I've run FixTDSS from Symantec, but it founds nothing. And at the second try, my laptop failed to start and got the BSOD; it could only restart using Last Known Good Configuration. I also couldn't perform the full scan completely without having the laptop crashed
I also have tried Malwarebytes, it found and cleaned some malwares, but after I restarted my laptop, the Tidserv notifications still there.
Yesterday I installed Advanced SystemCare 5 in hope it will fix some errors and resolve the problem, but it seems that my laptop just got slower and the Tidserv notifications keep coming back.
Anything I can do with my laptop without reinstalling the Windows? Sorry for my poor English. Thanks for any and all help
Here's the OTL log file:
OTL logfile created on: 28/12/2011 18:31:25 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Windows\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.03 Gb Available Physical Memory | 51.59% Memory free
3.99 Gb Paging File | 2.78 Gb Available in Paging File | 69.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 58.50 Gb Total Space | 4.49 Gb Free Space | 7.67% Space Free | Partition Type: NTFS
Drive D: | 101.17 Gb Total Space | 7.98 Gb Free Space | 7.88% Space Free | Partition Type: NTFS
Drive E: | 13.05 Gb Total Space | 2.03 Gb Free Space | 15.56% Space Free | Partition Type: NTFS
Drive G: | 62.60 Gb Total Space | 7.67 Gb Free Space | 12.26% Space Free | Partition Type: NTFS
Drive H: | 62.67 Gb Total Space | 1.50 Gb Free Space | 2.39% Space Free | Partition Type: NTFS
Drive I: | 3.60 Gb Total Space | 0.52 Gb Free Space | 14.44% Space Free | Partition Type: FAT32
Computer Name: SEVEN-PC | User Name: Windows | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/27 23:11:24 | 000,494,424 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
PRC - [2011/12/14 13:13:28 | 000,748,440 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
PRC - [2011/12/13 17:42:08 | 000,922,976 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2011/10/23 04:23:03 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Users\Windows\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe
PRC - [2011/10/16 21:22:40 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Windows\Desktop\OTL.exe
PRC - [2011/06/24 12:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/20 20:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/11/20 20:16:54 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2010/06/02 19:15:58 | 000,014,336 | ---- | M] (LSI Corporation) -- C:\Program Files\LSI SoftModem\agrsmsvc.exe
PRC - [2010/06/01 10:17:48 | 005,252,408 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2010/04/08 04:57:42 | 000,099,896 | R--- | M] (HP) -- C:\Windows\System32\HPSIsvc.exe
PRC - [2010/03/23 14:53:06 | 000,229,458 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\stacsv.exe
PRC - [2009/09/22 11:50:36 | 000,073,728 | ---- | M] (Software 2000 Limited) -- C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE
PRC - [2009/07/27 02:10:00 | 001,983,816 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2009/07/23 16:13:32 | 000,040,960 | ---- | M] () -- C:\Program Files\Lock Folder XP\LFService.exe
PRC - [2009/07/14 09:14:28 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PING.EXE
PRC - [2009/06/03 18:12:50 | 000,599,344 | ---- | M] (Validity Sensors, Inc.) -- C:\Windows\System32\vfsFPService.exe
PRC - [2009/03/02 18:43:08 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\AEstSrv.exe
PRC - [2009/02/10 12:02:28 | 000,385,240 | R--- | M] (cFos Software GmbH) -- C:\Program Files\cFosSpeed\spd.exe
PRC - [2009/02/10 12:02:24 | 000,876,760 | R--- | M] (cFos Software GmbH) -- C:\Program Files\cFosSpeed\cfosspeed.exe
PRC - [2008/12/09 14:01:54 | 002,440,120 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
PRC - [2008/12/09 13:42:34 | 001,443,144 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2008/12/09 13:42:32 | 001,795,400 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
PRC - [2008/08/15 06:45:52 | 000,115,560 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2008/08/15 06:45:28 | 000,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/07/06 13:24:54 | 005,730,304 | ---- | M] () -- c:\Program Files\dbbmn\bin\mysqld.exe
========== Modules (No Company Name) ==========
MOD - [2010/11/20 20:19:56 | 000,232,448 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.DLL
MOD - [2010/11/20 20:19:56 | 000,232,448 | ---- | M] () -- \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2010/03/19 10:45:36 | 007,745,536 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\QtGui4.dll
MOD - [2010/03/19 10:45:36 | 002,121,728 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\QtCore4.dll
MOD - [2010/03/19 10:45:36 | 000,135,168 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2009/07/23 16:13:32 | 000,040,960 | ---- | M] () -- C:\Program Files\Lock Folder XP\LFService.exe
========== Win32 Services (SafeList) ==========
SRV - [2011/12/27 23:11:24 | 000,494,424 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe -- (AdvancedSystemCareService5)
SRV - [2011/12/14 13:13:28 | 000,748,440 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2011/05/28 18:18:59 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/02/10 15:29:24 | 000,150,528 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe -- (Sony Ericsson PCCompanion)
SRV - [2010/11/20 20:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2010/11/20 20:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2010/11/20 20:18:03 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2010/06/02 19:15:58 | 000,014,336 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2010/04/08 04:57:42 | 000,099,896 | R--- | M] (HP) [Auto | Running] -- C:\Windows\System32\HPSIsvc.exe -- (HPSIService)
SRV - [2010/03/23 14:53:06 | 000,229,458 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\stacsv.exe -- (STacSV)
SRV - [2009/07/14 09:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/06/03 18:12:50 | 000,599,344 | ---- | M] (Validity Sensors, Inc.) [Auto | Running] -- C:\Windows\System32\vfsFPService.exe -- (vfsFPService)
SRV - [2009/03/02 18:43:08 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\AEstSrv.exe -- (AESTFilters)
SRV - [2009/02/10 12:02:28 | 000,385,240 | R--- | M] (cFos Software GmbH) [Auto | Running] -- C:\Program Files\cFosSpeed\spd.exe -- (cFosSpeedS)
SRV - [2008/12/09 14:01:54 | 002,440,120 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2008/12/09 13:42:32 | 001,795,400 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2008/12/09 13:01:28 | 000,320,840 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2008/08/15 06:45:28 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2008/08/15 06:45:28 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2008/07/01 08:36:35 | 003,093,872 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2007/07/06 13:24:54 | 005,730,304 | ---- | M] () [Auto | Running] -- c:\program files\dbbmn\bin\mysqld.exe -- (MySQL)
