OTL logfile created on: 2/23/2014 10:44:02 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\David\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.87 Gb Total Physical Memory | 0.77 Gb Available Physical Memory | 40.96% Memory free
3.75 Gb Paging File | 1.73 Gb Available in Paging File | 46.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.65 Gb Total Space | 65.71 Gb Free Space | 67.29% Space Free | Partition Type: NTFS
Drive D: | 68.36 Gb Total Space | 46.81 Gb Free Space | 68.48% Space Free | Partition Type: NTFS
Drive E: | 66.86 Gb Total Space | 23.17 Gb Free Space | 34.66% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 572.63 Gb Free Space | 61.47% Space Free | Partition Type: NTFS
Computer Name: DAVID-PC | User Name: David | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/02/23 22:34:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\David\Downloads\OTL.exe
PRC - [2014/02/21 18:48:07 | 001,863,560 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe
PRC - [2014/02/21 15:28:38 | 003,767,096 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014/02/21 15:28:38 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014/02/15 11:50:29 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2014/02/07 22:17:20 | 005,122,080 | ---- | M] (Astrill) -- C:\Program Files\Astrill\astrill.exe
PRC - [2014/01/27 13:20:36 | 000,540,032 | ---- | M] (Alipay Inc. ) -- C:\Program Files\alipay\alieditplus\AlipaySecSvc.exe
PRC - [2014/01/16 15:55:18 | 000,258,936 | ---- | M] () -- C:\Users\David\AppData\Roaming\Wandoujia2\Applications\2.70.0.5498\wandoujia_helper.exe
PRC - [2014/01/15 14:38:36 | 005,625,624 | ---- | M] (SUPERAntiSpyware) -- C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2014/01/09 14:14:48 | 003,529,504 | ---- | M] (IObit) -- C:\Program Files\IObit\Smart Defrag 3\SmartDefrag.exe
PRC - [2014/01/02 23:09:48 | 001,616,336 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe
PRC - [2014/01/02 23:09:48 | 000,921,040 | ---- | M] () -- C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe
PRC - [2013/12/27 06:20:14 | 001,983,520 | ---- | M] (Astrill) -- C:\Program Files\Astrill\ASProxy.exe
PRC - [2013/12/24 11:04:46 | 001,051,520 | ---- | M] (Alipay Inc. ) -- C:\Program Files\alipay\SafeTransaction\Alipaybsm.exe
PRC - [2013/12/18 02:03:44 | 000,894,280 | ---- | M] (阿里巴巴(中国)有限公司) -- C:\Program Files\alipay\SafeTransaction\TaobaoProtect.exe
PRC - [2013/12/13 17:31:56 | 000,422,536 | ---- | M] () -- C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe
PRC - [2013/12/09 15:01:58 | 000,881,440 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
PRC - [2013/12/03 16:10:24 | 000,775,968 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe
PRC - [2013/11/11 17:19:48 | 000,341,824 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2013/10/15 12:27:38 | 003,921,880 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2013/09/20 10:57:26 | 001,042,272 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2013/09/13 10:38:30 | 000,171,416 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2013/08/02 08:52:57 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2013/07/25 11:19:26 | 005,624,784 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2013/03/12 15:38:54 | 001,425,952 | ---- | M] (SPAMfighter ApS) -- C:\Program Files\Fighters\Tray\FightersTray.exe
PRC - [2012/11/23 10:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/07/24 19:26:54 | 000,040,960 | ---- | M] () -- C:\Users\David\AppData\Local\Programs\TouchFreeze\TouchFreeze.exe
PRC - [2012/04/21 15:11:09 | 000,077,064 | ---- | M] () -- C:\Program Files\WordWeb\wweb32.exe
PRC - [2011/08/12 07:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2014/02/21 18:48:06 | 016,265,096 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_12_0_0_70.dll
MOD - [2014/02/21 15:28:40 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014/02/15 11:50:27 | 003,578,992 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2014/01/20 13:17:04 | 000,073,544 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/01/20 13:16:38 | 001,044,808 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2014/01/16 15:55:18 | 000,258,936 | ---- | M] () -- C:\Users\David\AppData\Roaming\Wandoujia2\Applications\2.70.0.5498\wandoujia_helper.exe
