kevin106
Topic Starter
My laptop with Win 7 Home Premium lately runs very slow. I wonder if it was infected. OTL scan was done.
OTL.txt
OTL logfile created on: 8/30/2013 12:05:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kevin\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.49 Gb Total Physical Memory | 0.49 Gb Available Physical Memory | 32.96% Memory free
2.98 Gb Paging File | 1.36 Gb Available in Paging File | 45.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 66.72 Gb Total Space | 43.81 Gb Free Space | 65.66% Space Free | Partition Type: NTFS
Computer Name: KEVIN-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Kevin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
PRC - C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe ()
PRC - C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe (Google Inc.)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited)
PRC - C:\Users\Kevin\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
========== Modules (No Company Name) ==========
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_elementtree.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32api.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_socket.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32ts.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._gdi_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\pysqlite2._sqlite.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\windows._cacheinvalidation.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32com.shell.shell.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._html2.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_multiprocessing.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32profile.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32crypt.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._misc_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\pythoncom27.dll ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_ctypes.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._core_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\PyWinTypes27.dll ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32security.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_ssl.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._windows_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_hashlib.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._wizard.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32process.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32pdh.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32file.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32inet.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._controls_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\pyexpat.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32event.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\unicodedata.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\select.pyd ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\libglesv2.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\libegl.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\ffmpegsumo.dll ()
MOD - C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
========== Services (SafeList) ==========
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (swi_service) – C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
SRV - (swi_update) – C:\ProgramData\Sophos\Web Intelligence\swi_update.exe (Sophos Limited)
SRV - (SAVAdminService) – C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
SRV - (SAVService) – C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
SRV - (Sophos AutoUpdate Service) – C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
SRV - (Sophos Web Control Service) – C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (eRecoveryService) – C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
========== Driver Services (SafeList) ==========
DRV - (SAVOnAccess) – C:\Windows\System32\drivers\savonaccess.sys (Sophos Limited)
DRV - (SKMScan) – C:\Windows\System32\drivers\skmscan.sys (Sophos Limited)
DRV - (sdcfilter) – C:\Windows\System32\drivers\sdcfilter.sys (Sophos Limited)
DRV - (SophosBootDriver) – C:\Windows\System32\drivers\SophosBootDriver.sys (Sophos Plc)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (int15) – C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {73546C17-705F-4776-96EF-A483F8695E63}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{73546C17-705F-4776-96EF-A483F8695E63}: "URL" = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncodin
g}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.62\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - Extension: Google Docs = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Unblock Youku = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnfnkhpgegpcingjbfihlkjeighnddk\2.6.7.3_0\
CHR - Extension: Gmail = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No CLSID value found.
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found.
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
O4 - HKCU..\Run: [8CB61047070556905AB7FB604CF2473F5483F0D5._service_run] C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7EE4F889-FC71-4682-A73C-8AD7FF413183}: DhcpNameServer = 192.168.2.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Acer02.JPG
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Acer02.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/08/30 00:00:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Kevin\Desktop\OTL.exe
[2013/08/29 22:12:17 | 000,000,000 | —D | C] – C:\Windows\Panther
[2013/08/29 09:47:12 | 000,000,000 | —D | C] – C:\Windows\System32\MRT
[2013/08/29 09:22:22 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/08/29 09:22:22 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/08/29 09:22:21 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/08/29 09:22:21 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/08/29 09:22:21 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/08/29 09:22:21 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/08/29 09:22:20 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/08/29 09:22:20 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/08/29 09:22:20 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/08/29 09:22:20 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/08/29 09:22:20 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/08/29 09:22:20 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/08/29 09:22:20 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/08/29 09:22:20 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/08/29 09:22:19 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/08/29 09:22:19 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/08/29 09:22:19 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/08/29 09:22:19 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/08/29 09:22:19 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/08/29 09:22:19 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/08/29 09:22:19 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/08/29 09:22:19 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/08/29 09:22:19 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/08/29 09:22:18 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/08/29 09:22:18 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/08/29 09:22:18 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/08/29 09:22:18 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/08/29 09:22:18 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/08/29 09:22:18 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/08/29 09:22:18 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/08/29 09:22:18 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/08/29 09:22:18 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/08/29 09:22:18 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/08/29 09:22:18 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/08/29 09:22:18 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/08/29 09:22:18 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/08/29 09:20:23 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/08/29 09:20:23 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/08/29 09:20:23 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/08/29 09:20:23 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/08/29 09:20:23 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/08/29 09:20:23 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/08/29 09:20:23 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/08/29 09:20:23 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/08/29 09:20:23 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/08/29 09:20:23 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/08/29 09:20:23 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/08/29 09:20:23 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/08/29 09:20:23 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/08/29 09:20:23 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/29 09:20:22 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/08/29 09:20:22 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/08/29 09:18:04 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/08/29 08:00:11 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/08/29 07:46:39 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/08/29 07:46:38 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/08/29 07:46:21 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wwanprotdim.dll