========== Driver Services (SafeList) ==========
DRV - [2011/12/20 21:40:56 | 000,026,872 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\FixTDSS.sys -- (FixTDSS)
DRV - [2011/11/15 17:00:00 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/11/15 17:00:00 | 000,106,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/10/18 07:09:40 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20111226.032\navex15.sys -- (NAVEX15)
DRV - [2011/10/18 07:09:40 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20111226.032\naveng.sys -- (NAVENG)
DRV - [2011/06/21 17:46:10 | 000,167,936 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wpshelper.sys -- (WpsHelper)
DRV - [2011/05/16 03:35:25 | 000,107,616 | ---- | M] (SysProgs.org) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\BazisVirtualCDBus.sys -- (BazisVirtualCDBus)
DRV - [2010/11/20 20:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 18:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 18:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 17:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 17:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/11/20 16:39:17 | 000,074,752 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\tdx.sys -- (tdx)
DRV - [2010/07/16 15:03:36 | 000,025,656 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\hpdskflt.sys -- (hpdskflt)
DRV - [2010/07/16 15:03:18 | 000,035,896 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2010/06/02 19:15:58 | 001,161,760 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2010/03/23 14:53:06 | 000,423,424 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2010/03/15 10:38:44 | 000,123,504 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039unic.sys -- (s1039unic) Sony Ericsson Device 1039 USB Ethernet Emulation (WDM)
DRV - [2010/03/15 10:38:44 | 000,117,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039mgmt.sys -- (s1039mgmt) Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM)
DRV - [2010/03/15 10:38:44 | 000,113,904 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039obex.sys -- (s1039obex)
DRV - [2010/03/15 10:38:44 | 000,025,456 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039nd5.sys -- (s1039nd5) Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS)
DRV - [2010/03/15 09:38:44 | 000,124,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039mdm.sys -- (s1039mdm)
DRV - [2010/03/15 09:38:44 | 000,098,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039bus.sys -- (s1039bus) Sony Ericsson Device 1039 driver (WDM)
DRV - [2010/03/15 09:38:44 | 000,014,960 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039mdfl.sys -- (s1039mdfl)
DRV - [2010/03/06 15:40:57 | 000,017,408 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mvusbews.sys -- (mvusbews)
DRV - [2010/03/02 14:44:25 | 000,123,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2009/11/20 15:26:50 | 000,025,984 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2009/10/03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/08/22 12:24:04 | 000,066,592 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2009/07/23 11:03:54 | 000,116,136 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\jmcr.sys -- (JMCR)
DRV - [2009/07/14 07:54:16 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usb8023.sys -- (USB_RNDIS_51)
DRV - [2009/07/14 07:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/09 15:41:30 | 000,077,312 | ---- | M] (© Everstrike Software) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\LFSys.sys -- (LFSys)
DRV - [2009/05/21 06:08:40 | 000,059,904 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\enecir.sys -- (enecir)
DRV - [2009/05/13 10:35:40 | 000,203,824 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2009/04/30 00:46:54 | 000,015,872 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2009/03/26 07:02:36 | 002,340,224 | ---- | M] (Digital Camera) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SPUVCBv.sys -- (SPUVCbv)
DRV - [2009/02/10 12:02:34 | 000,787,672 | ---- | M] (cFos Software GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfosspeed.sys -- (cFosSpeed)
DRV - [2008/12/09 13:45:28 | 000,092,488 | ---- | M] (Symantec Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SYSTEM32\Drivers\SysPlant.sys -- (SysPlant)
DRV - [2008/12/09 13:43:46 | 000,042,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\WPSDRVnt.sys -- (WPS)
DRV - [2008/11/19 10:17:08 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\COH_Mon.sys -- (COH_Mon)
DRV - [2008/10/15 03:24:18 | 000,049,536 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Teefer2.sys -- (Teefer2)
DRV - [2008/10/14 04:31:46 | 000,319,664 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2008/10/14 04:31:46 | 000,279,600 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\srtsp.sys -- (SRTSP)
DRV - [2008/10/14 04:31:46 | 000,043,824 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2008/08/22 03:13:56 | 000,191,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2008/08/22 03:13:56 | 000,027,696 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2008/06/17 08:53:14 | 000,420,400 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2008/03/17 11:05:30 | 000,101,632 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/01/23 09:08:58 | 000,099,456 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\plkusbser.sys -- (plkusbser)
DRV - [2006/10/25 05:12:48 | 000,086,368 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\w200obex.sys -- (w200obex)
DRV - [2006/10/25 05:12:00 | 000,088,560 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\w200mgmt.sys -- (w200mgmt) Sony Ericsson W200 USB WMC Device Management Drivers (WDM)
DRV - [2006/10/25 05:11:12 | 000,097,056 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\w200mdm.sys -- (w200mdm)
DRV - [2006/10/25 05:11:08 | 000,009,328 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\w200mdfl.sys -- (w200mdfl)
DRV - [2006/10/25 05:10:20 | 000,061,504 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\w200bus.sys -- (w200bus) Sony Ericsson W200 driver (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.dapyx.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://id.msn.com/iat/us_id.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F6 D9 FE AF 62 70 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\4.9\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: D:\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: G:\Photo Editor\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@rim.com/npappworld: C:\Program Files\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll ()
