system\BlackShot.exe:*:Enabled:BlackShot
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet
"C:\Documents and Settings\TANST\Local Settings\Application Data\Akamai\netsession_win.exe" = C:\Documents and Settings\TANST\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Interface – (Akamai Technologies, Inc)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service – (Apple Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
"C:\Program Files\cacaoweb\cacaoweb.exe" = C:\Program Files\cacaoweb\cacaoweb.exe:*:Enabled:cacaoweb
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0990B5DF-92C3-4AD6-A18D-BF3ADF311240}" = Super Hybrid Engine
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{16D0F2D2-242C-4885-BEF1-4B1655C141AE}" = Bing Bar
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{19F5658D-92E8-4A08-8657-D38ABB1574B2}" = Asus ACPI Driver
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3B5C97AB-F523-4C8E-8A0D-A73A57C76F1C}" = AxedMS
"{3CA2B4FD-AEF2-ED4F-F5E5-0095DDA47AC7}" = Adobe Download Assistant
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{5C52CED3-D45C-4DA9-932F-B91BD44BB461}" = Adabas D 13.01.00
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E4DAE31-7CF3-441A-B6E5-B014D63C80CD}" = Eee Instant Key
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{85E3CFBC-9B1B-470C-AF72-54EACA0F1322}" = ECAP
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Azurewave Wireless LAN
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9510AB97-A36C-4352-8725-E72E5528FA1B}" = StarOffice 8 ASUS Edition
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96B51C0B-D3BE-4DF3-959C-28B22C10CFBB}" = Vodafone Mobile Connect Lite
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-2052-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Chinese Simplified
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B662C580-A3AF-11D4-A71C-0050BAAA39DD}" = Otaku Mascot
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DEB6ACEB-C418-4880-9133-1C5EB9AFBC79}" = Eee Storage
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{F270470B-D4A7-4EE2-B010-390E104443A7}" = croNous
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AhnLab Online Security" = AhnLab Online Security
"Akamai" = Akamai NetSession Interface Service
"Avira AntiVir Desktop" = Avira Free Antivirus
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Freecorder4.1" = Freecorder
"Google Chrome" = Google Chrome
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Keyboard LED Control V1.09_is1" = Keyboard LED Control V1.09
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 8.0 (x86 en-GB)" = Mozilla Firefox 8.0 (x86 en-GB)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OnlineArmor_is1" = Online Armor 5.5
"PhotoScape" = PhotoScape
"SP_56ec1d15" = Search Assistant MocaFlix 1.66
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YTdetect" = Yahoo! Detect
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-2228970593-2351082760-789675871-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/1/2013 AM 11:49:33 | Computer Name = TSTIOH5353 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 250000
Error - 3/1/2013 AM 11:49:33 | Computer Name = TSTIOH5353 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 250000
Error - 3/1/2013 AM 11:58:28 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 3/1/2013 PM 12:03:56 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 3/1/2013 PM 12:09:34 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 3/1/2013 PM 12:30:20 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 3/1/2013 PM 12:40:16 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 4/1/2013 PM 3:22:43 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 4/1/2013 PM 3:33:40 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 4/1/2013 PM 7:27:12 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
[ OSession Events ]
Error - 12/10/2011 PM 1:50:53 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 12352
seconds with 120 seconds of active time. This session ended with a crash.
Error - 29/10/2011 PM 12:47:06 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 1850
seconds with 120 seconds of active time. This session ended with a crash.
Error - 21/10/2011 AM 11:19:15 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 2073
seconds with 720 seconds of active time. This session ended with a crash.
Error - 22/10/2011 AM 6:47:31 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 767
seconds with 0 seconds of active time. This session ended with a crash.
Error - 22/10/2011 AM 7:06:57 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 1157
seconds with 60 seconds of active time. This session ended with a crash.
Error - 27/10/2011 PM 9:10:22 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 1772
seconds with 60 seconds of active time. This session ended with a crash.
Error - 28/10/2011 AM 1:16:39 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 34
seconds with 0 seconds of active time. This session ended with a crash.
Error - 28/10/2011 AM 1:52:54 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 2162
seconds with 0 seconds of active time. This session ended with a crash.
Error - 1/11/2011 PM 11:30:40 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 622
seconds with 0 seconds of active time. This session ended with a crash.
Error - 21/12/2012 AM 6:11:07 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
? ? ? , Microsoft Office Version: 12.0.6612.1000. This session lasted 41 seconds with
0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 31/12/2012 AM 10:05:19 | Computer Name = TSTIOH5353 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 1/1/2013 AM 10:16:14 | Computer Name = TSTIOH5353 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 1/1/2013 AM 10:25:08 | Computer Name = TSTIOH5353 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Documents and Settings\DAISYTAY\Local
Settings\Application Data\FLVService\lib\FLVSrvLib.dll. Reference error message:
Error Message is unavailable .
Error - 1/1/2013 AM 10:25:08 | Computer Name = TSTIOH5353 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Documents and Settings\DAISYTAY\Local
Settings\Application Data\FLVService\lib\FLVSrvLib.dll. Reference error message:
Error Message is unavailable .
Error - 2/1/2013 AM 10:18:01 | Computer Name = TSTIOH5353 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\WINDOWS\WindowsShell.Manifest.
Reference
error message: Error Message is unavailable .
Error - 2/1/2013 AM 10:18:48 | Computer Name = TSTIOH5353 | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 001E101F77CE has been denied by the DHCP server [removed] (The DHCP
Server sent a DHCPNACK message).
Error - 2/1/2013 AM 10:20:17 | Computer Name = TSTIOH5353 | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 001E101F77CE has been denied by the DHCP server [removed] (The DHCP
Server sent a DHCPNACK message).
Error - 2/1/2013 AM 10:22:48 | Computer Name = TSTIOH5353 | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 001E101F77CE has been denied by the DHCP server [removed] (The DHCP
Server sent a DHCPNACK message).
Error - 2/1/2013 AM 10:43:31 | Computer Name = TSTIOH5353 | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 001E101F5224 has been denied by the DHCP server [removed] (The DHCP
Server sent a DHCPNACK message).
Error - 3/1/2013 AM 11:37:16 | Computer Name = TSTIOH5353 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
< End of report >
Checkup.txt
Results of screen317's Security Check version 0.99.56
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
Avira Free Antivirus
Online Armor 5.5
`````````Anti-malware/Other Utilities Check:`````````
SUPERAntiSpyware
Malwarebytes Anti-Malware version 1.60.0.1800
Java™ 6 Update 31
Java version out of Date!
Adobe Flash Player 11.2.202.233
Adobe Reader 10.1.0
Adobe Reader out of Date!
Mozilla Firefox 8.0
Firefox out of Date!
Google Chrome 23.0.1271.95
Google Chrome 23.0.1271.97
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Tall Emu Online Armor OAcat.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 13%
Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````