[2013/08/29 07:46:14 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptdlg.dll
[2013/08/29 07:45:54 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/08/29 07:45:52 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certenc.dll
[2013/08/29 07:45:07 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/08/29 07:45:01 | 002,347,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/08/29 07:44:57 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2013/08/29 07:44:18 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/08/29 07:44:06 | 000,218,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2013/08/29 07:23:36 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\addpcs
[2013/08/29 07:22:49 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2013/08/29 07:22:49 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Local\Wajam
[2013/08/29 07:22:17 | 000,000,000 | —D | C] – C:\Program Files\Wajam
[2013/08/29 07:19:34 | 000,894,600 | —- | C] (CNET Download.com) – C:\Users\Kevin\Desktop\cbsidlm-cbsi134-Temp_File_Cleaner-SEO-10628816.exe
[1 C:\Users\Kevin\Desktop\*.tmp files -> C:\Users\Kevin\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/08/30 00:07:19 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/30 00:01:03 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Kevin\Desktop\OTL.exe
[2013/08/29 22:17:51 | 000,010,048 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/29 22:17:50 | 000,010,048 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/29 22:13:22 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/29 22:11:06 | 000,410,200 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/08/29 22:10:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/29 22:10:03 | 1200,230,400 | -HS- | M] () – C:\hiberfil.sys
[2013/08/29 09:56:53 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/08/29 09:56:53 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/08/29 09:22:22 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/08/29 09:22:22 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/08/29 09:22:21 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/08/29 09:22:21 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/08/29 09:22:21 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/08/29 09:22:21 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/08/29 09:22:21 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/08/29 09:22:20 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/08/29 09:22:20 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/08/29 09:22:20 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/08/29 09:22:20 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/08/29 09:22:20 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/08/29 09:22:20 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/08/29 09:22:20 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/08/29 09:22:20 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/08/29 09:22:19 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/08/29 09:22:19 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/08/29 09:22:19 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/08/29 09:22:19 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/08/29 09:22:19 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/08/29 09:22:19 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/08/29 09:22:19 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/08/29 09:22:19 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/08/29 09:22:18 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/08/29 09:22:18 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/08/29 09:22:18 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/08/29 09:22:18 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/08/29 09:22:18 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/08/29 09:22:18 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/08/29 09:22:18 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/08/29 09:22:18 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/08/29 09:22:18 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/08/29 09:22:18 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/08/29 09:22:18 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/08/29 09:22:18 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/08/29 09:22:18 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/08/29 09:22:18 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/08/29 09:20:24 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/29 09:20:23 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/08/29 09:20:23 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/08/29 09:20:23 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/08/29 09:20:23 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/08/29 09:20:23 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/08/29 09:20:23 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/08/29 09:20:23 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/08/29 09:20:23 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/08/29 09:20:23 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/08/29 09:20:23 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/08/29 09:20:23 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/08/29 09:20:23 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/08/29 09:20:23 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/08/29 09:20:23 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/08/29 09:20:23 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/29 09:20:22 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/08/29 09:18:04 | 001,505,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/08/29 08:42:54 | 000,002,133 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/29 07:22:46 | 000,000,000 | —- | M] () – C:\end
[2013/08/29 07:19:56 | 000,894,600 | —- | M] (CNET Download.com) – C:\Users\Kevin\Desktop\cbsidlm-cbsi134-Temp_File_Cleaner-SEO-10628816.exe
[2013/08/07 04:22:04 | 000,238,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[1 C:\Users\Kevin\Desktop\*.tmp files -> C:\Users\Kevin\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/08/29 09:22:18 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/08/29 07:22:16 | 000,000,000 | —- | C] () – C:\end
[2013/01/17 00:11:05 | 000,000,142 | —- | C] () – C:\Windows\ODBC.INI
[2013/01/16 22:56:39 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2013/01/15 18:41:25 | 000,016,384 | —- | C] () – C:\Windows\System32\LauncheRyAgentUser.exe
[2013/01/15 18:41:25 | 000,016,384 | —- | C] ( ) – C:\Windows\System32\ClearEvent.exe
[2013/01/15 18:38:45 | 000,000,000 | —- | C] () – C:\Windows\SETUP.INI
[2013/01/15 18:04:26 | 000,000,092 | —- | C] () – C:\Windows\CLEANUP.INI
========== ZeroAccess Check ==========
[2009/07/13 21:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 21:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 05:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 18:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/01/16 22:52:43 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Acer
[2013/08/29 07:23:36 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\addpcs
[2013/01/16 22:52:43 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\GetRightToGo
[2013/01/16 22:52:43 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Leadertech
[2013/04/08 19:53:19 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Thinstall
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 19:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 14:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/02/25 22:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 19:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 19:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/04/23 20:34:47 | 000,138,668 | —- | M] () MD5=1C6962D48032784C1213726F6304D2D8 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: EXPLORER.ZIP >