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Media Software and Services Inc)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Windows\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Windows\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Windows\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Fiddler2\FiddlerHook [2011/02/09 16:07:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/11 11:41:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/22 23:10:51 | 000,000,000 | ---D | M]
[2011/09/05 20:44:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Windows\AppData\Roaming\mozilla\Extensions
[2011/09/05 20:44:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Windows\AppData\Roaming\mozilla\Extensions\[email protected]
[2011/12/27 22:04:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Windows\AppData\Roaming\mozilla\Firefox\Profiles\tbd7h4k8.default\extensions
[2011/11/29 11:35:04 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C:\Users\Windows\AppData\Roaming\mozilla\Firefox\Profiles\tbd7h4k8.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/05/27 13:59:30 | 000,000,000 | ---D | M] (Playboost Gamebar) -- C:\Users\Windows\AppData\Roaming\mozilla\Firefox\Profiles\tbd7h4k8.default\extensions\{A79D8B60-1FF0-47F0-8E79-8CDE1FECB0FD}
[2011/11/30 11:37:01 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Windows\AppData\Roaming\mozilla\Firefox\Profiles\tbd7h4k8.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/11/29 11:45:23 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Windows\AppData\Roaming\mozilla\Firefox\Profiles\tbd7h4k8.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/05/01 05:56:37 | 000,000,000 | ---D | M] (User Agent Switcher) -- C:\Users\Windows\AppData\Roaming\mozilla\Firefox\Profiles\tbd7h4k8.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/05/01 05:56:42 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Windows\AppData\Roaming\mozilla\Firefox\Profiles\tbd7h4k8.default\extensions\[email protected]
[2010/09/23 09:29:08 | 000,000,000 | ---D | M] (Multiply Toolbar) -- C:\Users\Windows\AppData\Roaming\mozilla\Firefox\Profiles\tbd7h4k8.default\extensions\[email protected]
[2011/05/01 05:56:38 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Windows\AppData\Roaming\mozilla\Firefox\Profiles\tbd7h4k8.default\extensions\[email protected]
[2011/12/27 22:02:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/01/13 11:37:05 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/04/28 20:22:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/23 12:02:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/03 09:22:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/18 12:12:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/17 17:29:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/26 10:40:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/24 18:51:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/05/11 11:41:17 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/07/13 00:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011/05/11 11:41:19 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/10/15 15:36:28 | 000,003,803 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\MyHeritage.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Windows\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Windows\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Windows\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Orbit Downloader (Enabled) = C:\Users\Windows\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: BlackBerry AppWorld (Enabled) = C:\Program Files\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll
CHR - plugin: Media Go Detector (Enabled) = C:\Program Files\Sony\Media Go\npmediago.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = D:\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = G:\Photo Editor\Picasa3\npPicasa3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Windows\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: We Heart It = C:\Users\Windows\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblenkmcolcdonmlfknbpbgjebabcoae\1.2.6_0\
CHR - Extension: Picnik = C:\Users\Windows\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmnggcpelemfookhlhkdfbechcdadfp\1.0.6_0\
CHR - Extension: Blog This! = C:\Users\Windows\AppData\Local\Google\Chrome\User Data\Default\Extensions\pengoopmcjnbflcjbmoeodbmoflcgjlk\0.2_0\
CHR - Extension: WWF Indonesia = C:\Users\Windows\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifcghcdmgljhjflhabcieaojeihllap\1.0\
Hosts file not found
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (MHTBPos00 Class) - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\4.9\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\4.9\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:\Program Files\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [cFosSpeed] C:\Program Files\cFosSpeed\cfosspeed.exe (cFos Software GmbH)
O4 - HKLM..\Run: [LFService] C:\Program Files\Lock Folder XP\LFService.exe ()
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Windows\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MyWirelessCard] C:\Program Files\PROLINK\PHS100\PROLINK HSDPA Modem.exe ()
O4 - HKCU..\Run: [SMΔRT-Protection] C:\Program Files\Smadav\SMΔRTP.exe (Smadsoft)
O4 - HKCU..\Run: [Sony Ericsson PC Companion] C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
O4 - HKCU..\Run: [WebcamMaxAutoRun] G:\Photo Editor\WebcamMax\WebcamMax.exe (CoolwareMax)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files\Fiddler2\Fiddler.exe (Eric Lawrence)
O9 - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files\Fiddler2\Fiddler.exe (Eric Lawrence)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000038 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000039 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000040 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000041 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000042 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000043 - %SystemRoot%\System32\winrnr.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Masters%20of%20Mystery%20-%20Crime%20of%20Fashion/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Masters%20of%20Mystery%20-%20Crime%20of%20Fashion/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F6B46FA-DDBD-4880-AE97-5666AABDB098}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/07/04 07:11:23 | 000,000,000 | ---D | M] - D:\auto -- [ NTFS ]
O32 - AutoRun File - [2011/12/05 20:50:38 | 000,000,000 | RHSD | M] - I:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{01b9274e-c1ba-11e0-81b8-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{01b9274e-c1ba-11e0-81b8-002622994ba7}\Shell\AutoRun\command - "" = M:\Setup.exe
O33 - MountPoints2\{01b92752-c1ba-11e0-81b8-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{01b92752-c1ba-11e0-81b8-002622994ba7}\Shell\AutoRun\command - "" = M:\Autorun.exe