MOD - [2014/01/16 15:55:16 | 001,058,680 | ---- | M] () -- C:\Users\David\AppData\Roaming\Wandoujia2\Applications\2.70.0.5498\adb_dev.dll
MOD - [2014/01/16 15:55:14 | 000,161,656 | ---- | M] () -- C:\Users\David\AppData\Roaming\Wandoujia2\Applications\2.70.0.5498\wandoujia_shlext_dll.dll
MOD - [2014/01/16 15:54:44 | 034,665,336 | ---- | M] () -- C:\Users\David\AppData\Roaming\Wandoujia2\Applications\2.70.0.5498\core.dll
MOD - [2014/01/02 23:09:48 | 000,921,040 | ---- | M] () -- C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe
MOD - [2013/05/16 10:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2013/05/16 10:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2013/01/15 18:48:26 | 000,348,992 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 7\madexcept_.bpl
MOD - [2013/01/15 18:48:26 | 000,051,008 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 7\maddisAsm_.bpl
MOD - [2013/01/15 18:48:24 | 000,183,616 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 7\madbasic_.bpl
MOD - [2013/01/15 18:47:56 | 000,893,248 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 7\webres.dll
MOD - [2012/09/05 18:55:36 | 000,892,288 | ---- | M] () -- C:\Program Files\IObit\Smart Defrag 3\webres.dll
MOD - [2012/07/24 19:26:54 | 000,040,960 | ---- | M] () -- C:\Users\David\AppData\Local\Programs\TouchFreeze\TouchFreeze.exe
MOD - [2012/07/24 19:26:54 | 000,034,304 | ---- | M] () -- C:\Users\David\AppData\Local\Programs\TouchFreeze\TouchFreeze.dll
MOD - [2012/07/15 12:27:53 | 002,216,480 | ---- | M] () -- C:\Windows\wweb32.dll
MOD - [2012/07/15 12:25:03 | 000,581,480 | ---- | M] () -- C:\Program Files\WordWeb\wwextdb.dll
MOD - [2012/07/15 12:25:02 | 000,022,800 | ---- | M] () -- C:\Program Files\WordWeb\WUCNT.dll
MOD - [2012/04/21 15:11:09 | 000,077,064 | ---- | M] () -- C:\Program Files\WordWeb\wweb32.exe
========== Services (SafeList) ==========
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService)
SRV - [2014/02/21 18:48:07 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/21 15:28:38 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2014/02/15 11:50:28 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/02/14 21:48:15 | 002,151,744 | ---- | M] (IObit) [Auto | Stopped] -- C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe -- (LiveUpdateSvc)
SRV - [2014/01/27 13:20:36 | 000,540,032 | ---- | M] (Alipay Inc. ) [Auto | Running] -- C:\Program Files\alipay\alieditplus\AlipaySecSvc.exe -- (AlipaySecSvc)
SRV - [2014/01/19 20:15:44 | 000,434,024 | ---- | M] (Astrill) [On_Demand | Stopped] -- C:\Program Files\Astrill\ASOvpnSvc.exe -- (ASOVPNHelper)
SRV - [2013/12/27 06:20:14 | 001,983,520 | ---- | M] (Astrill) [On_Demand | Running] -- C:\Program Files\Astrill\ASProxy.exe -- (ASProxy)
SRV - [2013/12/13 17:31:56 | 000,422,536 | ---- | M] () [Auto | Running] -- C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe -- (ICBC Daemon Service)
SRV - [2013/12/09 15:01:58 | 000,881,440 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe -- (AdvancedSystemCareService7)
SRV - [2013/11/11 17:19:48 | 000,341,824 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/05/27 12:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/08/12 07:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore.exe -- (!SASCORE)
SRV - [2009/07/14 09:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - [2014/02/21 15:28:44 | 000,775,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2014/02/21 15:28:44 | 000,410,784 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2014/02/21 15:28:44 | 000,180,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2014/02/21 15:28:44 | 000,079,720 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2014/02/21 15:28:44 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2014/02/21 15:28:44 | 000,064,168 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\aswStm.sys -- (aswStm)
DRV - [2014/02/21 15:28:44 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013/12/24 10:40:32 | 000,018,624 | ---- | M] (IObit) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2013/11/19 16:10:38 | 000,032,288 | ---- | M] (IObit.com) [Kernel | On_Demand | Running] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\RegFilter.sys -- (RegFilter)