[2006/03/06 22:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
< MD5 for: IEXPLORE.EXE >
[2013/07/24 19:48:45 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=139C8953AC56A9E559C7DEF07BC45ED7 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20613_none_b1cc6e48e11fccf7\iexplore.exe
[2013/02/21 21:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_b104f0edc83023b1\iexplore.exe
[2013/02/21 21:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_b183bdcce155df6c\iexplore.exe
[2013/07/24 19:42:37 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=57EC630DBD5F0713E77CB3540AB80A8E – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16502_none_b14ca11fc7faf7e5\iexplore.exe
[2013/01/08 15:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_b10dc045c829d512\iexplore.exe
[2013/08/29 09:22:21 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/08/29 09:22:21 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_ba6aa26e65e05c0d\iexplore.exe
[2013/01/17 19:57:30 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
[2013/02/01 21:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_b17dbc10e15b4762\iexplore.exe
[2012/11/16 09:33:24 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=B201AF83DF2E85323E29EB83E4046810 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_b11b910fc81f0526\iexplore.exe
[2012/11/15 20:08:47 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=C0BA71C1B3FB6E3DD432FF3CCAEBDC62 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_b1985d5ae1468e33\iexplore.exe
[2013/02/01 21:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_b0feef31c8358ba7\iexplore.exe
[2013/01/08 14:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_b18b8cdae1507776\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2013/01/17 19:57:31 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/08/29 09:22:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/08/29 09:22:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-38CD2DC9.PF >
[2013/08/29 09:17:11 | 000,019,784 | —- | M] () MD5=BC920AF9249F2D6B6FAB1F03B390DF53 – C:\Windows\Prefetch\IEXPLORE.EXE-38CD2DC9.pf
< MD5 for: SERVICES >
[2009/06/10 14:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 14:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 03:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 18:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 18:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 19:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 19:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/13 21:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 21:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 14:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 14:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 19:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/13 19:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 13:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 13:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: WINLOGON.ADML >
[2009/07/13 19:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 14:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 05:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 05:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 05:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 05:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
< MD5 for: WINLOGON.EXE-B020DC41.PF >
[2013/04/17 18:40:24 | 000,009,906 | —- | M] () MD5=F39F9262475CC1DACD8C1A0AE95B9EAC – C:\Windows\Prefetch\WINLOGON.EXE-B020DC41.pf
< MD5 for: WINLOGON.MFL >
[2009/07/13 19:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 19:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 13:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 13:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2007/01/14 04:28:55 | 000,003,269 | —- | M] () – C:\-20070114.log
[2013/01/15 22:02:23 | 000,004,621 | —- | M] () – C:\-20130115.log
[2007/01/14 04:16:30 | 000,000,166 | —- | M] () – C:\Arcade.log
[2009/06/10 14:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/11/20 05:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2013/01/16 23:44:04 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 14:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2013/08/29 07:22:46 | 000,000,000 | —- | M] () – C:\end
[2013/08/29 22:10:03 | 1200,230,400 | -HS- | M] () – C:\hiberfil.sys
[2013/01/15 21:57:12 | 000,000,379 | —- | M] () – C:\MDR.log
[2013/08/29 22:10:09 | 1600,311,296 | -HS- | M] () – C:\pagefile.sys
[2007/01/14 04:05:26 | 000,000,284 | —- | M] () – C:\RHDSetup.log
[2007/01/14 04:19:44 | 000,000,178 | —- | M] () – C:\setup.log
< %systemroot%\Fonts\*.com >
[2009/07/13 21:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 14:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 18:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 05:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 21:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is ACER
Volume Serial Number is 1099-6666
Directory of C:\
07/13/2009 09:53 PM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/13/2009 09:53 PM Application Data [C:\ProgramData]
07/13/2009 09:53 PM Desktop [C:\Users\Public\Desktop]
07/13/2009 09:53 PM Documents [C:\Users\Public\Documents]
07/13/2009 09:53 PM Favorites [C:\Users\Public\Favorites]
07/13/2009 09:53 PM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 09:53 PM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/13/2009 09:53 PM All Users [C:\ProgramData]
07/13/2009 09:53 PM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/13/2009 09:53 PM Application Data [C:\ProgramData]
07/13/2009 09:53 PM Desktop [C:\Users\Public\Desktop]
07/13/2009 09:53 PM Documents [C:\Users\Public\Documents]
07/13/2009 09:53 PM Favorites [C:\Users\Public\Favorites]
07/13/2009 09:53 PM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 09:53 PM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/13/2009 09:53 PM Application Data [C:\Users\Default\AppData\Roaming]
07/13/2009 09:53 PM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/13/2009 09:53 PM Local Settings [C:\Users\Default\AppData\Local]
07/13/2009 09:53 PM My Documents [C:\Users\Default\Documents]
07/13/2009 09:53 PM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/13/2009 09:53 PM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009 09:53 PM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/13/2009 09:53 PM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009 09:53 PM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009 09:53 PM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/13/2009 09:53 PM Application Data [C:\Users\Default\AppData\Local]
07/13/2009 09:53 PM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009 09:53 PM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/13/2009 09:53 PM My Music [C:\Users\Default\Music]
07/13/2009 09:53 PM My Pictures [C:\Users\Default\Pictures]
07/13/2009 09:53 PM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Kevin
01/16/2013 10:49 PM Application Data [C:\Users\Kevin\AppData\Roaming]
01/16/2013 10:49 PM Cookies [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Cookies]
01/16/2013 10:49 PM Local Settings [C:\Users\Kevin\AppData\Local]
01/16/2013 10:49 PM My Documents [C:\Users\Kevin\Documents]
01/16/2013 10:49 PM NetHood [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/16/2013 10:49 PM PrintHood [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/16/2013 10:49 PM Recent [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Recent]
01/16/2013 10:49 PM SendTo [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\SendTo]
01/16/2013 10:49 PM Start Menu [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu]
01/16/2013 10:49 PM Templates [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Kevin\AppData\Local
01/16/2013 10:49 PM Application Data [C:\Users\Kevin\AppData\Local]
01/16/2013 10:49 PM History [C:\Users\Kevin\AppData\Local\Microsoft\Windows\History]
01/16/2013 10:49 PM Temporary Internet Files [C:\Users\Kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Kevin\Documents
01/16/2013 10:49 PM My Music [C:\Users\Kevin\Music]
01/16/2013 10:49 PM My Pictures [C:\Users\Kevin\Pictures]
01/16/2013 10:49 PM My Videos [C:\Users\Kevin\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/13/2009 09:53 PM My Music [C:\Users\Public\Music]
07/13/2009 09:53 PM My Pictures [C:\Users\Public\Pictures]
07/13/2009 09:53 PM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 48,410,677,248 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/01/15 21:47:09 | 000,000,221 | -HS- | M] () – C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2013/01/17 22:20:12 | 000,000,221 | -HS- | M] () – C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2013/08/29 07:19:56 | 000,894,600 | —- | M] (CNET Download.com) – C:\Users\Kevin\Desktop\cbsidlm-cbsi134-Temp_File_Cleaner-SEO-10628816.exe