O33 - MountPoints2\{054de98b-8d8f-11df-8bd0-8eb22499b347}\Shell - "" = AutoRun
O33 - MountPoints2\{054de98b-8d8f-11df-8bd0-8eb22499b347}\Shell\AutoRun\command - "" = I:\Startme.exe
O33 - MountPoints2\{063f25c4-f1e5-11de-867f-ce1910d3aa44}\Shell - "" = AutoRun
O33 - MountPoints2\{063f25d1-f1e5-11de-867f-ce1910d3aa44}\Shell - "" = AutoRun
O33 - MountPoints2\{0d312631-6ecd-11df-83cc-e10fb0d2d07c}\Shell - "" = AutoRun
O33 - MountPoints2\{0d312631-6ecd-11df-83cc-e10fb0d2d07c}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{1277e0d6-89b8-11e0-aa76-af8c4cdc2501}\Shell - "" = AutoRun
O33 - MountPoints2\{1277e0d6-89b8-11e0-aa76-af8c4cdc2501}\Shell\AutoRun\command - "" = I:\SISetup.exe
O33 - MountPoints2\{182f31b1-0f5d-11e0-9f6c-93d7d5e5f4e0}\Shell - "" = AutoRun
O33 - MountPoints2\{182f31b1-0f5d-11e0-9f6c-93d7d5e5f4e0}\Shell\AutoRun\command - "" = J:\AutoRun.exe
O33 - MountPoints2\{182f31b4-0f5d-11e0-9f6c-93d7d5e5f4e0}\Shell - "" = AutoRun
O33 - MountPoints2\{182f31b4-0f5d-11e0-9f6c-93d7d5e5f4e0}\Shell\AutoRun\command - "" = J:\AutoRun.exe
O33 - MountPoints2\{19b3d786-9663-11e0-bbd2-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{19b3d786-9663-11e0-bbd2-002622994ba7}\Shell\AutoRun\command - "" = M:\Autorun.exe
O33 - MountPoints2\{1e6374c5-f1e6-11de-9632-c5eb26147444}\Shell - "" = AutoRun
O33 - MountPoints2\{27ba60c6-9676-11e0-a914-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{27ba60c6-9676-11e0-a914-002622994ba7}\Shell\AutoRun\command - "" = M:\Autorun.exe
O33 - MountPoints2\{28b4fd24-956b-11e0-a265-00247eee1698}\Shell - "" = AutoRun
O33 - MountPoints2\{28b4fd24-956b-11e0-a265-00247eee1698}\Shell\AutoRun\command - "" = V:\Setup.exe
O33 - MountPoints2\{28b4fd4b-956b-11e0-a265-00247eee1698}\Shell - "" = AutoRun
O33 - MountPoints2\{28b4fd4b-956b-11e0-a265-00247eee1698}\Shell\AutoRun\command - "" = W:\Autorun.exe
O33 - MountPoints2\{36a8e1eb-8c2b-11df-ac3f-efe2abf63869}\Shell - "" = AutoRun
O33 - MountPoints2\{36a8e1eb-8c2b-11df-ac3f-efe2abf63869}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{3c028ec0-d874-11de-ae92-00247eee1698}\Shell - "" = AutoRun
O33 - MountPoints2\{3c028ec0-d874-11de-ae92-00247eee1698}\Shell\AutoRun\command - "" = K:\QsSetup.exe
O33 - MountPoints2\{4190a554-8d52-11e0-b6f7-fc7bef190d75}\Shell - "" = AutoRun
O33 - MountPoints2\{4190a554-8d52-11e0-b6f7-fc7bef190d75}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{4190a557-8d52-11e0-b6f7-fc7bef190d75}\Shell - "" = AutoRun
O33 - MountPoints2\{4190a557-8d52-11e0-b6f7-fc7bef190d75}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{55a1e561-f223-11de-b903-817ecb69c643}\Shell - "" = AutoRun
O33 - MountPoints2\{55a1e568-f223-11de-b903-817ecb69c643}\Shell - "" = AutoRun
O33 - MountPoints2\{55a1e568-f223-11de-b903-817ecb69c643}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{7e060411-9595-11e0-a2b5-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{7e060411-9595-11e0-a2b5-002622994ba7}\Shell\AutoRun\command - "" = W:\Setup.exe
O33 - MountPoints2\{8ef958ca-961b-11e0-bdbf-00247eee1698}\Shell - "" = AutoRun
O33 - MountPoints2\{8ef958ca-961b-11e0-bdbf-00247eee1698}\Shell\AutoRun\command - "" = J:\Autorun.exe
O33 - MountPoints2\{8ef958d7-961b-11e0-bdbf-00247eee1698}\Shell - "" = AutoRun
O33 - MountPoints2\{8ef958d7-961b-11e0-bdbf-00247eee1698}\Shell\AutoRun\command - "" = J:\Setup.exe
O33 - MountPoints2\{8ef958da-961b-11e0-bdbf-00247eee1698}\Shell - "" = AutoRun
O33 - MountPoints2\{8ef958da-961b-11e0-bdbf-00247eee1698}\Shell\AutoRun\command - "" = K:\Autorun.exe
O33 - MountPoints2\{8ef958e3-961b-11e0-bdbf-00247eee1698}\Shell - "" = AutoRun
O33 - MountPoints2\{8ef958e3-961b-11e0-bdbf-00247eee1698}\Shell\AutoRun\command - "" = L:\RunGame.exe
O33 - MountPoints2\{8ef958e9-961b-11e0-bdbf-00247eee1698}\Shell - "" = AutoRun
O33 - MountPoints2\{8ef958e9-961b-11e0-bdbf-00247eee1698}\Shell\AutoRun\command - "" = M:\Autorun.exe
O33 - MountPoints2\{a8a6292b-959e-11e0-a21e-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{a8a6292b-959e-11e0-a21e-002622994ba7}\Shell\AutoRun\command - "" = V:\Setup.exe
O33 - MountPoints2\{a8a62961-959e-11e0-a21e-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{a8a62961-959e-11e0-a21e-002622994ba7}\Shell\AutoRun\command - "" = W:\Autorun.exe
O33 - MountPoints2\{a8a62964-959e-11e0-a21e-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{a8a62964-959e-11e0-a21e-002622994ba7}\Shell\AutoRun\command - "" = X:\RunGame.exe
O33 - MountPoints2\{a8a6296c-959e-11e0-a21e-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{a8a6296c-959e-11e0-a21e-002622994ba7}\Shell\AutoRun\command - "" = X:\RunGame.exe
O33 - MountPoints2\{a8a6296d-959e-11e0-a21e-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{a8a6296d-959e-11e0-a21e-002622994ba7}\Shell\AutoRun\command - "" = Y:\Setup.exe
O33 - MountPoints2\{a8a62970-959e-11e0-a21e-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{a8a62970-959e-11e0-a21e-002622994ba7}\Shell\AutoRun\command - "" = J:\Autorun.exe
O33 - MountPoints2\{b09786f0-8daa-11e0-898d-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{b09786f0-8daa-11e0-898d-002622994ba7}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{b09786f3-8daa-11e0-898d-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{b09786f3-8daa-11e0-898d-002622994ba7}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{e08cdf1a-9558-11e0-a291-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{e08cdf1a-9558-11e0-a291-002622994ba7}\Shell\AutoRun\command - "" = V:\RunGame.exe
O33 - MountPoints2\{e08cdf2c-9558-11e0-a291-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{e08cdf2c-9558-11e0-a291-002622994ba7}\Shell\AutoRun\command - "" = V:\Setup.exe
O33 - MountPoints2\{e08cdf2f-9558-11e0-a291-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{e08cdf2f-9558-11e0-a291-002622994ba7}\Shell\AutoRun\command - "" = V:\RunGame.exe
O33 - MountPoints2\{e08cdf3a-9558-11e0-a291-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{e08cdf3a-9558-11e0-a291-002622994ba7}\Shell\AutoRun\command - "" = V:\RunGame.exe
O33 - MountPoints2\{e08cdf3d-9558-11e0-a291-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{e08cdf3d-9558-11e0-a291-002622994ba7}\Shell\AutoRun\command - "" = V:\RunGame.exe
O33 - MountPoints2\{e08cdf44-9558-11e0-a291-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{e08cdf44-9558-11e0-a291-002622994ba7}\Shell\AutoRun\command - "" = V:\Setup.exe
O33 - MountPoints2\{ede4f663-9498-11e0-bd61-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{ede4f663-9498-11e0-bd61-002622994ba7}\Shell\AutoRun\command - "" = V:\Setup.exe
O33 - MountPoints2\{ede4f666-9498-11e0-bd61-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{ede4f666-9498-11e0-bd61-002622994ba7}\Shell\AutoRun\command - "" = V:\RunGame.exe
O33 - MountPoints2\{ede4f668-9498-11e0-bd61-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{ede4f668-9498-11e0-bd61-002622994ba7}\Shell\AutoRun\command - "" = V:\RunGame.exe