DRV - [2013/11/19 16:10:38 | 000,020,944 | ---- | M] (IObit.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\UrlFilter.sys -- (UrlFilter)
DRV - [2013/03/23 15:49:20 | 000,021,480 | ---- | M] (IObit) [File_System | Disabled | Stopped] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys -- (FileMonitor)
DRV - [2012/02/29 21:46:08 | 000,025,856 | ---- | M] (Astrill) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\asvpndrv.sys -- (asvpndrv)
DRV - [2011/07/23 00:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011/07/13 05:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/07/01 10:46:40 | 000,026,624 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2010/11/20 20:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 18:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 18:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 17:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2010/11/20 17:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/08/03 16:25:28 | 000,026,112 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tapoas.sys -- (tapoas)
DRV - [2009/07/14 06:02:52 | 000,043,008 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2008/12/01 22:14:34 | 004,179,968 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2006/11/14 17:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...?client=aff-ime
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B8 35 25 F3 C5 07 CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\..\SearchScopes\{095EEDD2-9A61-4BA6-9891-94E310EA237C}: "URL" = http://startpage.com...uage=english_uk
IE - HKCU\..\SearchScopes\{0CA308D4-5FE7-4E88-837B-02527DC767D2}: "URL" = http://www.baidu.com...d={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Startpage HTTPS"
FF - prefs.js..browser.search.selectedEngine: "Startpage HTTPS"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.startpage.com"
FF - prefs.js..extensions.enabledAddons: wcapturex%40deskperience.com:5.0.4406
FF - prefs.js..extensions.enabledAddons: %7Bbbfec13e-8cb4-53f4-c852-999eb2a852cb%7D:0.2.3
FF - prefs.js..extensions.enabledAddons: addon%40astrill.com:1.6.2
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:9.0.2013.75
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF - HKLM\Software\MozillaPlugins\@alipay.com/npalidcp: C:\Windows\system32\aliedit\3.7.0.0\npalidcp.dll (Alipay.com co.,ltd)
FF - HKLM\Software\MozillaPlugins\@alipay.com/npaliedit: C:\Windows\system32\aliedit\3.7.0.0\npaliedit.dll (Alipay.com co.,ltd)
FF - HKLM\Software\MozillaPlugins\@alipay.com/npAliSecCtrl: C:\Windows\system32\aliedit\3.7.0.0\npAliSecCtrl.dll (Alipay.com Inc. )
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@icbc.com/npChromeClientBinding,ver=1.0.0.0: C:\Program Files\ICBCEbankTools\ICBCChromeExtension\npChromeClientBinding.dll (ICBC)
FF - HKLM\Software\MozillaPlugins\@icbc.com/npChromeFullScreen,ver=1.0.0.1: C:\Program Files\ICBCEbankTools\ICBCChromeExtension\npChromeFullScreen.dll (ICBC)
FF - HKLM\Software\MozillaPlugins\@icbc.com/npChromeSubmit,ver=1.0.0.1: C:\Program Files\ICBCEbankTools\ICBCChromeExtension\npChromeSubmit.dll (ICBC)
FF - HKLM\Software\MozillaPlugins\@icbc.com/npChromeXXin,ver=1.0.0.1: C:\Program Files\ICBCEbankTools\ICBCChromeExtension\npChromeXXin.dll ( )
FF - HKLM\Software\MozillaPlugins\@icbc/icbc_ms_npClCache,Version=1.0.0.2: C:\Program Files\ICBCEbankTools\FirefoxPlugins\npClCache.dll ()
FF - HKLM\Software\MozillaPlugins\@icbc/icbc_ms_npClientBinding,Version=1.0.0.2: C:\Program Files\ICBCEbankTools\FirefoxPlugins\npClientBinding.dll ( )
FF - HKLM\Software\MozillaPlugins\@icbc/icbc_ms_npFullScreen,Version=1.0.0.2: C:\Program Files\ICBCEbankTools\FirefoxPlugins\npFullScreen.dll ()
FF - HKLM\Software\MozillaPlugins\@icbc/icbc_ms_npsubmit,Version=1.0.0.7: C:\Program Files\ICBCEbankTools\FirefoxPlugins\npsubmit.dll ( )
FF - HKLM\Software\MozillaPlugins\@icbc/icbc_ms_npxxin,Version=1.0.0.8: C:\Program Files\ICBCEbankTools\FirefoxPlugins\npxxin.dll ( )