[2013/01/17 22:25:13 | 015,075,864 | —- | M] (Google Inc.) – C:\Users\Kevin\Desktop\GooglePinyinInstaller.exe
[2013/08/30 00:01:03 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Kevin\Desktop\OTL.exe
[1 C:\Users\Kevin\Desktop\*.tmp files -> C:\Users\Kevin\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-08-29 17:00:35
< End of report >
Extras.txt
OTL Extras logfile created on: 8/30/2013 12:05:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kevin\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.49 Gb Total Physical Memory | 0.49 Gb Available Physical Memory | 32.96% Memory free
2.98 Gb Paging File | 1.36 Gb Available in Paging File | 45.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 66.72 Gb Total Space | 43.81 Gb Free Space | 65.66% Space Free | Partition Type: NTFS
Computer Name: KEVIN-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"" =
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07FB4F3C-16F4-4D73-831F-67A3259320FB}" = rport=10243 | protocol=6 | dir=out | app=system |
"{345EB324-CBAA-41E4-A9EE-36735F67C73D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{37D14B3C-0EB0-469F-8C70-48F4BB1AEE10}" = rport=138 | protocol=17 | dir=out | app=system |
"{3A66E8DD-B83A-4098-94B4-B14BD884AA40}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4814C0A6-9008-4058-8FBC-99E5E22165A0}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{5C9A0760-E75C-476B-910B-3E57905728E0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{5DCB5A67-A8A9-4384-BB41-6FC4B6E99321}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{613DB84B-2025-4AB9-91D1-D88DA95135BE}" = lport=445 | protocol=6 | dir=in | app=system |
"{65E62E7B-3C34-4957-BCDD-3608568C644A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{751880B3-6F3E-489D-BDEE-573AB2B7FE02}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7B551164-2206-4A4E-8407-1F9AF2EAE0CB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7F563466-66C7-41AB-9FAC-5CE99872A8EB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{82BAB721-EF91-4C72-97C2-F68DD1ED5EE1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A73C8847-A1FE-42E4-82BE-2B58E5BFBAE7}" = lport=139 | protocol=6 | dir=in | app=system |
"{B6C48D16-CF82-47EC-96ED-E2283B392844}" = rport=445 | protocol=6 | dir=out | app=system |
"{BCB90625-1467-439C-86E5-32706856A469}" = rport=139 | protocol=6 | dir=out | app=system |
"{DAD893EB-0708-44D7-8C0C-F2FE2CCDA5DA}" = lport=137 | protocol=17 | dir=in | app=system |
"{E13DCD54-A941-4599-97FF-59768EAC3BA0}" = rport=137 | protocol=17 | dir=out | app=system |
"{EAAD9CF1-3C05-4C4A-83C6-07C2250D89FA}" = lport=10243 | protocol=6 | dir=in | app=system |
"{ED381E7D-475B-46F4-BD00-0377D831005A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F6DE7578-F398-4588-9342-0FED7E46C659}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FAF4555C-6C69-4C2F-A5C3-6A9FE0CB38C0}" = lport=138 | protocol=17 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F1EDC1A-65BC-4629-9EC0-0BD77557C5CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1753D194-856F-4AE0-9369-114E75CB72A6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{19CB0346-D080-44C3-8010-00AFB02CAA96}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{229F06F9-0B42-46B1-BBD2-7C9CD1164FCA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2C2B329B-5E01-4C3E-957C-03FF24040684}" = protocol=6 | dir=out | app=system |
"{564E4D93-0897-4A2C-966A-610B6241AC3C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6C9C30B9-77F6-42F1-A841-4DC026B157C1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6F543147-644B-4090-96C4-ACD0801D0D0E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{9FFA5CC5-281A-497A-86E0-B41EA59E6CB9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B0822FCC-36A7-4949-9186-673B39CC08EB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{B30C257D-FE0F-49C9-AAC7-B5CE9AEE32C6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BC1344E1-91F9-45FD-8187-F6B6710F915D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BD4B99DC-67A9-4E59-9F2F-03C2CB3259BA}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BFAFFB66-7EFE-4B5B-88A3-78775A820523}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C562013B-E0D1-416E-B0BB-BE2A0A3E67C2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CC2E1F5A-2046-4AC7-99F9-B9458960979D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D0BE4786-D665-44F7-A941-71861382C785}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{DEBD8B02-613F-42D1-82CC-16190AD99C51}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E6F108CE-BA19-496D-BCE3-FCBC82FF2905}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{F9486C25-8BD9-4002-B5ED-4109227DAC4C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0409969E-BEFB-44D3-90B9-63BE50FBAE5E}" = TIPCI
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{C2D4CD4A-AE20-40B3-8726-8ED1C03E8C15}" = Google Drive
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Chrome" = Google Chrome
"GooglePinyin2" = 谷歌拼音输入法 2.7
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{0409969E-BEFB-44D3-90B9-63BE50FBAE5E}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"LManager" = Launch Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wajam" = Wajam
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 2/15/2013 10:35:17 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:42:11 AM | Computer Name = Kevin-PC | Source = ESENT | ID = 215
Description = WinMail (2988) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.
Error - 3/4/2013 11:49:55 PM | Computer Name = Kevin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: ALMon.exe, version: 3.47.115.344, time
stamp: 0x50efe301 Faulting module name: ole32.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7b96f Exception code: 0xc0000005 Fault offset: 0x0003bc21 Faulting process
id: 0x8c4 Faulting application start time: 0x01ce195196b73bef Faulting application
path: C:\Program Files\Sophos\AutoUpdate\ALMon.exe Faulting module path: C:\Windows\system32\ole32.dll
Report
Id: bdcb2667-8547-11e2-a4e2-001636fab2c0
Error - 3/4/2013 11:52:27 PM | Computer Name = Kevin-PC | Source = VSS | ID = 8194
Description =
Error - 3/5/2013 11:34:10 PM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 3/24/2013 6:46:31 PM | Computer Name = Kevin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: googledrivesync.exe, version: 1.7.4018.3496,
time stamp: 0x509418e4 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec49b60 Exception code: 0xc0000005 Fault offset: 0x00052cc7 Faulting
process id: 0x948 Faulting application start time: 0x01ce28d6d4e034e5 Faulting application
path: C:\Program Files\Google\Drive\googledrivesync.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: ab5a1529-94d4-11e2-a07b-001636fab2c0
[ System Events ]
Error - 4/16/2013 1:03:40 AM | Computer Name = Kevin-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7EE4F889-FC71-4682-A73C-8AD7FF413183}
because another computer on the network has the same name. The server could not
start.
Error - 4/16/2013 1:03:40 AM | Computer Name = Kevin-PC | Source = NetBT | ID = 4321
Description = The name "KEVIN-PC :20" could not be registered on the interface
with IP address 192.168.2.6. The computer with the IP address 192.168.2.5 did not
allow the name to be claimed by this computer.
Error - 4/16/2013 1:48:12 PM | Computer Name = Kevin-PC | Source = bowser | ID = 8003
Description =
Error - 4/16/2013 4:59:21 PM | Computer Name = Kevin-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7EE4F889-FC71-4682-A73C-8AD7FF413183}
because another computer on the network has the same name. The server could not
start.
Error - 4/16/2013 4:59:22 PM | Computer Name = Kevin-PC | Source = NetBT | ID = 4321
Description = The name "KEVIN-PC :20" could not be registered on the interface
with IP address 192.168.2.4. The computer with the IP address 192.168.2.5 did not
allow the name to be claimed by this computer.
Error - 4/17/2013 1:07:53 AM | Computer Name = Kevin-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7EE4F889-FC71-4682-A73C-8AD7FF413183}
because another computer on the network has the same name. The server could not
start.
Error - 4/17/2013 1:07:53 AM | Computer Name = Kevin-PC | Source = NetBT | ID = 4321
Description = The name "KEVIN-PC :20" could not be registered on the interface
with IP address 192.168.2.4. The computer with the IP address 192.168.2.5 did not
allow the name to be claimed by this computer.
Error - 4/17/2013 2:48:01 PM | Computer Name = Kevin-PC | Source = bowser | ID = 8003
Description =
Error - 4/18/2013 12:40:17 AM | Computer Name = Kevin-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:39:43 PM on ?4/?17/?2013 was unexpected.
