Hi,
My computer starts very slowly and it takes a long time to load the main desktop screen. After that, when I click on the applications or files, it takes about 5 mins to open. For example, when I open some websites in Internet Explorer, after the webpages have loaded and when I click to see the pages, the system 'hangs' and shows no response. I have to wait for about 5 mins before I can see the webpages. Then after a while, the same thing happens and I cannot see anything on Internet Explorer so I have to wait again before everything is ok. I'm not sure whether there's malware or simply something wrong with my system.
Here's the OTL log:
vOTL logfile created on: 4/16/2014 8:33:11 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.97 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 42.96% Memory free
4.81 Gb Paging File | 3.16 Gb Available in Paging File | 65.66% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.87 Gb Total Space | 8.69 Gb Free Space | 3.73% Space Free | Partition Type: NTFS
Drive E: | 232.88 Gb Total Space | 2.84 Gb Free Space | 1.22% Space Free | Partition Type: NTFS
Drive F: | 58.59 Gb Total Space | 0.48 Gb Free Space | 0.81% Space Free | Partition Type: NTFS
Drive G: | 174.29 Gb Total Space | 1.53 Gb Free Space | 0.88% Space Free | Partition Type: NTFS
Drive H: | 189.92 Gb Total Space | 0.44 Gb Free Space | 0.23% Space Free | Partition Type: NTFS
Computer Name: USER-8CE73256DD | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/04/16 20:33:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
PRC - [2014/03/30 20:30:08 | 002,484,504 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2014/03/30 20:30:08 | 001,444,120 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2014/03/11 10:13:24 | 000,022,216 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2014/03/11 10:13:14 | 000,951,576 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2014/02/20 02:05:02 | 001,534,736 | ---- | M] (Youku.com) -- C:\Program Files\YouKu\youkuclient\YoukuDesktop.exe
PRC - [2014/02/20 02:04:52 | 005,723,928 | ---- | M] (Youku.com) -- C:\Program Files\YouKu\youkuclient\YoukuMediaCenter.exe
PRC - [2013/12/18 21:05:43 | 000,182,696 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2013/12/11 17:52:14 | 001,236,096 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- H:\Program Files\QvodPlayer\QvodTerminal.exe
PRC - [2013/11/26 19:34:27 | 000,458,832 | ---- | M] (BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.) -- C:\Program Files\iQIYI\QiyiService.exe
PRC - [2013/10/31 11:35:46 | 000,070,880 | ---- | M] () -- C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
PRC - [2013/10/31 11:35:30 | 000,449,760 | ---- | M] (Sony) -- C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
PRC - [2013/10/10 12:50:08 | 004,993,024 | ---- | M] (FS2YOU) -- C:\Program Files\GridService\peer.exe
PRC - [2013/04/04 14:50:32 | 000,887,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2010/05/05 04:07:22 | 000,503,080 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Update\NASvc.exe
PRC - [2008/04/14 11:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2014/02/14 10:25:58 | 000,571,392 | ---- | M] () -- C:\Program Files\Sony\Sony PC Companion\PhoneUpdate.dll
MOD - [2014/02/05 16:55:04 | 000,562,688 | ---- | M] () -- C:\WINDOWS\system32\qedit.dll
MOD - [2014/02/03 15:51:10 | 001,125,592 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportMS.dll
MOD - [2013/12/18 14:55:54 | 003,069,568 | ---- | M] () -- H:\Program Files\QvodPlayer\image_hash.dll
MOD - [2013/12/18 14:55:48 | 000,243,752 | ---- | M] () -- H:\Program Files\QvodPlayer\QvodImageInfo.dll
MOD - [2013/10/31 11:35:46 | 000,070,880 | ---- | M] () -- C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
MOD - [2013/09/13 10:02:30 | 000,208,896 | ---- | M] () -- C:\Program Files\Sony\Sony PC Companion\MExplorer.dll
MOD - [2013/05/20 11:58:08 | 000,620,718 | ---- | M] () -- C:\Program Files\Sony\Sony PC Companion\sqlite3.dll
MOD - [2013/01/02 14:49:10 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2012/06/27 15:09:06 | 000,557,056 | ---- | M] () -- C:\Program Files\Trusteer\Rapport\bin\js32.dll
MOD - [2012/04/30 10:57:42 | 000,039,936 | ---- | M] () -- C:\Program Files\Sony\Sony PC Companion\TMonitorAPI.dll
MOD - [2011/07/07 14:54:36 | 000,233,984 | ---- | M] () -- C:\Program Files\Sony\Sony PC Companion\Report.dll
MOD - [2010/01/11 15:44:54 | 000,053,248 | ---- | M] () -- C:\Program Files\Sony\Sony PC Companion\VObject.dll
MOD - [2008/04/14 11:42:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 11:41:52 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
========== Services (SafeList) ==========
SRV - [2014/03/30 20:30:08 | 001,444,120 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2014/03/13 04:22:24 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/03/11 10:13:24 | 000,022,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2013/12/18 21:05:43 | 000,182,696 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013/11/26 19:34:27 | 000,458,832 | ---- | M] (BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.) [Auto | Running] -- C:\Program Files\iQIYI\QiyiService.exe -- (QiyiService)