O33 - MountPoints2\{ede4f66a-9498-11e0-bd61-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{ede4f66a-9498-11e0-bd61-002622994ba7}\Shell\AutoRun\command - "" = V:\RunGame.exe
O33 - MountPoints2\{ede4f674-9498-11e0-bd61-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{ede4f674-9498-11e0-bd61-002622994ba7}\Shell\AutoRun\command - "" = V:\Setup.exe
O33 - MountPoints2\{ede4f677-9498-11e0-bd61-002622994ba7}\Shell - "" = AutoRun
O33 - MountPoints2\{ede4f677-9498-11e0-bd61-002622994ba7}\Shell\AutoRun\command - "" = W:\RunGame.exe
O33 - MountPoints2\{f199f647-f380-11de-a052-8c723d2da163}\Shell - "" = AutoRun
O33 - MountPoints2\{f199f654-f380-11de-a052-8c723d2da163}\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\QsSetup.exe
O33 - MountPoints2\J\Shell - "" = AutoRun
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\QsSetup.exe
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\QsSetup.exe
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\QsSetup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/28 17:04:05 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Windows\Desktop\OTL.exe
[2011/12/28 09:00:50 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/12/27 22:03:52 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
[2011/12/27 22:03:50 | 000,000,000 | ---D | C] -- C:\Program Files\YouTube Downloader Toolbar
[2011/12/27 22:03:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot
[2011/12/27 21:14:12 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2011/12/27 21:11:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5
[2011/12/27 21:11:56 | 000,000,000 | ---D | C] -- C:\Users\Windows\AppData\Roaming\IObit
[2011/12/27 21:11:44 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2011/12/10 15:08:50 | 000,026,872 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\FixTDSS.sys
[2011/12/10 15:08:50 | 000,000,000 | ---D | C] -- C:\Users\Windows\AppData\Roaming\FixTDSS
[2011/12/04 19:08:10 | 001,932,256 | ---- | C] (Symantec Corporation) -- C:\Users\Windows\Desktop\FixTDSS.exe
[2011/12/01 17:21:52 | 029,622,600 | ---- | C] (Rovio) -- C:\Users\Windows\AppData\Roaming\AngryBirdsSeasonsInstaller_2.0.0.exe
[2011/12/01 17:21:48 | 001,491,216 | ---- | C] (Rovio Mobile) -- C:\Users\Windows\AppData\Roaming\AngryBirdsSeasons.exe
[2011/11/30 12:50:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rovio
========== Files - Modified Within 30 Days ==========
[2011/12/28 18:28:01 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3626651802-3374829526-3147755075-1000UA.job
[2011/12/28 18:10:30 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/28 17:35:55 | 000,013,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/28 17:35:55 | 000,013,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/28 17:34:15 | 000,007,607 | ---- | M] () -- C:\Users\Windows\AppData\Local\Resmon.ResmonCfg
[2011/12/28 17:10:17 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/28 16:55:55 | 000,698,228 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/28 16:55:55 | 000,132,610 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/28 16:45:39 | 000,006,650 | ---- | M] () -- C:\Windows\PROLINK HSDPA Modem.INI
[2011/12/28 16:35:08 | 000,409,784 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/28 16:34:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/28 16:34:44 | 1608,216,576 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/28 01:43:24 | 000,002,373 | ---- | M] () -- C:\Users\Windows\Desktop\Google Chrome.lnk
[2011/12/28 01:22:04 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3626651802-3374829526-3147755075-1000UA.job
[2011/12/27 22:22:07 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3626651802-3374829526-3147755075-1000Core.job
[2011/12/27 21:28:57 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForWindows.job
[2011/12/27 21:12:01 | 000,001,165 | ---- | M] () -- C:\Users\Public\Desktop\Quick Care.lnk
[2011/12/27 21:11:58 | 000,001,143 | ---- | M] () -- C:\Users\Public\Desktop\Advanced SystemCare 5.lnk
[2011/12/20 21:40:56 | 000,026,872 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\FixTDSS.sys
[2011/12/11 07:43:04 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3626651802-3374829526-3147755075-1000Core.job
[2011/12/05 21:20:54 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2011/12/04 19:14:25 | 001,932,256 | ---- | M] (Symantec Corporation) -- C:\Users\Windows\Desktop\FixTDSS.exe
[2011/12/04 13:42:04 | 000,001,739 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2011/12/04 00:37:04 | 000,000,330 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForSEVEN-PC$.job
[2011/12/01 17:21:52 | 029,622,600 | ---- | M] (Rovio) -- C:\Users\Windows\AppData\Roaming\AngryBirdsSeasonsInstaller_2.0.0.exe
[2011/12/01 17:21:48 | 001,491,216 | ---- | M] (Rovio Mobile) -- C:\Users\Windows\AppData\Roaming\AngryBirdsSeasons.exe
[2011/11/30 12:50:24 | 000,001,641 | ---- | M] () -- C:\Users\Public\Desktop\Angry Birds Rio.lnk
========== Files Created - No Company Name ==========
[2011/12/27 21:12:01 | 000,001,165 | ---- | C] () -- C:\Users\Public\Desktop\Quick Care.lnk
[2011/12/27 21:11:58 | 000,001,143 | ---- | C] () -- C:\Users\Public\Desktop\Advanced SystemCare 5.lnk
[2011/12/10 15:47:33 | 000,000,328 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForWindows.job
[2011/12/04 13:42:04 | 000,001,751 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2011/12/04 13:42:04 | 000,001,739 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2011/11/30 12:50:24 | 000,001,641 | ---- | C] () -- C:\Users\Public\Desktop\Angry Birds Rio.lnk
[2011/10/05 22:10:39 | 000,794,906 | ---- | C] () -- C:\Windows\unins000.exe
[2011/10/05 22:10:39 | 000,004,153 | ---- | C] () -- C:\Windows\unins000.dat
[2011/07/27 11:37:37 | 000,000,000 | ---- | C] () -- C:\Users\Windows\AppData\Local\{B5FDDFDB-1CEA-4BD4-ADDA-1A0FEC47C3CD}
[2011/06/30 23:36:40 | 000,000,000 | ---- | C] () -- C:\Users\Windows\AppData\Local\{8A69D9AB-51D4-4B6A-90FC-AAD3EFEF5A45}
[2011/05/30 11:13:33 | 000,081,920 | ---- | C] () -- C:\Windows\System32\mvusbews.dll
[2011/05/30 11:13:28 | 000,047,104 | ---- | C] () -- C:\Windows\System32\HP1100SMs.dll
[2011/05/30 11:13:24 | 001,511,424 | ---- | C] () -- C:\Windows\System32\HP1100SM.EXE
[2011/05/30 11:13:24 | 000,147,456 | ---- | C] () -- C:\Windows\System32\HP1100LM.DLL
[2011/05/09 07:32:29 | 000,000,000 | ---- | C] () -- C:\Users\Windows\AppData\Local\{1F8AA570-28C0-445A-B9AD-890D17541DC1}
[2011/04/27 14:27:07 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/04/27 14:25:32 | 000,074,752 | ---- | C] () -- C:\Windows\System32\drivers\tdx.sys
[2011/04/27 14:25:05 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/03/03 13:11:57 | 000,000,082 | ---- | C] () -- C:\Windows\mafosav.INI