FF - HKLM\Software\MozillaPlugins\@icbc/npAssistComm,Version=1.0.0.1: C:\Program Files\ICBCEbankTools\ICBCSetupIntegration\npAssistComm.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@wandoujia.com: C:\Program Files\WandouLabs\npWandoujiaHelper.dll (wandoujia.com)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014/02/21 15:28:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\WordWeb\WCaptureMoz [2014/01/03 18:21:00 | 000,000,000 | ---D | M]
[2014/01/31 15:05:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\David\AppData\Roaming\Mozilla\Extensions
[2014/01/03 16:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\David\AppData\Roaming\Mozilla\Extensions\net.openvpn.client
[2014/01/31 15:05:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\David\AppData\Roaming\Mozilla\Extensions\[email protected]
[2014/02/22 17:56:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\j9jtgznc.default\extensions
[2014/02/14 13:39:40 | 000,000,000 | ---D | M] ("Astrill Proxy Switcher") -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\j9jtgznc.default\extensions\[email protected]
[2014/01/23 16:29:07 | 000,000,000 | ---D | M] (Ads Removal) -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\j9jtgznc.default\extensions\[email protected]
[2014/01/11 12:27:08 | 000,000,000 | ---D | M] (Popup Chinese Dictionary) -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\j9jtgznc.default\extensions\[email protected]
[2014/02/10 11:01:53 | 000,000,000 | ---D | M] (ICBCClrCache) -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\j9jtgznc.default\extensions\[email protected]
[2014/02/22 17:56:09 | 000,120,925 | ---- | M] () (No name found) -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\j9jtgznc.default\extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi
[2014/01/03 20:55:08 | 002,317,406 | ---- | M] () (No name found) -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\j9jtgznc.default\extensions\{bbfec13e-8cb4-53f4-c852-999eb2a852cb}.xpi
[2014/01/03 16:26:49 | 000,003,936 | ---- | M] () -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\j9jtgznc.default\searchplugins\baidu.xml
[2014/02/23 14:15:58 | 000,005,705 | ---- | M] () -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\j9jtgznc.default\searchplugins\startpage-https.xml
[2014/02/15 11:50:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/02/15 11:50:30 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/02/21 15:28:50 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2014/01/03 18:21:00 | 000,000,000 | ---D | M] (WordWeb one-click lookup) -- C:\PROGRAM FILES\WORDWEB\WCAPTUREMOZ
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.google.com/
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\anepbdekljkmmimmhbniglnnanmmkoja\0.1.13_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkmlkkjojmombglmlpbpapmhcaljjkde\3.7_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkmlkkjojmombglmlpbpapmhcaljjkde\3.8_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\lehjanbmddecbhgnnncapflmglinppcj\1.4_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009/06/11 05:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Íã¶¹¼Ô apk °²×°Æ÷) - {000DA090-57AA-424B-A8F0-621B7C08B8F4} - C:\Program Files\WandouLabs\wandoujia_bho.dll (Wandoulabs)
O2 - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (ICBC Anti-Phishing class) - {BB4491A2-D11A-4c6b-91C0-B53246A3122B} - C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\Icbc_AntiPhishing.dll (中国工商银行)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CommonToolkitTray] C:\Program Files\Fighters\Tray\FightersTray.exe (SPAMfighter ApS)
O4 - HKLM..\Run: [ICBCEBankAssist] C:\Program Files\ICBCEbankTools\ICBCSetupIntegration\RunEBank.exe ()
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware)
O4 - HKCU..\Run: [TouchFreeze] C:\Users\David\AppData\Local\Programs\TouchFreeze\TouchFreeze.exe ()
O4 - HKCU..\Run: [uTorrent] C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - Startup: C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wandoujia_helper.lnk = C:\Users\David\AppData\Roaming\Wandoujia2\Applications\2.70.0.5498\wandoujia_helper.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\ASProxy.dll (Astrill)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\ASProxy.dll (Astrill)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\ASProxy.dll (Astrill)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\ASProxy.dll (Astrill)