SRV - [2013/07/18 09:23:32 | 000,215,088 | ---- | M] (新浪网技术(中国)有限公司) [Auto | Running] -- C:\Program Files\sina\Sina_live\2010\live_deamon.dll -- (sina_live_deamon)
SRV - [2013/02/04 17:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2011/03/16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/05/05 04:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbfake.sys -- (hwusbfake)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2014/04/16 19:47:22 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2014/04/16 19:41:11 | 000,039,464 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C03DDEA6-C3B2-4753-A5AB-4606CFE974FC}\MpKslfbcc7bc6.sys -- (MpKslfbcc7bc6)
DRV - [2014/03/30 20:30:22 | 000,228,888 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2014/03/30 20:30:22 | 000,156,024 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys -- (RapportEI)
DRV - [2014/03/30 20:30:22 | 000,107,256 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2013/12/13 05:51:06 | 000,340,432 | ---- | M] () [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_59849.sys -- (RapportCerberus_59849)
DRV - [2012/12/30 04:59:38 | 000,024,184 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2012/07/21 19:42:37 | 000,025,200 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2012/07/21 19:42:37 | 000,012,400 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggflt.sys -- (ggflt)
DRV - [2010/11/09 14:35:30 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\cpuz135_x32.sys -- (cpuz135)
DRV - [2010/10/05 18:11:24 | 006,164,584 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2010/09/09 15:13:02 | 000,234,728 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2010/07/29 00:25:42 | 000,025,112 | ---- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ivusb.sys -- (ivusb)
DRV - [2010/05/17 17:11:22 | 000,006,272 | ---- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BS_I2cIo.sys -- (BS_I2cIo)
DRV - [2009/11/18 07:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/11/18 07:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009/04/08 03:32:48 | 000,116,224 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV - [2008/04/14 08:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2005/03/16 14:23:54 | 000,013,696 | R--- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BIOS.sys -- (BIOS)
DRV - [2001/08/23 20:00:00 | 000,012,160 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\fsvga.sys -- (FsVga)
DRV - [1996/04/04 03:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{F7AF02FD-F5FE-4175-AE15-A0E004D02D4E}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.soccernet.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope = {F7AF02FD-F5FE-4175-AE15-A0E004D02D4E}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2}: "URL" = http://www.baidu.com...99_oem_dg&ch=33
IE - HKCU\..\SearchScopes\{F7AF02FD-F5FE-4175-AE15-A0E004D02D4E}: "URL" = http://www.google.co...1I7NDKB_enSG548
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@baidu.com/npxbdsetup: C:\WINDOWS\Downloaded Program Files\443437\npxbdsetup.dll ()
FF - HKLM\Software\MozillaPlugins\@baidu.com/npxbdyy: C:\Program Files\Baidu\BaiduPlayer\1.19.0.137\npxbdyy.dll ()
FF - HKLM\Software\MozillaPlugins\@iqiyi.com/npclient: C:\Program Files\iQIYI\npclient.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pptv.com/plugin: C:\Program Files\Internet Explorer\PPLite\plugin\3.4.0.0111\npplugin2.dll (PPLive Corporation)
FF - HKLM\Software\MozillaPlugins\@qq.com/QQlive: C:\Program Files\Tencent\QQLive\LiveOcx\npQQLive.dll File not found
FF - HKLM\Software\MozillaPlugins\@qvod.com/QvodInsert: H:\Program Files\QvodPlayer\npQvodInsert.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKLM\Software\MozillaPlugins\@qvod.com/QvodShare: H:\Program Files\QvodPlayer\npShareModule.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@sohu.com/npifox: H:\Program Files\搜狐影音\npifox.dll ()
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@qvod.com/QvodInsert: H:\Program Files\QvodPlayer\npQvodInsert.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\KuaiWanInsert: H:\Program Files\QvodPlayer\AddIn\KWWebgame\npKWWebGame.dll (Shenzhen QVOD Technology Co.,Ltd)
========== Chrome ==========
CHR - default_search_provider: Web (Enabled)
CHR - default_search_provider: search_url = http://feed.snapdo.c...Date=11/11/2013
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\34.0.1847.116\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft庐 DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft庐 DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: PPLive PPTV Plugin (Enabled) = C:\Program Files\Internet Explorer\PPLite\plugin\1.0.1.3117\npplugin2.dll
CHR - plugin: Java Platform SE 7 U25 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Media Go Detector (Enabled) = C:\Program Files\Sony\Media Go\npmediago.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.16 (Enabled) = C:\WINDOWS\system32\npDeployJava1.dll