[2011/02/26 07:58:43 | 000,000,064 | -H-- | C] () -- C:\Windows\pb.dat
[2011/01/10 11:23:38 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2010/11/09 18:28:32 | 000,000,000 | ---- | C] () -- C:\Windows\Player.INI
[2010/11/08 19:30:04 | 000,147,456 | ---- | C] () -- C:\Windows\autoclk.exe
[2010/11/08 19:30:04 | 000,049,152 | ---- | C] () -- C:\Windows\pnpclk.dll
[2010/10/15 15:48:50 | 000,001,227 | ---- | C] () -- C:\Windows\MyHeritage.INI
[2010/10/15 15:36:21 | 000,454,656 | ---- | C] () -- C:\Windows\System32\PaintX.dll
[2010/10/09 21:38:06 | 000,139,776 | ---- | C] () -- C:\Windows\System32\RTPScan.dll
[2010/10/09 21:38:06 | 000,133,632 | ---- | C] () -- C:\Windows\System32\PCMAVext.dll
[2010/08/01 22:56:10 | 000,000,045 | ---- | C] () -- C:\Windows\AutoScreenRecorder.INI
[2010/07/27 12:40:12 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010/07/21 10:00:31 | 000,139,152 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010/07/21 10:00:30 | 000,139,152 | ---- | C] () -- C:\Users\Windows\AppData\Roaming\PnkBstrK.sys
[2010/07/21 10:00:19 | 000,111,928 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010/07/21 10:00:14 | 000,794,408 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2010/07/21 10:00:14 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010/07/10 14:30:21 | 000,003,584 | ---- | C] () -- C:\Users\Windows\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/30 09:30:35 | 000,000,023 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2010/06/26 22:59:07 | 000,168,448 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/06/19 11:32:34 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010/06/02 19:17:19 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2010/04/05 13:03:54 | 000,065,536 | ---- | C] () -- C:\Windows\System32\HPPLVS.dll
[2010/03/05 20:57:58 | 000,000,990 | -HS- | C] () -- C:\Users\Windows\AppData\Roaming\systemfl.$dk
[2010/03/05 15:03:20 | 000,284,160 | R--- | C] () -- C:\Windows\System32\mvhlewsi.dll
[2010/02/27 14:48:03 | 000,007,607 | ---- | C] () -- C:\Users\Windows\AppData\Local\Resmon.ResmonCfg
[2010/01/09 19:27:17 | 000,000,008 | ---- | C] () -- C:\Windows\System32\F73859.bin
[2010/01/09 19:27:14 | 000,000,008 | ---- | C] () -- C:\Windows\System32\e9243f.bin
[2010/01/09 19:01:53 | 000,122,880 | ---- | C] () -- C:\Windows\UnGins.exe
[2009/11/24 05:16:18 | 000,006,650 | ---- | C] () -- C:\Windows\PROLINK HSDPA Modem.INI
[2009/10/25 22:27:20 | 000,013,312 | ---- | C] () -- C:\Windows\LPRES.DLL
[2009/07/14 12:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,409,784 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,698,228 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,132,610 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/11 05:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/01 10:48:16 | 000,053,478 | ---- | C] () -- C:\Windows\mvtcpui.ini
[2007/11/15 08:17:34 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CogentBioSDK.dll
========== LOP Check ==========
[2010/03/05 21:27:44 | 000,000,000 | -HSD | M] -- C:\Users\Windows\AppData\Roaming\.#
[2011/07/05 23:20:35 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\.minecraft
[2010/06/14 19:53:01 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\.purple
[2010/02/27 16:41:25 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\3M
[2010/06/26 15:17:23 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Artogon
[2011/12/27 21:24:06 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\BitTorrent
[2011/11/14 10:22:51 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Camfrog
[2010/07/28 16:01:08 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Canon
[2009/12/17 22:26:43 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\DAEMON Tools Lite
[2010/03/08 11:26:01 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\DriverCure
[2011/10/05 22:13:42 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\FFSJ
[2011/12/10 15:08:50 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\FixTDSS
[2011/09/05 20:44:38 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Flickr
[2010/03/03 21:45:24 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\FreeFixer
[2011/02/28 19:43:59 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Gamelab
[2010/02/27 16:46:27 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\GetRightToGo
[2009/11/27 14:16:58 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\GrabPro
[2010/01/05 20:30:23 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\gtk-2.0
[2011/03/16 09:57:23 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\IBAGroup
[2011/12/27 21:11:56 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\IObit
[2011/10/24 17:05:47 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Money Manager Ex
[2010/10/15 18:43:49 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\MyHeritage
[2011/11/08 18:25:23 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\MyPhoneExplorer
[2010/10/07 19:13:18 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Opera
[2011/12/28 17:17:38 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Orbit
[2011/02/26 08:04:24 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Petbook
[2011/05/26 19:56:40 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\PhotoScape
[2011/09/30 11:36:39 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Pogo Games
[2011/11/30 12:52:19 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Rovio
[2011/07/13 21:47:29 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Smadav
[2010/07/13 21:31:22 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Sony
[2011/01/12 10:13:29 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\SpinTop
[2011/01/31 13:40:03 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\SYSTEMAX Software Development
[2010/10/15 15:36:20 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\The Complete Genealogy Reporter - FTB
[2009/11/27 11:44:19 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\uTorrent
[2009/11/27 16:09:10 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\VitySoft
[2010/10/13 15:59:32 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\WebcamMax
[2011/11/28 20:48:34 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\Wildfire
[2010/06/04 09:09:11 | 000,000,000 | ---D | M] -- C:\Users\Windows\AppData\Roaming\WinBatch
[2011/12/27 22:22:07 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3626651802-3374829526-3147755075-1000Core.job
[2011/12/28 01:22:04 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3626651802-3374829526-3147755075-1000UA.job
[2011/12/27 22:31:18 | 000,032,552 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2011/12/20 18:36:55 | 000,000,692 | ---- | M] ()(C:\Users\Public\Desktop\SMAD?V.lnk) -- C:\Users\Public\Desktop\SMADΔV.lnk
[2010/10/13 08:20:16 | 000,000,692 | ---- | C] ()(C:\Users\Public\Desktop\SMAD?V.lnk) -- C:\Users\Public\Desktop\SMADΔV.lnk