O10 - Protocol_Catalog9\Catalog_Entries\000000000041 - C:\Windows\System32\ASProxy.dll (Astrill)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: alipay.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: alipay.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: alisoft.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: alisoft.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: taobao.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: taobao.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: alipay.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: alipay.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: alisoft.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: alisoft.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: cfca.com.cn ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: cfca.com.cn ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: icbc.com.cn ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: taobao.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: taobao.com ([]https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E0B22CA-3CDF-4399-8F09-35325D02A04F}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B69EE329-2CA7-4807-B85B-14C2398B23F2}: NameServer = 221.7.128.68 221.7.136.68
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2012/07/17 06:33:00 | 000,000,032 | ---- | M] () - G:\Autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/02/23 16:54:49 | 000,000,000 | ---D | C] -- C:\Users\David\Desktop\GXMU
[2014/02/23 10:07:31 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Roaming\TaobaoProtect
[2014/02/23 10:07:28 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Local\alipay
[2014/02/21 17:50:25 | 000,000,000 | ---D | C] -- C:\OETemp
[2014/02/21 15:32:28 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Roaming\AVAST Software
[2014/02/21 15:30:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
[2014/02/21 15:29:02 | 000,064,168 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswStm.sys
[2014/02/21 15:29:01 | 000,775,952 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2014/02/21 15:29:00 | 000,410,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2014/02/21 15:28:59 | 000,067,824 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2014/02/21 15:28:58 | 000,079,720 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2014/02/21 15:28:52 | 000,270,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014/02/21 15:28:42 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014/02/21 15:27:40 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014/02/21 15:26:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014/02/21 13:15:44 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Roaming\Fighters
[2014/02/21 13:15:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fighters
[2014/02/21 13:15:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Fighters
[2014/02/21 13:15:09 | 000,000,000 | ---D | C] -- C:\Program Files\Fighters
[2014/02/21 13:13:41 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Roaming\DesktopIconGoodgame
[2014/02/20 09:51:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014/02/20 09:51:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2014/02/20 09:51:47 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2014/02/15 11:50:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014/02/15 06:00:22 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2014/02/14 21:48:47 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Roaming\ProductData
[2014/02/14 21:48:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
[2014/02/14 13:32:25 | 000,353,824 | ---- | C] (Astrill) -- C:\Windows\System32\ASProxy.dll
[2014/02/14 13:32:20 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Roaming\Astrill
[2014/02/14 13:30:17 | 000,025,856 | ---- | C] (Astrill) -- C:\Windows\System32\drivers\asvpndrv.sys
[2014/02/14 13:30:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Astrill
[2014/02/14 13:30:16 | 000,000,000 | ---D | C] -- C:\Program Files\Astrill