CHR - plugin: 56iCan Browser Plugin (Enabled) = H:\Program Files\56ican\np56icanplugin.dll
CHR - plugin: BaiduPlayer Browser Plugin (Enabled) = H:\Program Files\Baidu\BaiduPlayer\1.17.0.172\npxbdyy.dll
CHR - plugin: npifox Dynamic Link Library (Enabled) = H:\Program Files\鎼滅嫄褰遍煶\npifox.dll
CHR - Extension: Google Docs = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Wallet = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2013/11/16 08:48:39 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (QvodExtend) - {A8502600-B272-4F68-A67B-A0305D46D297} - H:\Program Files\QvodPlayer\QvodExtend\5.0.97.0\QvodExtend.dll (Shenzhen QVOD Technology Co.,Ltd)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll File not found
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Grid Service] C:\Program Files\GridService\peer.exe (FS2YOU)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QvodTerminal] H:\Program Files\QvodPlayer\QvodTerminal.exe (Shenzhen QVOD Technology Co.,Ltd)
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Google Update] Reg Error: Value error. File not found
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background File not found
O4 - HKCU..\Run: [Sony PC Companion] C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &使用FLVCD获取本页视频的下载地址 - C:\Documents and Settings\User\Application Data\flvcd\flvcd_link.htm ()
O8 - Extra context menu item: &使用FLVCD获取该视频的下载地址 - C:\Documents and Settings\User\Application Data\flvcd\flvcd_href.htm ()
O8 - Extra context menu item: Download with Mipony - H:\Program Files\MiPony\Browser\IEContext.htm ()
O8 - Extra context menu item: 使用快播按图找片 - H:\Program Files\QvodPlayer\AddIn\ImgSeed.htm ()
O8 - Extra context menu item: 收藏到搜狐影音 - Reg Error: Value error. File not found
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\YouKu\youkuclient\ikutm.dll (youku.com)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\YouKu\youkuclient\ikutm.dll (youku.com)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\YouKu\youkuclient\ikutm.dll (youku.com)
O15 - HKLM\..Trusted Domains: gogobox.com.tw ([]gb2 in Trusted sites)
O15 - HKLM\..Trusted Domains: gogobox.com.tw ([]http in Trusted sites)
O16 - DPF: {1DABF8D5-8430-4985-9B7F-A30E53D709B3} http://dl_dir.qq.com...MMInstaller.cab (InstallHelper Class)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bit...m/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.c...oft_webscan.cab (Emsisoft Web Malware Scan)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ad...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 202.156.1.16 218.186.2.16 218.186.2.6
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{84BB2E11-9558-430C-8909-EDB3C4C1FB8B}: DhcpNameServer = 202.156.1.16 218.186.2.16 218.186.2.6
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{99500004-75DD-4DC2-A969-0129C59083B3}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/01/07 07:24:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2013/06/15 09:36:56 | 001,029,537 | ---- | M] () - H:\AutoClick.rar -- [ NTFS ]
O33 - MountPoints2\{1af53b09-c268-11e0-8308-003067a72b32}\Shell - "" = AutoRun
O33 - MountPoints2\{1af53b09-c268-11e0-8308-003067a72b32}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1af53b09-c268-11e0-8308-003067a72b32}\Shell\AutoRun\command - "" = I:\Startme.exe
O33 - MountPoints2\{92e934f0-19ef-11e0-9bf7-00138f9363a1}\Shell - "" = AutoRun
O33 - MountPoints2\{92e934f0-19ef-11e0-9bf7-00138f9363a1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{92e934f0-19ef-11e0-9bf7-00138f9363a1}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{b9d0d698-19ec-11e0-9bf6-bfec7e776b98}\Shell - "" = AutoRun
O33 - MountPoints2\{b9d0d698-19ec-11e0-9bf6-bfec7e776b98}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b9d0d698-19ec-11e0-9bf6-bfec7e776b98}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{b9d0d69e-19ec-11e0-9bf6-bfec7e776b98}\Shell - "" = AutoRun
O33 - MountPoints2\{b9d0d69e-19ec-11e0-9bf6-bfec7e776b98}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b9d0d69e-19ec-11e0-9bf6-bfec7e776b98}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{d4b6eaa5-0add-11e2-869a-003067a72b32}\Shell - "" = AutoRun
O33 - MountPoints2\{d4b6eaa5-0add-11e2-869a-003067a72b32}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d4b6eaa5-0add-11e2-869a-003067a72b32}\Shell\AutoRun\command - "" = I:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/04/16 20:33:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\OTL.exe
[2014/04/16 19:47:10 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2014/03/30 20:30:22 | 000,107,256 | ---- | C] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys
========== Files - Modified Within 30 Days ==========
[2014/04/16 20:33:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