========== Alternate Data Streams ==========
@Alternate Data Stream - 842 bytes -> C:\ProgramData\Temp:35E5AF34
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:8FF81EB0
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:CFA8C6E3
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:3B5038B1
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:7E6454EB
< End of report >
Extras.txt generated by OTL:
OTL Extras logfile created on: 28/12/2011 18:31:25 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Windows\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.03 Gb Available Physical Memory | 51.59% Memory free
3.99 Gb Paging File | 2.78 Gb Available in Paging File | 69.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 58.50 Gb Total Space | 4.49 Gb Free Space | 7.67% Space Free | Partition Type: NTFS
Drive D: | 101.17 Gb Total Space | 7.98 Gb Free Space | 7.88% Space Free | Partition Type: NTFS
Drive E: | 13.05 Gb Total Space | 2.03 Gb Free Space | 15.56% Space Free | Partition Type: NTFS
Drive G: | 62.60 Gb Total Space | 7.67 Gb Free Space | 12.26% Space Free | Partition Type: NTFS
Drive H: | 62.67 Gb Total Space | 1.50 Gb Free Space | 2.39% Space Free | Partition Type: NTFS
Drive I: | 3.60 Gb Total Space | 0.52 Gb Free Space | 14.44% Space Free | Partition Type: FAT32
Computer Name: SEVEN-PC | User Name: Windows | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UacDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"FirstRunDisabled" = 0
"UacDisableNotify" = 0
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{01521746-02A6-4A72-00BD-A285DF6B80C6}" = The Sims 2 University
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{06283453-7826-2168-5324-689421793582}" = MessengerData WMP Plugin
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation®Store
"{1061DF04-CF33-40B0-8360-D07C9BBEB122}" = HP Wireless Assistant
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series" = Canon iP2700 series Printer Driver
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 3.3
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java 6 Update 29
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{3744B641-61DE-417F-BCDC-9CCED4224DF8}" = LightScribe System Software
"{395AB8C5-F3A8-4380-8718-7A11EC5829F9}" = PHS100
"{3BAB4914-9CC1-4CC2-A3DA-56EF62DFD373}" = Symantec Endpoint Protection
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{4933D2E2-B621-487F-A7E7-96DA7312BCFE}" = Angry Birds Rio
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57CDBAE6-0896-4E78-88F0-C673E4BB44FD}" = Lock Folder XP
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71381523-BEA1-4410-954E-36EEF570DBA8}_is1" = Empires & Allies version 2.2a
"{724D7BEE-883D-452E-B8DA-26E88343CAE9}" = ADSL MODEM USB Driver
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{8DE03F6E-FCD2-4497-A8FF-F6C4430618B6}" = BlackBerry App World Browser Plugin
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EC63FE1-D017-460D-90B1-CCC97239AF73}" = Media Go
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Alps Touch Pad Driver
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA668889-AA01-AA01-AADC-65462C3DE344}" = FreeFixer
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B53E61D7-7C80-40DF-82D2-CF5390D6D20A}" = HP Advisor
"{B60DCA15-56A3-4D2D-8747-22CF7D7B588B}" = HP Support Assistant
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation®Network Downloader
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 2.01.173
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{F65B8208-5221-43D9-AA12-DDEA64EC4AF6}" = Validity Sensors software
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{FD66AF34-C18A-4cea-8421-2F3B39E9B07E}" = YouTube Downloader Toolbar v4.9
"5B73F775A90397BAF80173B8A6C0B327BE3872FB" = ENE CIR Receiver Driver
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced PC Tweaker_is1" = Advanced PC Tweaker v4.2
"Advanced SystemCare 5_is1" = Advanced SystemCare 5
"AVerMedia TV Tuner Card" = AVerMedia TV Tuner Card 1.0.0.4
"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CanonMyPrinter" = Canon Utilities My Printer
"cFosSpeed" = cFosSpeed v4.50
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"conduitEngine" = Conduit Engine
"Dapyx Messenger Archive_is1" = Dapyx Messenger Archive v1.02
"Dream Day Wedding - Viva Las Vegas 1.00" = Dream Day Wedding - Viva Las Vegas 1.00
"Dream Day Wedding Bella ItaliaJust For Fun Games" = Dream Day Wedding Bella ItaliaJust For Fun Games
"Dream Day Wedding Married in Manhattan" = Dream Day Wedding Married in Manhattan
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EOS Utility" = Canon Utilities EOS Utility
"Family Tree Builder" = MyHeritage Family Tree Builder
"Fiddler2" = Fiddler2
"File Splitter and Joiner_is1" = File Splitter and Joiner (FFSJ v3.3)
"Flickr Uploadr" = Flickr Uploadr 3.2.1
"GOM Player" = GOM Player
"GTK 2.0" = GTK+ Runtime 2.14.7 rev a (remove only)
"HP LaserJet Professional P1100-P1560-P1600 Series" = HP LaserJet Professional P1100-P1560-P1600 Series
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.5 (Basic)
"Latihan Soal CPNS4.5" = Latihan Soal CPNS
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"LSI Soft Modem" = LSI HDA Modem
"Luxor" = Luxor
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MiniLyrics" = Minilyrics(remove only)
"mIRC" = mIRC
"Mobile Partner" = Mobile Partner
"Money Manager Ex_is1" = Money Manager Ex 0.9.5.1
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"MPE" = MyPhoneExplorer
"Nero8Lite_is1" = Nero 8 Micro 8.3.6.0
"NVIDIA Drivers" = NVIDIA Drivers
"Opera 11.52.1100" = Opera 11.52
"Orbit_is1" = Orbit Downloader
"PhotoScape" = PhotoScape
"Picasa 3" = Picasa 3
"Picture Style Editor" = Canon Utilities Picture Style Editor
"Pidgin" = Pidgin
"Pidgin-Musictracker" = Pidgin-Musictracker plugin (remove only)
"Plants Vs Zombies" = Plants Vs Zombies
"PunkBusterSvc" = PunkBuster Services
"RealAlt_is1" = Real Alternative 2.0.2 Lite
"Recover My Files_is1" = Recover My Files
"Recovery Toolbox for RAR_is1" = Recovery Toolbox for RAR 1.1
"ST6UNST #1" = Simple Chat
"The Poppit Show 1.3.41o" = The Poppit Show 1.3.41o
"WebcamMax" = WebcamMax
"Winamp" = Winamp
"WinCDEmu" = WinCDEmu
"WinRAR archiver" = WinRAR archiver
"Wisdom-soft Set up ASR 3.1 Pro" = Wisdom-soft Set up ASR 3.1 Pro
"xVideos Video Downloader_is1" = xVideos Video Downloader 3.22
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"FolderLock6" = Folder Lock
"Google Chrome" = Google Chrome
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 27/12/2011 20:43:20 | Computer Name = Seven-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 27/12/2011 20:43:20 | Computer Name = Seven-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 27/12/2011 20:43:20 | Computer Name = Seven-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 27/12/2011 20:43:20 | Computer Name = Seven-PC | Source = Windows Search Service | ID = 7010