[2014/02/14 05:42:00 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014/02/14 05:41:58 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014/02/14 05:41:58 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014/02/14 05:41:57 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014/02/14 05:41:57 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014/02/14 05:41:56 | 001,806,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014/02/14 05:41:56 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014/02/14 05:41:54 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014/02/13 20:46:23 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3r.dll
[2014/02/13 20:32:39 | 003,419,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2014/02/13 20:32:39 | 001,987,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2014/02/13 20:32:24 | 000,594,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2014/02/13 20:32:24 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2014/02/13 20:32:24 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2014/02/13 20:32:24 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2014/02/13 20:32:24 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2014/02/13 20:32:24 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2014/02/13 20:32:24 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
[2014/02/13 20:32:24 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2014/02/13 20:32:23 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2014/02/11 12:30:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2014/02/11 12:30:23 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2014/02/11 10:36:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JetBoost
[2014/02/11 10:36:26 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueSprig
[2014/02/10 11:01:48 | 000,188,040 | ---- | C] (Industrial and Commercial Bank of China) -- C:\Windows\System32\IE_FULL_SCREEN.dll
[2014/02/10 11:01:46 | 000,000,000 | -HSD | C] -- C:\Windows\System32\AI_RecycleBin
[2014/02/10 11:00:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Industrial and Commercial Bank of China Internet Banking Client Software
[2014/02/10 11:00:11 | 000,000,000 | ---D | C] -- C:\Program Files\ICBCEbankTools
[2014/02/10 11:00:11 | 000,000,000 | ---D | C] -- C:\ProgramData\icbc_data
[2014/02/09 21:25:19 | 000,000,000 | ---D | C] -- C:\Users\David\Documents\vita_dark-2
[2014/02/08 19:53:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2014/02/08 19:52:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2014/02/04 19:23:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2014/02/04 19:22:47 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2014/02/04 19:22:46 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2014/02/04 19:22:46 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2014/02/03 20:02:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2014/01/31 15:05:52 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Roaming\Flickr
[2014/01/31 15:05:52 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Local\Flickr
[2014/01/30 16:32:50 | 000,000,000 | ---D | C] -- C:\Program Files\Flickr Uploadr
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\David\*.tmp files -> C:\Users\David\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/02/23 20:42:58 | 000,666,176 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/02/23 20:42:58 | 000,387,790 | ---- | M] () -- C:\Windows\System32\prfh0804.dat
[2014/02/23 20:42:58 | 000,125,820 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/02/23 20:42:58 | 000,123,268 | ---- | M] () -- C:\Windows\System32\prfc0804.dat
[2014/02/23 14:54:31 | 000,004,092 | ---- | M] () -- C:\Windows\System32\ASProxy.ini
[2014/02/23 14:54:31 | 000,002,456 | ---- | M] () -- C:\Windows\System32\ASProxyOff.ini
[2014/02/23 10:13:53 | 000,014,336 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/02/23 10:13:53 | 000,014,336 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/02/23 10:07:20 | 000,001,078 | ---- | M] () -- C:\Users\David\AppData\Roaming\base64.cer
[2014/02/23 10:05:01 | 000,000,272 | ---- | M] () -- C:\Windows\tasks\Driver Booster Update.job
[2014/02/23 10:04:50 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\SLOW-PCfighter-David-Notification.job