[2014/04/16 20:25:42 | 000,000,536 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/04/16 20:08:47 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2014/04/16 19:56:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/04/16 19:47:22 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2014/04/16 19:40:58 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014/04/16 19:34:23 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/04/16 19:32:23 | 000,000,220 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Logon.job
[2014/04/16 19:24:39 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/04/16 15:26:01 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-343818398-179605362-1801674531-1003UA.job
[2014/04/16 06:26:00 | 000,000,972 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-343818398-179605362-1801674531-1003Core.job
[2014/04/16 05:46:46 | 000,000,004 | ---- | M] () -- C:\authres.html
[2014/04/15 22:05:02 | 000,000,087 | ---- | M] () -- C:\WINDOWS\psnetwork.ini
[2014/04/15 07:55:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2014/04/15 06:39:17 | 000,123,904 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/04/10 05:56:58 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2014/04/09 23:25:32 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2014/04/08 16:30:13 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014/03/31 22:28:01 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\User\Application Data\coreavc.ini
[2014/03/31 22:28:01 | 000,000,138 | ---- | M] () -- C:\WINDOWS\vsfilter.INI
[2014/03/30 20:30:22 | 000,107,256 | ---- | M] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys
[2014/03/26 23:33:07 | 000,001,917 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2014/03/26 05:23:42 | 000,001,739 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Sony PC Companion 2.1.lnk
[2014/03/19 17:56:35 | 000,000,281 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Shortcut to Maxtor (H).lnk
========== Files Created - No Company Name ==========
[2014/03/26 23:42:58 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2014/03/26 05:23:42 | 000,001,739 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Sony PC Companion 2.1.lnk
[2014/03/19 17:56:35 | 000,000,281 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\Shortcut to Maxtor (H).lnk
[2013/11/26 19:34:41 | 000,000,087 | ---- | C] () -- C:\WINDOWS\psnetwork.ini
[2013/10/24 14:27:46 | 002,310,992 | ---- | C] () -- C:\WINDOWS\System32\shellfire.dll
[2013/09/22 21:31:15 | 000,000,149 | ---- | C] () -- C:\WINDOWS\phw.ini
[2013/06/14 23:52:56 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\fusioncache.dat
[2012/11/30 06:28:11 | 000,000,305 | ---- | C] () -- C:\WINDOWS\System32\bdsecushr.dat
[2012/10/07 14:08:32 | 000,000,138 | ---- | C] () -- C:\WINDOWS\vsfilter.INI
[2012/10/07 14:08:25 | 000,001,042 | ---- | C] () -- C:\Documents and Settings\User\Application Data\coreavc.ini
[2011/02/23 17:13:02 | 003,408,326 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-343818398-179605362-1801674531-1003-0.dat
[2011/02/23 17:13:01 | 000,146,698 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/01/07 12:32:53 | 000,123,904 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2011/01/07 12:29:56 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 11:42:06 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 20:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 11:42:10 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/01/07 07:39:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2013/01/20 21:42:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Application Data
[2011/01/11 12:38:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Awem
[2013/11/26 19:42:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Baidu
[2014/04/16 06:38:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2013/07/07 01:52:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grid
[2013/11/10 14:00:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/01/07 07:41:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kingsoft
[2013/10/16 22:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KuaiWan
[2014/01/16 20:33:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LocalStorage
[2012/04/27 21:43:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2011/02/08 15:11:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NatGeoGames
[2011/02/02 13:20:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2013/11/26 19:38:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PPLive
[2013/11/26 19:34:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QiYi
[2013/12/24 17:12:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RaySource
[2012/03/09 05:50:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2014/03/22 20:25:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony Mobile
[2011/02/19 14:31:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2013/04/18 10:06:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2013/07/07 19:38:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2012/04/27 21:37:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Anarchy
[2011/10/20 07:27:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Awem
[2013/11/26 19:42:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Baidu