Error - 4/18/2013 1:08:41 PM | Computer Name = Kevin-PC | Source = bowser | ID = 8003
Description =
< End of report >
OTL.txt
OTL logfile created on: 8/30/2013 12:05:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kevin\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.49 Gb Total Physical Memory | 0.49 Gb Available Physical Memory | 32.96% Memory free
2.98 Gb Paging File | 1.36 Gb Available in Paging File | 45.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 66.72 Gb Total Space | 43.81 Gb Free Space | 65.66% Space Free | Partition Type: NTFS
Computer Name: KEVIN-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Kevin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
PRC - C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe ()
PRC - C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe (Google Inc.)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited)
PRC - C:\Users\Kevin\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
========== Modules (No Company Name) ==========
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_elementtree.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32api.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_socket.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32ts.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._gdi_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\pysqlite2._sqlite.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\windows._cacheinvalidation.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32com.shell.shell.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._html2.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_multiprocessing.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32profile.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32crypt.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._misc_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\pythoncom27.dll ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_ctypes.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._core_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\PyWinTypes27.dll ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32security.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_ssl.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._windows_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_hashlib.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._wizard.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32process.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32pdh.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32file.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32inet.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._controls_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\pyexpat.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32event.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\unicodedata.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\select.pyd ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\libglesv2.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\libegl.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\ffmpegsumo.dll ()
MOD - C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
========== Services (SafeList) ==========
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (swi_service) – C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
SRV - (swi_update) – C:\ProgramData\Sophos\Web Intelligence\swi_update.exe (Sophos Limited)
SRV - (SAVAdminService) – C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
SRV - (SAVService) – C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
SRV - (Sophos AutoUpdate Service) – C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
SRV - (Sophos Web Control Service) – C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (eRecoveryService) – C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
========== Driver Services (SafeList) ==========
DRV - (SAVOnAccess) – C:\Windows\System32\drivers\savonaccess.sys (Sophos Limited)
DRV - (SKMScan) – C:\Windows\System32\drivers\skmscan.sys (Sophos Limited)
DRV - (sdcfilter) – C:\Windows\System32\drivers\sdcfilter.sys (Sophos Limited)
DRV - (SophosBootDriver) – C:\Windows\System32\drivers\SophosBootDriver.sys (Sophos Plc)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (int15) – C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {73546C17-705F-4776-96EF-A483F8695E63}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{73546C17-705F-4776-96EF-A483F8695E63}: "URL" = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncodin
g}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.62\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - Extension: Google Docs = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Unblock Youku = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnfnkhpgegpcingjbfihlkjeighnddk\2.6.7.3_0\
CHR - Extension: Gmail = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No CLSID value found.
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found.
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
O4 - HKCU..\Run: [8CB61047070556905AB7FB604CF2473F5483F0D5._service_run] C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7EE4F889-FC71-4682-A73C-8AD7FF413183}: DhcpNameServer = 192.168.2.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Acer02.JPG
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Acer02.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/08/30 00:00:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Kevin\Desktop\OTL.exe
[2013/08/29 22:12:17 | 000,000,000 | —D | C] – C:\Windows\Panther
[2013/08/29 09:47:12 | 000,000,000 | —D | C] – C:\Windows\System32\MRT
[2013/08/29 09:22:22 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/08/29 09:22:22 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/08/29 09:22:21 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/08/29 09:22:21 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/08/29 09:22:21 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/08/29 09:22:21 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/08/29 09:22:20 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/08/29 09:22:20 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/08/29 09:22:20 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/08/29 09:22:20 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/08/29 09:22:20 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/08/29 09:22:20 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/08/29 09:22:20 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/08/29 09:22:20 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/08/29 09:22:19 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/08/29 09:22:19 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/08/29 09:22:19 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/08/29 09:22:19 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/08/29 09:22:19 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/08/29 09:22:19 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/08/29 09:22:19 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/08/29 09:22:19 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/08/29 09:22:19 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/08/29 09:22:18 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/08/29 09:22:18 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/08/29 09:22:18 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/08/29 09:22:18 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/08/29 09:22:18 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/08/29 09:22:18 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/08/29 09:22:18 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/08/29 09:22:18 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/08/29 09:22:18 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/08/29 09:22:18 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/08/29 09:22:18 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/08/29 09:22:18 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/08/29 09:22:18 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/08/29 09:20:23 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/08/29 09:20:23 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/08/29 09:20:23 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/08/29 09:20:23 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/08/29 09:20:23 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/08/29 09:20:23 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/08/29 09:20:23 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/08/29 09:20:23 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/08/29 09:20:23 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/08/29 09:20:23 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/08/29 09:20:23 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/08/29 09:20:23 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/08/29 09:20:23 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/08/29 09:20:23 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/29 09:20:22 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/08/29 09:20:22 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/08/29 09:18:04 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/08/29 08:00:11 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/08/29 07:46:39 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/08/29 07:46:38 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/08/29 07:46:21 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wwanprotdim.dll