[2014/02/23 10:04:50 | 000,000,378 | ---- | M] () -- C:\Windows\tasks\SLOW-PCfighter-David-Startup.job
[2014/02/23 10:03:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/02/23 10:03:18 | 1508,376,576 | -HS- | M] () -- C:\hiberfil.sys
[2014/02/22 17:43:01 | 000,000,945 | ---- | M] () -- C:\Users\Public\Desktop\Astrill.lnk
[2014/02/22 08:29:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/02/21 18:48:07 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014/02/21 18:48:07 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014/02/21 16:34:11 | 000,002,129 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/02/21 15:30:44 | 000,002,115 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2014/02/21 15:28:44 | 000,775,952 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2014/02/21 15:28:44 | 000,410,784 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2014/02/21 15:28:44 | 000,180,248 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014/02/21 15:28:44 | 000,079,720 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2014/02/21 15:28:44 | 000,067,824 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2014/02/21 15:28:44 | 000,064,168 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswStm.sys
[2014/02/21 15:28:44 | 000,049,944 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014/02/21 15:28:42 | 000,270,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014/02/21 15:28:42 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014/02/21 13:13:42 | 000,001,466 | ---- | M] () -- C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Goodgame Empire.lnk
[2014/02/20 14:29:06 | 000,000,979 | ---- | M] () -- C:\Users\David\Desktop\CCleaner.lnk
[2014/02/20 10:51:21 | 000,002,147 | ---- | M] () -- C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
[2014/02/20 09:51:48 | 000,002,685 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2014/02/16 10:10:24 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/02/16 10:10:24 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/02/14 21:48:22 | 000,001,182 | ---- | M] () -- C:\Users\Public\Desktop\IObit Uninstaller.lnk
[2014/02/14 17:46:08 | 000,020,774 | ---- | M] () -- C:\Users\David\Documents\cc_20140214_174556.reg
[2014/02/11 15:37:55 | 000,453,464 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/02/11 12:30:44 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2014/02/11 10:36:27 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Quick Boost.lnk
[2014/02/11 10:36:27 | 000,001,099 | ---- | M] () -- C:\Users\Public\Desktop\JetBoost.lnk
[2014/02/10 11:00:13 | 000,001,187 | ---- | M] () -- C:\Users\Public\Desktop\ICBCEBankAssist.lnk
[2014/02/10 10:10:27 | 000,001,403 | ---- | M] () -- C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/02/09 15:59:13 | 000,001,020 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2014/02/06 09:42:21 | 000,655,261 | ---- | M] () -- C:\Users\David\Documents\Silentwaragainsthumanity.pdf
[2014/02/05 16:56:17 | 001,806,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014/02/05 16:49:56 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014/02/05 16:49:14 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014/02/05 16:48:56 | 000,065,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014/02/05 16:48:40 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014/02/05 16:47:57 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014/02/05 16:47:16 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014/02/05 16:46:50 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014/02/04 19:23:51 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014/01/31 15:04:57 | 000,001,923 | ---- | M] () -- C:\Users\David\Desktop\Flickr Uploadr.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\David\*.tmp files -> C:\Users\David\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/02/21 15:30:44 | 000,002,115 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2014/02/21 15:29:02 | 000,180,248 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014/02/21 15:29:00 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014/02/21 13:15:56 | 000,000,378 | ---- | C] () -- C:\Windows\tasks\SLOW-PCfighter-David-Startup.job