[2013/12/25 09:21:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\baiduAddr
[2011/01/20 13:20:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\BlamGames
[2013/03/23 11:43:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Building the Great Wall of China
[2012/07/26 09:26:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\CometPlayer
[2011/01/09 02:32:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\DAEMON Tools Pro
[2011/09/09 23:38:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\dekovir
[2013/08/22 20:19:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\flvcd
[2013/11/17 13:56:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\FMRTE14
[2012/06/08 17:00:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\FMRTEv5
[2011/02/02 12:58:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Go-Go Gourmet Chef of the Year
[2013/04/16 23:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Happy Kingdom
[2013/07/22 23:13:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\HipSoft
[2011/01/09 02:33:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\IObit
[2011/01/07 07:41:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Kingsoft
[2012/09/28 22:06:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mipony
[2011/02/08 15:11:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\NatGeoGames
[2011/02/02 13:20:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\PlayFirst
[2013/11/26 19:11:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\PPlive
[2013/11/09 08:23:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\PPStream
[2013/09/22 21:12:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\PPStreamSetup
[2013/11/26 19:34:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Qiyi
[2013/07/05 22:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\QuickScan
[2011/08/09 20:42:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Sony
[2011/02/19 14:30:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Sports Interactive
[2011/01/08 15:38:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Supermarket Mania 2
[2014/04/11 19:21:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\tigerplayer
[2013/11/08 19:46:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Wandoujia2
[2014/03/11 06:39:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\youku
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012/08/09 09:57:41 | 000,000,000 | ---D | M](C:\Program Files\??êó) -- C:\Program Files\˶Êó
[2012/08/09 09:57:41 | 000,000,000 | ---D | M](C:\Program Files\??êó) -- C:\Program Files\˶Êó
(C:\Program Files\??êó) -- C:\Program Files\˶Êó
========== Alternate Data Streams ==========
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CC386FD2
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63C68F03
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:38D2EA83
< End of report >
The OTL Extras log:
OTL Extras logfile created on: 4/16/2014 8:33:11 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.97 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 42.96% Memory free
4.81 Gb Paging File | 3.16 Gb Available in Paging File | 65.66% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.87 Gb Total Space | 8.69 Gb Free Space | 3.73% Space Free | Partition Type: NTFS
Drive E: | 232.88 Gb Total Space | 2.84 Gb Free Space | 1.22% Space Free | Partition Type: NTFS
Drive F: | 58.59 Gb Total Space | 0.48 Gb Free Space | 0.81% Space Free | Partition Type: NTFS
Drive G: | 174.29 Gb Total Space | 1.53 Gb Free Space | 0.88% Space Free | Partition Type: NTFS
Drive H: | 189.92 Gb Total Space | 0.44 Gb Free Space | 0.23% Space Free | Partition Type: NTFS
Computer Name: USER-8CE73256DD | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"17539:TCP" = 17539:TCP:*:Enabled:BitComet 17539 TCP
"17539:UDP" = 17539:UDP:*:Enabled:BitComet 17539 UDP
"50000:UDP" = 50000:UDP:*:Enabled:sina_live
"50001:UDP" = 50001:UDP:*:Enabled:sina_live
"6001:TCP" = 6001:TCP:*:Enabled:sina_live
"6002:TCP" = 6002:TCP:*:Enabled:sina_live
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe" = C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe:*:Enabled:PPTV网络电视
"H:\Program Files\QvodPlayer\QvodTerminal.exe" = H:\Program Files\QvodPlayer\QvodTerminal.exe:*:Enabled:QvodTerminal -- (Shenzhen QVOD Technology Co.,Ltd)
"C:\Program Files\GridService\peer.exe" = C:\Program Files\GridService\peer.exe:*:Enabled:Grid Service -- (FS2YOU)
"C:\Program Files\YouKu\youkuclient\YoukuMediaCenter.exe" = C:\Program Files\YouKu\youkuclient\YoukuMediaCenter.exe:*:Enabled:youku media center service -- (Youku.com)
"C:\Program Files\BitComet\BitComet.exe" = C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client -- (www.BitComet.com)
"C:\Program Files\Tudou\iTudou\iTudou.exe" = C:\Program Files\Tudou\iTudou\iTudou.exe:*:Enabled:iTudou 2.6.10.0 -- (土豆网)
"C:\Documents and Settings\All Users\Application Data\QiYi\QiyiKernel\App\QiyiKernel.exe" = C:\Documents and Settings\All Users\Application Data\QiYi\QiyiKernel\App\QiyiKernel.exe:*:Enabled:QiyiKernel -- (BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.)