[2013/08/29 07:46:14 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptdlg.dll
[2013/08/29 07:45:54 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/08/29 07:45:52 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certenc.dll
[2013/08/29 07:45:07 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/08/29 07:45:01 | 002,347,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/08/29 07:44:57 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2013/08/29 07:44:18 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/08/29 07:44:06 | 000,218,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2013/08/29 07:23:36 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\addpcs
[2013/08/29 07:22:49 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2013/08/29 07:22:49 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Local\Wajam
[2013/08/29 07:22:17 | 000,000,000 | —D | C] – C:\Program Files\Wajam
[2013/08/29 07:19:34 | 000,894,600 | —- | C] (CNET Download.com) – C:\Users\Kevin\Desktop\cbsidlm-cbsi134-Temp_File_Cleaner-SEO-10628816.exe
[1 C:\Users\Kevin\Desktop\*.tmp files -> C:\Users\Kevin\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/08/30 00:07:19 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/30 00:01:03 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Kevin\Desktop\OTL.exe
[2013/08/29 22:17:51 | 000,010,048 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/29 22:17:50 | 000,010,048 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/29 22:13:22 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/29 22:11:06 | 000,410,200 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/08/29 22:10:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/29 22:10:03 | 1200,230,400 | -HS- | M] () – C:\hiberfil.sys
[2013/08/29 09:56:53 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/08/29 09:56:53 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/08/29 09:22:22 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/08/29 09:22:22 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/08/29 09:22:21 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/08/29 09:22:21 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/08/29 09:22:21 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/08/29 09:22:21 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/08/29 09:22:21 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/08/29 09:22:20 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/08/29 09:22:20 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/08/29 09:22:20 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/08/29 09:22:20 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/08/29 09:22:20 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/08/29 09:22:20 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/08/29 09:22:20 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/08/29 09:22:20 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/08/29 09:22:19 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/08/29 09:22:19 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/08/29 09:22:19 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/08/29 09:22:19 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/08/29 09:22:19 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/08/29 09:22:19 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/08/29 09:22:19 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/08/29 09:22:19 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/08/29 09:22:18 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/08/29 09:22:18 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/08/29 09:22:18 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/08/29 09:22:18 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/08/29 09:22:18 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/08/29 09:22:18 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/08/29 09:22:18 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/08/29 09:22:18 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/08/29 09:22:18 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/08/29 09:22:18 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/08/29 09:22:18 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/08/29 09:22:18 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/08/29 09:22:18 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/08/29 09:22:18 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/08/29 09:20:24 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/29 09:20:23 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/08/29 09:20:23 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/08/29 09:20:23 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/08/29 09:20:23 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/08/29 09:20:23 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/08/29 09:20:23 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/08/29 09:20:23 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/08/29 09:20:23 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/08/29 09:20:23 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/08/29 09:20:23 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/08/29 09:20:23 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/08/29 09:20:23 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/08/29 09:20:23 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/08/29 09:20:23 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/08/29 09:20:23 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/29 09:20:22 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/08/29 09:18:04 | 001,505,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/08/29 08:42:54 | 000,002,133 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/29 07:22:46 | 000,000,000 | —- | M] () – C:\end
[2013/08/29 07:19:56 | 000,894,600 | —- | M] (CNET Download.com) – C:\Users\Kevin\Desktop\cbsidlm-cbsi134-Temp_File_Cleaner-SEO-10628816.exe
[2013/08/07 04:22:04 | 000,238,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[1 C:\Users\Kevin\Desktop\*.tmp files -> C:\Users\Kevin\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/08/29 09:22:18 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/08/29 07:22:16 | 000,000,000 | —- | C] () – C:\end
[2013/01/17 00:11:05 | 000,000,142 | —- | C] () – C:\Windows\ODBC.INI
[2013/01/16 22:56:39 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2013/01/15 18:41:25 | 000,016,384 | —- | C] () – C:\Windows\System32\LauncheRyAgentUser.exe
[2013/01/15 18:41:25 | 000,016,384 | —- | C] ( ) – C:\Windows\System32\ClearEvent.exe
[2013/01/15 18:38:45 | 000,000,000 | —- | C] () – C:\Windows\SETUP.INI
[2013/01/15 18:04:26 | 000,000,092 | —- | C] () – C:\Windows\CLEANUP.INI
========== ZeroAccess Check ==========
[2009/07/13 21:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 21:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 05:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 18:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/01/16 22:52:43 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Acer
[2013/08/29 07:23:36 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\addpcs
[2013/01/16 22:52:43 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\GetRightToGo
[2013/01/16 22:52:43 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Leadertech
[2013/04/08 19:53:19 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Thinstall
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 19:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 14:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/02/25 22:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 19:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 19:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/04/23 20:34:47 | 000,138,668 | —- | M] () MD5=1C6962D48032784C1213726F6304D2D8 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: EXPLORER.ZIP >
[2006/03/06 22:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