[2014/02/21 13:15:44 | 000,000,384 | ---- | C] () -- C:\Windows\tasks\SLOW-PCfighter-David-Notification.job
[2014/02/21 13:13:42 | 000,001,466 | ---- | C] () -- C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Goodgame Empire.lnk
[2014/02/14 17:46:06 | 000,020,774 | ---- | C] () -- C:\Users\David\Documents\cc_20140214_174556.reg
[2014/02/14 13:43:04 | 000,004,092 | ---- | C] () -- C:\Windows\System32\ASProxy.ini
[2014/02/14 13:43:04 | 000,002,456 | ---- | C] () -- C:\Windows\System32\ASProxyOff.ini
[2014/02/14 13:30:17 | 000,000,945 | ---- | C] () -- C:\Users\Public\Desktop\Astrill.lnk
[2014/02/11 16:51:07 | 000,003,952 | ---- | C] () -- C:\Users\David\Desktop\Razor Face.mp3
[2014/02/11 12:30:44 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2014/02/11 10:36:27 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Quick Boost.lnk
[2014/02/11 10:36:27 | 000,001,099 | ---- | C] () -- C:\Users\Public\Desktop\JetBoost.lnk
[2014/02/10 11:01:51 | 000,114,312 | ---- | C] () -- C:\Windows\System32\EditControl.dll
[2014/02/10 11:01:51 | 000,073,352 | ---- | C] () -- C:\Windows\System32\UploadControl.dll
[2014/02/10 11:01:49 | 000,308,360 | ---- | C] () -- C:\Windows\System32\InputControl.dll
[2014/02/10 11:01:49 | 000,277,128 | ---- | C] () -- C:\Windows\System32\SubmitControl.dll
[2014/02/10 11:01:48 | 000,174,728 | ---- | C] () -- C:\Windows\System32\icbcclean.dll
[2014/02/10 11:00:13 | 000,001,187 | ---- | C] () -- C:\Users\Public\Desktop\ICBCEBankAssist.lnk
[2014/02/10 10:10:27 | 000,001,409 | ---- | C] () -- C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014/02/10 10:10:27 | 000,001,403 | ---- | C] () -- C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/02/06 09:42:21 | 000,655,261 | ---- | C] () -- C:\Users\David\Documents\Silentwaragainsthumanity.pdf
[2014/02/04 19:23:51 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014/01/30 16:36:55 | 000,001,923 | ---- | C] () -- C:\Users\David\Desktop\Flickr Uploadr.lnk
[2014/01/30 16:36:54 | 000,001,935 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flickr Uploadr.lnk
[2014/01/10 10:43:23 | 000,387,790 | ---- | C] () -- C:\Windows\System32\prfh0804.dat
[2014/01/10 10:43:23 | 000,123,268 | ---- | C] () -- C:\Windows\System32\prfc0804.dat
[2014/01/10 10:43:23 | 000,111,310 | ---- | C] () -- C:\Windows\System32\prfi0804.dat
[2014/01/10 10:43:23 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0804.dat
[2014/01/05 12:37:51 | 000,054,704 | ---- | C] () -- C:\Windows\System32\USBCoInstaller.dll
[2014/01/04 18:45:22 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2014/01/04 18:43:15 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2014/01/04 09:32:52 | 000,001,078 | ---- | C] () -- C:\Users\David\AppData\Roaming\base64.cer
[2014/01/03 21:09:21 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014/01/03 18:21:01 | 002,216,480 | ---- | C] () -- C:\Windows\wweb32.dll
[2013/11/05 17:04:18 | 000,189,232 | ---- | C] () -- C:\Windows\System32\HB_BOCToken.x86.dll
[2013/11/05 17:04:12 | 000,074,544 | ---- | C] () -- C:\Windows\System32\WD_BOCToken.x86.dll
[2013/11/05 17:03:52 | 000,052,528 | ---- | C] () -- C:\Windows\System32\ES_BOCToken.x86.dll
========== ZeroAccess Check ==========
[2009/07/14 12:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 09:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 20:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 09:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Files - Unicode (All) ==========
[2014/02/23 22:16:39 | 000,002,328 | ---- | M] ()(C:\Users\David\Desktop\?? T8830Pro - ???.lnk) -- C:\Users\David\Desktop\华为 T8830Pro - 豌豆荚.lnk
[2014/01/05 12:42:46 | 000,002,328 | ---- | C] ()(C:\Users\David\Desktop\?? T8830Pro - ???.lnk) -- C:\Users\David\Desktop\华为 T8830Pro - 豌豆荚.lnk
[2014/01/05 12:42:46 | 000,000,877 | ---- | M] ()(C:\Users\David\Desktop\?? T8830Pro???.lnk) -- C:\Users\David\Desktop\华为 T8830Pro的备份.lnk
[2014/01/05 12:42:46 | 000,000,877 | ---- | C] ()(C:\Users\David\Desktop\?? T8830Pro???.lnk) -- C:\Users\David\Desktop\华为 T8830Pro的备份.lnk
(C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\???) -- C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\豌豆荚
< End of report >