"C:\Program Files\iQIYI\QYFollowVideo.exe" = C:\Program Files\iQIYI\QYFollowVideo.exe:*:Enabled:QYFollowVideo -- (爱奇艺)
"C:\Program Files\iQIYI\QiyiClient.exe" = C:\Program Files\iQIYI\QiyiClient.exe:*:Enabled:QIYICLIENT -- (爱奇艺)
"H:\Program Files\Baidu\BaiduPlayer\1.17.0.172\BaiduP2PService.exe" = H:\Program Files\Baidu\BaiduPlayer\1.17.0.172\BaiduP2PService.exe:*:Enabled:百度流媒体服务 -- (Baidu.com, Inc.)
"C:\Program Files\Baidu\BaiduPlayer\1.19.0.137\BaiduP2PService.exe" = C:\Program Files\Baidu\BaiduPlayer\1.19.0.137\BaiduP2PService.exe:*:Enabled:BaiduP2PService.exe -- (Baidu.com, Inc.)
"C:\Program Files\Baidu\BaiduPlayer\1.19.0.137\StatReport.exe" = C:\Program Files\Baidu\BaiduPlayer\1.19.0.137\StatReport.exe:*:Enabled:StatReport.exe -- (Baidu.com, Inc.)
"C:\Program Files\Baidu\BaiduPlayer\1.19.0.137\BaiduPlayer.exe" = C:\Program Files\Baidu\BaiduPlayer\1.19.0.137\BaiduPlayer.exe:*:Enabled:BaiduPlayer.exe -- ()
"C:\Documents and Settings\All Users\Application Data\Baidu\BaiduPlayer\bdupdate.exe" = C:\Documents and Settings\All Users\Application Data\Baidu\BaiduPlayer\bdupdate.exe:*:Enabled:bdupdate.exe -- (Baidu.com, Inc.)
"C:\Program Files\Baidu\BaiduPlayer\1.19.0.137\BaiduSetupAx_0.exe" = C:\Program Files\Baidu\BaiduPlayer\1.19.0.137\BaiduSetupAx_0.exe:*:Enabled:BaiduSetupAx_0.exe
"H:\Program Files\Steam\Steam.exe" = H:\Program Files\Steam\Steam.exe:*:Enabled:Steam Client Bootstrapper (buildbot_winslave04_steam_steam_rel_client_win32@winslave04) -- (Valve Corporation)
"H:\Program Files\QvodPlayer\QvodPlayer.exe" = H:\Program Files\QvodPlayer\QvodPlayer.exe:*:Enabled:快播 -- (Shenzhen QVOD Technology Co.,Ltd)
"C:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin -- (Skype Limited)
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer -- (Microsoft Corporation)
"C:\Program Files\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe" = C:\Program Files\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe:*:Enabled:Update Engine -- ()
"C:\Program Files\gogobox\gogobox.exe" = C:\Program Files\gogobox\gogobox.exe:*:Enabled:GOGOBOX_FirewallAgent -- (NEXTLiNK Technology Co., Ltd.)
"C:\Program Files\gogobox\gogobox_updater.exe" = C:\Program Files\gogobox\gogobox_updater.exe:*:Enabled:GOGOBOX_FirewallAgent -- (NEXTLiNK Technology Co., Ltd.)