< MD5 for: IEXPLORE.EXE >
[2013/07/24 19:48:45 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=139C8953AC56A9E559C7DEF07BC45ED7 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20613_none_b1cc6e48e11fccf7\iexplore.exe
[2013/02/21 21:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_b104f0edc83023b1\iexplore.exe
[2013/02/21 21:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_b183bdcce155df6c\iexplore.exe
[2013/07/24 19:42:37 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=57EC630DBD5F0713E77CB3540AB80A8E – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16502_none_b14ca11fc7faf7e5\iexplore.exe
[2013/01/08 15:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_b10dc045c829d512\iexplore.exe
[2013/08/29 09:22:21 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/08/29 09:22:21 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_ba6aa26e65e05c0d\iexplore.exe
[2013/01/17 19:57:30 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
[2013/02/01 21:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_b17dbc10e15b4762\iexplore.exe
[2012/11/16 09:33:24 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=B201AF83DF2E85323E29EB83E4046810 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_b11b910fc81f0526\iexplore.exe
[2012/11/15 20:08:47 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=C0BA71C1B3FB6E3DD432FF3CCAEBDC62 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_b1985d5ae1468e33\iexplore.exe
[2013/02/01 21:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_b0feef31c8358ba7\iexplore.exe
[2013/01/08 14:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_b18b8cdae1507776\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2013/01/17 19:57:31 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/08/29 09:22:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/08/29 09:22:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-38CD2DC9.PF >
[2013/08/29 09:17:11 | 000,019,784 | —- | M] () MD5=BC920AF9249F2D6B6FAB1F03B390DF53 – C:\Windows\Prefetch\IEXPLORE.EXE-38CD2DC9.pf
< MD5 for: SERVICES >
[2009/06/10 14:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 14:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 03:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 18:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 18:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 19:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 19:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/13 21:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 21:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 14:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 14:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 19:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/13 19:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 13:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 13:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: WINLOGON.ADML >
[2009/07/13 19:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 14:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 05:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 05:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 05:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 05:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
< MD5 for: WINLOGON.EXE-B020DC41.PF >
[2013/04/17 18:40:24 | 000,009,906 | —- | M] () MD5=F39F9262475CC1DACD8C1A0AE95B9EAC – C:\Windows\Prefetch\WINLOGON.EXE-B020DC41.pf
< MD5 for: WINLOGON.MFL >
[2009/07/13 19:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 19:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 13:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 13:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2007/01/14 04:28:55 | 000,003,269 | —- | M] () – C:\-20070114.log
[2013/01/15 22:02:23 | 000,004,621 | —- | M] () – C:\-20130115.log
[2007/01/14 04:16:30 | 000,000,166 | —- | M] () – C:\Arcade.log
[2009/06/10 14:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/11/20 05:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2013/01/16 23:44:04 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 14:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2013/08/29 07:22:46 | 000,000,000 | —- | M] () – C:\end
[2013/08/29 22:10:03 | 1200,230,400 | -HS- | M] () – C:\hiberfil.sys
[2013/01/15 21:57:12 | 000,000,379 | —- | M] () – C:\MDR.log
[2013/08/29 22:10:09 | 1600,311,296 | -HS- | M] () – C:\pagefile.sys
[2007/01/14 04:05:26 | 000,000,284 | —- | M] () – C:\RHDSetup.log
[2007/01/14 04:19:44 | 000,000,178 | —- | M] () – C:\setup.log
< %systemroot%\Fonts\*.com >
[2009/07/13 21:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 14:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 18:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 05:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 21:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is ACER
Volume Serial Number is 1099-6666
Directory of C:\
07/13/2009 09:53 PM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/13/2009 09:53 PM Application Data [C:\ProgramData]
07/13/2009 09:53 PM Desktop [C:\Users\Public\Desktop]
07/13/2009 09:53 PM Documents [C:\Users\Public\Documents]
07/13/2009 09:53 PM Favorites [C:\Users\Public\Favorites]
07/13/2009 09:53 PM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 09:53 PM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/13/2009 09:53 PM All Users [C:\ProgramData]
07/13/2009 09:53 PM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/13/2009 09:53 PM Application Data [C:\ProgramData]
07/13/2009 09:53 PM Desktop [C:\Users\Public\Desktop]
07/13/2009 09:53 PM Documents [C:\Users\Public\Documents]
07/13/2009 09:53 PM Favorites [C:\Users\Public\Favorites]
07/13/2009 09:53 PM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 09:53 PM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/13/2009 09:53 PM Application Data [C:\Users\Default\AppData\Roaming]
07/13/2009 09:53 PM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/13/2009 09:53 PM Local Settings [C:\Users\Default\AppData\Local]
07/13/2009 09:53 PM My Documents [C:\Users\Default\Documents]
07/13/2009 09:53 PM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/13/2009 09:53 PM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009 09:53 PM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/13/2009 09:53 PM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009 09:53 PM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009 09:53 PM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/13/2009 09:53 PM Application Data [C:\Users\Default\AppData\Local]
07/13/2009 09:53 PM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009 09:53 PM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/13/2009 09:53 PM My Music [C:\Users\Default\Music]
07/13/2009 09:53 PM My Pictures [C:\Users\Default\Pictures]
07/13/2009 09:53 PM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Kevin
01/16/2013 10:49 PM Application Data [C:\Users\Kevin\AppData\Roaming]
01/16/2013 10:49 PM Cookies [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Cookies]
01/16/2013 10:49 PM Local Settings [C:\Users\Kevin\AppData\Local]
01/16/2013 10:49 PM My Documents [C:\Users\Kevin\Documents]
01/16/2013 10:49 PM NetHood [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/16/2013 10:49 PM PrintHood [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/16/2013 10:49 PM Recent [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Recent]
01/16/2013 10:49 PM SendTo [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\SendTo]
01/16/2013 10:49 PM Start Menu [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu]
01/16/2013 10:49 PM Templates [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Kevin\AppData\Local
01/16/2013 10:49 PM Application Data [C:\Users\Kevin\AppData\Local]
01/16/2013 10:49 PM History [C:\Users\Kevin\AppData\Local\Microsoft\Windows\History]
01/16/2013 10:49 PM Temporary Internet Files [C:\Users\Kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Kevin\Documents
01/16/2013 10:49 PM My Music [C:\Users\Kevin\Music]
01/16/2013 10:49 PM My Pictures [C:\Users\Kevin\Pictures]
01/16/2013 10:49 PM My Videos [C:\Users\Kevin\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/13/2009 09:53 PM My Music [C:\Users\Public\Music]
07/13/2009 09:53 PM My Pictures [C:\Users\Public\Pictures]
07/13/2009 09:53 PM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 48,410,677,248 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/01/15 21:47:09 | 000,000,221 | -HS- | M] () – C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2013/01/17 22:20:12 | 000,000,221 | -HS- | M] () – C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2013/08/29 07:19:56 | 000,894,600 | —- | M] (CNET Download.com) – C:\Users\Kevin\Desktop\cbsidlm-cbsi134-Temp_File_Cleaner-SEO-10628816.exe