Description =
Error - 27/12/2011 20:43:30 | Computer Name = Seven-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 27/12/2011 20:43:30 | Computer Name = Seven-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 27/12/2011 20:43:31 | Computer Name = Seven-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 27/12/2011 20:43:31 | Computer Name = Seven-PC | Source = Windows Search Service | ID = 7010
Description =
Error - 28/12/2011 05:31:09 | Computer Name = Seven-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.31.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 1c30 Start Time:
01ccc53ff1ee6eb4 Termination Time: 6 Application Path: C:\Users\Windows\Desktop\OTL.exe
Report
Id: 9aecc2f4-3136-11e1-b938-002622994ba7
Error - 28/12/2011 06:36:24 | Computer Name = Seven-PC | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Common Files\Symantec
Shared\ccApp.exe Event Info: Set Information Process Action Taken: Logged Actor
Process: C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (PID 772) Time:
Wednesday, December 28, 2011 6:36:23 PM
[ Hewlett-Packard Events ]
Error - 31/10/2010 18:57:27 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()
Error - 14/12/2010 02:40:57 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()
Error - 19/12/2010 14:59:50 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. Configurator
at Configurator.ConfiguratorClass.loadXML() at Configurator.ConfiguratorClass..ctor(Boolean
loadxml) at HPSFConfigReader.ConfigHelper..ctor() at HPAssistant.csSettings.loadApplicationResources(Boolean
isOnAppLoad)
Error - 22/12/2010 20:27:21 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()
Error - 19/03/2011 20:34:36 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US String was not recognized as a valid DateTime. mscorlib at System.DateTimeParse.Parse(String
s, DateTimeFormatInfo dtfi, DateTimeStyles styles) at HPAssistant.Pages.MaintainHistory.loadApplied(Boolean
bUseHistory) at HPAssistant.Pages.MaintainHistory.Page_Loaded(Object sender,
RoutedEventArgs e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastLoadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error - 19/03/2011 20:34:53 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US String was not recognized as a valid DateTime. mscorlib at System.DateTimeParse.Parse(String
s, DateTimeFormatInfo dtfi, DateTimeStyles styles) at HPAssistant.Pages.MaintainHistory.loadApplied(Boolean
bUseHistory) at HPAssistant.Pages.MaintainHistory.Page_Loaded(Object sender,
RoutedEventArgs e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastLoadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error - 20/04/2011 20:29:51 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()
Error - 07/09/2011 20:29:15 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()
Error - 15/09/2011 04:47:52 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()
Error - 10/11/2011 04:02:43 | Computer Name = Seven-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()
[ Media Center Events ]
Error - 24/02/2011 01:56:40 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 1:56:40 PM - Error connecting to the internet. 1:56:40 PM - Unable
to contact server..
Error - 24/02/2011 01:57:00 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 1:56:45 PM - Error connecting to the internet. 1:56:45 PM - Unable
to contact server..
Error - 26/03/2011 09:37:35 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 9:37:30 PM - Error connecting to the internet. 9:37:31 PM - Unable
to contact server..
Error - 10/09/2011 03:18:20 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 3:18:19 PM - Failed to retrieve NetTV (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)
Error - 25/09/2011 20:05:17 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 8:05:17 AM - Error connecting to the internet. 8:05:17 AM - Unable
to contact server..
Error - 26/09/2011 07:00:10 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 7:00:08 PM - Error connecting to the internet. 7:00:08 PM - Unable
to contact server..
Error - 02/10/2011 07:39:02 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 7:39:01 PM - Error connecting to the internet. 7:39:01 PM - Unable
to contact server..
Error - 18/10/2011 09:09:27 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 9:09:25 PM - Error connecting to the internet. 9:09:25 PM - Unable
to contact server..
Error - 23/10/2011 21:34:15 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 9:34:14 AM - Error connecting to the internet. 9:34:14 AM - Unable
to contact server..
Error - 03/11/2011 09:28:29 | Computer Name = Seven-PC | Source = MCUpdate | ID = 0
Description = 9:28:25 PM - Error connecting to the internet. 9:28:25 PM - Unable
to contact server..
[ OSession Events ]
Error - 14/01/2010 03:48:57 | Computer Name = Seven-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 856 seconds with 540 seconds of active time. This session ended with a crash.
Error - 02/08/2011 02:21:28 | Computer Name = Seven-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 22357
seconds with 11160 seconds of active time. This session ended with a crash.
Error - 18/10/2011 21:59:21 | Computer Name = Seven-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 28/12/2011 04:35:24 | Computer Name = Seven-PC | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060
Error - 28/12/2011 04:35:24 | Computer Name = Seven-PC | Source = Service Control Manager | ID = 7003
Description = The IKE and AuthIP IPsec Keying Modules service depends the following
service: BFE. This service might not be installed.
Error - 28/12/2011 04:35:25 | Computer Name = Seven-PC | Source = Service Control Manager | ID = 7003
Description = The IPsec Policy Agent service depends the following service: BFE.
This service might not be installed.
Error - 28/12/2011 04:37:10 | Computer Name = Seven-PC | Source = PNRPSvc | ID = 102
Description =
Error - 28/12/2011 04:37:10 | Computer Name = Seven-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535
Error - 28/12/2011 04:46:09 | Computer Name = Seven-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 28/12/2011 05:35:36 | Computer Name = Seven-PC | Source = Application Popup | ID = 875
Description = Driver COH_Mon.sys has been blocked from loading.
Error - 28/12/2011 05:35:36 | Computer Name = Seven-PC | Source = Service Control Manager | ID = 7000
Description = The COH_Mon service failed to start due to the following error: %%1275
Error - 28/12/2011 06:30:47 | Computer Name = Seven-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 28/12/2011 06:35:44 | Computer Name = Seven-PC | Source = Service Control Manager | ID = 7000
Description = The COH_Mon service failed to start due to the following error: %%1275
< End of report >