"C:\Program Files\gogobox\gogobox_e.exe" = C:\Program Files\gogobox\gogobox_e.exe:*:Enabled:GOGOBOX_FirewallAgent -- ()
"C:\Program Files\gogobox\gogobox_t.exe" = C:\Program Files\gogobox\gogobox_t.exe:*:Enabled:GOGOBOX_FirewallAgent -- (Netxtream)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03C8F224-5374-423D-BA14-270610258E83}_is1" = 搜狐影音3.1.0.0
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation®Store
"{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1" = EZDownloader
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18651D22-C569-40DA-9DCE-0F98A4BBE19F}" = FMRTE
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1E4A6F03-4D71-4496-9B2D-71C8B59F64DE}" = BiosNotice
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java 6 Update 37
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 51
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36A345C9-0691-45A1-AEEF-29ECEC8B5014}" = Microsoft Security Client
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{63486834-B10B-4DD4-8216-C8D66A157D7E}_is1" = FMRTE 5.2.4
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6BB5ABD5-3CD2-48CF-AA24-74F0B0568923}" = BrowseToSave
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}" = Facebook Video Calling 2.0.0.447
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.06)
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{AC7F2C31-9BBE-46A4-9C36-B2FA08B9F446}" = winniethepoohcur
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation®Network Downloader
"{BE4F388F-E7B6-43E8-8856-6B74AC375A87}" = Media Go
"{BE9CA23E-C5F5-410E-A3E5-8DD7657F80C8}" =
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8A28D99-7591-45DC-8AF5-DBFB572CC8DA}" = Snap.Do
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E2EE37-5AA9-4B4F-8D3F-5D5459778864}_is1" = FMRTE 14.1.3.3
"{DBC12450-EB73-4B1D-A2E0-EFEE811720B2}" = FormatFactory
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.197
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F5D73EED-4AAD-4784-84EA-A57FF75BC23D}_is1" = 鼠标连点器 2.0
"{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}" = Nero Burning ROM 10
"7 Wonders Magical Mystery Tour 1.00" = 7 Wonders Magical Mystery Tour 1.00
"Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX
"Airline Baggage Mania 1.00" = Airline Baggage Mania 1.00
"BaiduPlayer" = BaiduPlayer1.19.0.137
"Ballad of Solar 1.00" = Ballad of Solar 1.00
"Be Richest 1.00" = Be Richest 1.00
"BitComet" = BitComet 1.07
"Blooming Daisies 1.00" = Blooming Daisies 1.00
"Build a lot 6 On Vacation 1.2" = Build a lot 6 On Vacation 1.2
"Build a lot Fairy Tales 1.00" = Build a lot Fairy Tales 1.00
"Building the Great Wall of China 1.00" = Building the Great Wall of China 1.00
"Coffee Rush 3 1.00" = Coffee Rush 3 1.00
"Cooking Dash 3 Thrills and Spills Collectors Edition 1.00" = Cooking Dash 3 Thrills and Spills Collectors Edition 1.00
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.17
"Cradle Of Egypt Collectors Edition 1.00" = Cradle Of Egypt Collectors Edition 1.00
"Cradle Of Rome 2 1.00" = Cradle Of Rome 2 1.00
"Dragon Empire_is1" = Dragon Empire
"FileHippo.com" = FileHippo.com Update Checker
"Fishers Family Farm 1.00" = Fishers Family Farm 1.00
"FormatFactory" = FormatFactory 3.2.1.0
"FPE 2001" = FPE 2001
"Go-Go Gourmet 2 - Chef of the Year1.0" = Go-Go Gourmet 2 - Chef of the Year
"GOGOBOX" = GOGOBOX
"Google Chrome" = Google Chrome
"Happy Kingdom 1.0" = Happy Kingdom 1.0
"ie8" = Windows Internet Explorer 8
"iKu" = Youku iku
"iTudou" = iTudou 2.6.10.0
"Jewel Quest 6 The Sapphire Dragon Collectors Edition 1.00" = Jewel Quest 6 The Sapphire Dragon Collectors Edition 1.00
"Kingsoft Office" = Kingsoft Office 2010 (6.6.0.2496)
"Mahjong Royal Towers 1.00" = Mahjong Royal Towers 1.00
"Mahjongg - Legends of the Tiles" = Mahjongg - Legends of the Tiles
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"MiPony" = MiPony 1.3.0
"MpcStar" = MpcStar 5.3
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"Oriental Dreams_is1" = Oriental Dreams
"qqlive" = 腾讯视频
"QvodPlayer" = 快播 5.18.161
"Rapport_msi" = Trusteer Endpoint Protection
"RaySource" = RaySource 2.4.0.2
"RealPlayer 6.0" = RealPlayer
"SopCast" = SopCast 3.2.9
"SpeedFan" = SpeedFan (remove only)
"Steam App 231670" = Football Manager 2014
"Steam App 242460" = Football Manager 2014 Editor
"Steam App 242480" = Football Manager 2014 Resource Archiver
"Steam App 71270" = Football Manager 2012
"Steam App 71400" = Football Manager 2012 Editor
"Steam App 71410" = Football Manager 2012 Resource Archiver
"Supermarket Mania 2 1.00" = Supermarket Mania 2 1.00
"Trade Mania 1.00" = Trade Mania 1.00
"Update Engine" = Sony Mobile Update Engine
"VLC media player" = VLC media player 0.9.8a
"vShare.tv plugin" = vShare.tv plugin 1.3
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WhoCrashed_is1" = WhoCrashed 3.01
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR 壓縮工具
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YoukuClient" = 优酷客户端
"手机顽童_is1" = 手机顽童圣诞特别版
"搜狐影音" = 搜狐影音
"新浪Live" = 新浪Live
"爱奇艺视频" = 爱奇艺视频2.0
"硕鼠" = 硕鼠 0.4.7.6 正式版
"金庸群侠苍龙版_is1" = 金庸群侠苍龙版
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{3581bea1-b5b1-4e06-a474-e1b985b85d37}" = Snap.Do Engine
"Easy St. Tycoon" = Easy St. Tycoon
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/13/2014 10:05:13 AM | Computer Name = USER-8CE73256DD | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/13/2014 10:05:13 AM | Computer Name = USER-8CE73256DD | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/13/2014 10:05:13 AM | Computer Name = USER-8CE73256DD | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/13/2014 10:06:05 AM | Computer Name = USER-8CE73256DD | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x696e554c.