[2013/01/17 22:25:13 | 015,075,864 | —- | M] (Google Inc.) – C:\Users\Kevin\Desktop\GooglePinyinInstaller.exe
[2013/08/30 00:01:03 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Kevin\Desktop\OTL.exe
[1 C:\Users\Kevin\Desktop\*.tmp files -> C:\Users\Kevin\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-08-29 17:00:35
< End of report >
Extras.txt
OTL Extras logfile created on: 8/30/2013 12:05:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kevin\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.49 Gb Total Physical Memory | 0.49 Gb Available Physical Memory | 32.96% Memory free
2.98 Gb Paging File | 1.36 Gb Available in Paging File | 45.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 66.72 Gb Total Space | 43.81 Gb Free Space | 65.66% Space Free | Partition Type: NTFS
Computer Name: KEVIN-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"" =
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07FB4F3C-16F4-4D73-831F-67A3259320FB}" = rport=10243 | protocol=6 | dir=out | app=system |
"{345EB324-CBAA-41E4-A9EE-36735F67C73D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{37D14B3C-0EB0-469F-8C70-48F4BB1AEE10}" = rport=138 | protocol=17 | dir=out | app=system |
"{3A66E8DD-B83A-4098-94B4-B14BD884AA40}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4814C0A6-9008-4058-8FBC-99E5E22165A0}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{5C9A0760-E75C-476B-910B-3E57905728E0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{5DCB5A67-A8A9-4384-BB41-6FC4B6E99321}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{613DB84B-2025-4AB9-91D1-D88DA95135BE}" = lport=445 | protocol=6 | dir=in | app=system |
"{65E62E7B-3C34-4957-BCDD-3608568C644A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{751880B3-6F3E-489D-BDEE-573AB2B7FE02}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7B551164-2206-4A4E-8407-1F9AF2EAE0CB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7F563466-66C7-41AB-9FAC-5CE99872A8EB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{82BAB721-EF91-4C72-97C2-F68DD1ED5EE1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A73C8847-A1FE-42E4-82BE-2B58E5BFBAE7}" = lport=139 | protocol=6 | dir=in | app=system |
"{B6C48D16-CF82-47EC-96ED-E2283B392844}" = rport=445 | protocol=6 | dir=out | app=system |
"{BCB90625-1467-439C-86E5-32706856A469}" = rport=139 | protocol=6 | dir=out | app=system |
"{DAD893EB-0708-44D7-8C0C-F2FE2CCDA5DA}" = lport=137 | protocol=17 | dir=in | app=system |
"{E13DCD54-A941-4599-97FF-59768EAC3BA0}" = rport=137 | protocol=17 | dir=out | app=system |
"{EAAD9CF1-3C05-4C4A-83C6-07C2250D89FA}" = lport=10243 | protocol=6 | dir=in | app=system |
"{ED381E7D-475B-46F4-BD00-0377D831005A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F6DE7578-F398-4588-9342-0FED7E46C659}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FAF4555C-6C69-4C2F-A5C3-6A9FE0CB38C0}" = lport=138 | protocol=17 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F1EDC1A-65BC-4629-9EC0-0BD77557C5CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1753D194-856F-4AE0-9369-114E75CB72A6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{19CB0346-D080-44C3-8010-00AFB02CAA96}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{229F06F9-0B42-46B1-BBD2-7C9CD1164FCA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2C2B329B-5E01-4C3E-957C-03FF24040684}" = protocol=6 | dir=out | app=system |
"{564E4D93-0897-4A2C-966A-610B6241AC3C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6C9C30B9-77F6-42F1-A841-4DC026B157C1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6F543147-644B-4090-96C4-ACD0801D0D0E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{9FFA5CC5-281A-497A-86E0-B41EA59E6CB9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B0822FCC-36A7-4949-9186-673B39CC08EB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{B30C257D-FE0F-49C9-AAC7-B5CE9AEE32C6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BC1344E1-91F9-45FD-8187-F6B6710F915D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BD4B99DC-67A9-4E59-9F2F-03C2CB3259BA}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BFAFFB66-7EFE-4B5B-88A3-78775A820523}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C562013B-E0D1-416E-B0BB-BE2A0A3E67C2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CC2E1F5A-2046-4AC7-99F9-B9458960979D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D0BE4786-D665-44F7-A941-71861382C785}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{DEBD8B02-613F-42D1-82CC-16190AD99C51}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E6F108CE-BA19-496D-BCE3-FCBC82FF2905}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{F9486C25-8BD9-4002-B5ED-4109227DAC4C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0409969E-BEFB-44D3-90B9-63BE50FBAE5E}" = TIPCI
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{C2D4CD4A-AE20-40B3-8726-8ED1C03E8C15}" = Google Drive
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Chrome" = Google Chrome
"GooglePinyin2" = 谷歌拼音输入法 2.7
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{0409969E-BEFB-44D3-90B9-63BE50FBAE5E}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"LManager" = Launch Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wajam" = Wajam
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 2/15/2013 10:35:17 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 2/15/2013 10:42:11 AM | Computer Name = Kevin-PC | Source = ESENT | ID = 215
Description = WinMail (2988) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.
Error - 3/4/2013 11:49:55 PM | Computer Name = Kevin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: ALMon.exe, version: 3.47.115.344, time
stamp: 0x50efe301 Faulting module name: ole32.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7b96f Exception code: 0xc0000005 Fault offset: 0x0003bc21 Faulting process
id: 0x8c4 Faulting application start time: 0x01ce195196b73bef Faulting application
path: C:\Program Files\Sophos\AutoUpdate\ALMon.exe Faulting module path: C:\Windows\system32\ole32.dll
Report
Id: bdcb2667-8547-11e2-a4e2-001636fab2c0
Error - 3/4/2013 11:52:27 PM | Computer Name = Kevin-PC | Source = VSS | ID = 8194
Description =
Error - 3/5/2013 11:34:10 PM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
Error - 3/24/2013 6:46:31 PM | Computer Name = Kevin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: googledrivesync.exe, version: 1.7.4018.3496,
time stamp: 0x509418e4 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec49b60 Exception code: 0xc0000005 Fault offset: 0x00052cc7 Faulting
process id: 0x948 Faulting application start time: 0x01ce28d6d4e034e5 Faulting application
path: C:\Program Files\Google\Drive\googledrivesync.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: ab5a1529-94d4-11e2-a07b-001636fab2c0
[ System Events ]
Error - 4/16/2013 1:03:40 AM | Computer Name = Kevin-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7EE4F889-FC71-4682-A73C-8AD7FF413183}
because another computer on the network has the same name. The server could not
start.
Error - 4/16/2013 1:03:40 AM | Computer Name = Kevin-PC | Source = NetBT | ID = 4321
Description = The name "KEVIN-PC :20" could not be registered on the interface
with IP address 192.168.2.6. The computer with the IP address 192.168.2.5 did not
allow the name to be claimed by this computer.
Error - 4/16/2013 1:48:12 PM | Computer Name = Kevin-PC | Source = bowser | ID = 8003
Description =
Error - 4/16/2013 4:59:21 PM | Computer Name = Kevin-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7EE4F889-FC71-4682-A73C-8AD7FF413183}
because another computer on the network has the same name. The server could not
start.
Error - 4/16/2013 4:59:22 PM | Computer Name = Kevin-PC | Source = NetBT | ID = 4321
Description = The name "KEVIN-PC :20" could not be registered on the interface
with IP address 192.168.2.4. The computer with the IP address 192.168.2.5 did not
allow the name to be claimed by this computer.
Error - 4/17/2013 1:07:53 AM | Computer Name = Kevin-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7EE4F889-FC71-4682-A73C-8AD7FF413183}
because another computer on the network has the same name. The server could not
start.
Error - 4/17/2013 1:07:53 AM | Computer Name = Kevin-PC | Source = NetBT | ID = 4321
Description = The name "KEVIN-PC :20" could not be registered on the interface
with IP address 192.168.2.4. The computer with the IP address 192.168.2.5 did not
allow the name to be claimed by this computer.
Error - 4/17/2013 2:48:01 PM | Computer Name = Kevin-PC | Source = bowser | ID = 8003
Description =
Error - 4/18/2013 12:40:17 AM | Computer Name = Kevin-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:39:43 PM on ?4/?17/?2013 was unexpected.
Error - 4/18/2013 1:08:41 PM | Computer Name = Kevin-PC | Source = bowser | ID = 8003
Description =
< End of report >