Error - 3/13/2014 11:27:45 AM | Computer Name = USER-8CE73256DD | Source = Application Error | ID = 1000
Description = Faulting application fm.exe, version 14.1.3.45519, faulting module
fm.exe, version 14.1.3.45519, fault address 0x0154fa50.
Error - 3/13/2014 11:48:12 AM | Computer Name = USER-8CE73256DD | Source = Application Error | ID = 1000
Description = Faulting application wps.exe, version 1.0.0.2496, faulting module
wps.exe, version 1.0.0.2496, fault address 0x00176ac4.
Error - 3/14/2014 11:32:43 AM | Computer Name = USER-8CE73256DD | Source = Application Error | ID = 1000
Description = Faulting application fm.exe, version 14.1.3.45519, faulting module
fm.exe, version 14.1.3.45519, fault address 0x0154fa50.
Error - 3/16/2014 1:42:16 AM | Computer Name = USER-8CE73256DD | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module realmediasplitter.ax, version 1.0.1.2, fault address 0x00005983.
Error - 3/18/2014 11:27:29 AM | Computer Name = USER-8CE73256DD | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x03e3c51e.
Error - 3/18/2014 11:27:47 AM | Computer Name = USER-8CE73256DD | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x033fc51e.
[ System Events ]
Error - 4/16/2014 5:35:36 AM | Computer Name = USER-8CE73256DD | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Display Driver Service service failed to start due to the
following error: %%1053
Error - 4/16/2014 5:36:58 AM | Computer Name = USER-8CE73256DD | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.
Error - 4/16/2014 5:37:27 AM | Computer Name = USER-8CE73256DD | Source = Microsoft Antimalware | ID = 2041
Description = The support for your operating system has expired. Running %%860 on
an out of support operating system is not an adequate solution to protect against
threats.
Error - 4/16/2014 7:38:44 AM | Computer Name = USER-8CE73256DD | Source = Service Control Manager | ID = 7022
Description = The WebClient service hung on starting.
Error - 4/16/2014 7:38:44 AM | Computer Name = USER-8CE73256DD | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 4/16/2014 7:40:35 AM | Computer Name = USER-8CE73256DD | Source = Service Control Manager | ID = 7022
Description = The Automatic Updates service hung on starting.
Error - 4/16/2014 7:40:35 AM | Computer Name = USER-8CE73256DD | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.
Error - 4/16/2014 7:46:14 AM | Computer Name = USER-8CE73256DD | Source = Microsoft Antimalware | ID = 3002
Description = %%860 Real-Time Protection feature has encountered an error and failed.
Feature:
%%834 Error Code: 0x80004005 Error description: Unspecified error Reason: %%838
Error - 4/16/2014 8:25:41 AM | Computer Name = USER-8CE73256DD | Source = Microsoft Antimalware | ID = 3002
Description = %%860 Real-Time Protection feature has encountered an error and failed.
Feature:
%%834 Error Code: 0x80004005 Error description: Unspecified error Reason: %%838
Error - 4/16/2014 8:25:42 AM | Computer Name = USER-8CE73256DD | Source = Service Control Manager | ID = 7034
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 3 time(s).
< End of report >
Thanks.