OTL.txt
OTL logfile created on: 9/11/2013 1:01:37 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\\Documents and Settings\\Windows xp\\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
958.42 Mb Total Physical Memory | 601.15 Mb Available Physical Memory | 62.72% Memory free
2.26 Gb Paging File | 1.97 Gb Available in Paging File | 87.16% Paging File free
Paging file location(s): C:\\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\\WINDOWS | %ProgramFiles% = C:\\Program Files
Drive C: | 48.83 Gb Total Space | 27.26 Gb Free Space | 55.83% Space Free | Partition Type: NTFS
Drive F: | 25.68 Gb Total Space | 25.02 Gb Free Space | 97.42% Space Free | Partition Type: FAT32
Computer Name: INTEL-8271358DF | User Name: Windows xp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/09/11 01:00:21 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Documents and Settings\\Windows xp\\Desktop\\OTL.exe
PRC - [2013/09/06 19:59:46 | 000,458,832 | ---- | M] (BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.) -- C:\\Program Files\\iQIYI\\QiyiService.exe
PRC - [2013/08/22 19:29:32 | 001,261,184 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- C:\\Program Files\\QvodPlayer\\QvodTerminal.exe
PRC - [2013/08/19 18:10:25 | 000,164,816 | ---- | M] (APN LLC.) -- C:\\Program Files\\AskPartnerNetwork\\Toolbar\\apnmcp.exe
PRC - [2013/08/19 18:10:18 | 001,601,488 | ---- | M] (APN) -- C:\\Program Files\\AskPartnerNetwork\\Toolbar\\Updater\\TBNotifier.exe
PRC - [2013/08/13 22:41:17 | 002,838,480 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Application Data\\BrowserDefender\\2.6.1562.220\\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\\BrowserDefender.exe
PRC - [2013/08/05 18:15:22 | 004,105,080 | ---- | M] (PPStream Inc.) -- C:\\Program Files\\PPStream\\PPSKernel.exe
PRC - [2012/12/07 18:27:50 | 000,167,424 | ---- | M] () -- C:\\Program Files\\HTC\\Internet Pass-Through\\PassThruSvr.exe
PRC - [2010/08/16 15:51:30 | 000,061,440 | ---- | M] () -- C:\\Program Files\\D-Link\\DWA-123\\ALPBCSVC.exe
PRC - [2009/03/10 22:18:14 | 000,934,792 | ---- | M] (Microsoft Corporation) -- C:\\WINDOWS\\system32\\WgaTray.exe
PRC - [2008/04/14 08:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\\WINDOWS\\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2013/08/22 17:19:31 | 000,187,888 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\BabSolution\\Shared\\enhancedNT.dll
MOD - [2013/08/21 19:03:42 | 004,218,288 | ---- | M] () -- C:\\Program Files\\QvodPlayer\\QvodRes.dll
MOD - [2013/08/13 22:41:17 | 002,838,480 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Application Data\\BrowserDefender\\2.6.1562.220\\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\\BrowserDefender.exe
MOD - [2013/08/13 22:40:06 | 002,699,216 | ---- | M] () -- c:\\Documents and Settings\\All Users\\Application Data\\BrowserDefender\\2.6.1562.220\\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\\BrowserDefender.dll
MOD - [2013/08/01 23:29:20 | 000,138,880 | ---- | M] () -- C:\\Program Files\\QvodPlayer\\NetUtil.dll
MOD - [2013/07/17 17:28:28 | 000,261,760 | ---- | M] () -- C:\\Program Files\\QMovie\\QvodShellIconImp.dll
MOD - [2013/07/07 21:08:40 | 000,073,728 | ---- | M] () -- C:\\WINDOWS\\system32\\ANPDApi.dll
MOD - [2012/12/07 18:27:50 | 000,167,424 | ---- | M] () -- C:\\Program Files\\HTC\\Internet Pass-Through\\PassThruSvr.exe
MOD - [2010/08/16 15:51:30 | 000,061,440 | ---- | M] () -- C:\\Program Files\\D-Link\\DWA-123\\ALPBCSVC.exe
MOD - [2003/05/15 14:43:24 | 000,119,808 | ---- | M] () -- C:\\Program Files\\WinRAR\\RarExt.dll
========== Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\\System32\\hidserv.dll -- (HidServ)
SRV - [2013/09/06 19:59:46 | 000,458,832 | ---- | M] (BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.) [Auto | Running] -- C:\\Program Files\\iQIYI\\QiyiService.exe -- (QiyiService)
SRV - [2013/08/19 18:10:25 | 000,164,816 | ---- | M] (APN LLC.) [Auto | Running] -- C:\\Program Files\\AskPartnerNetwork\\Toolbar\\apnmcp.exe -- (APNMCP)
SRV - [2013/08/13 22:41:17 | 002,838,480 | ---- | M] () [Auto | Running] -- C:\\Documents and Settings\\All Users\\Application Data\\BrowserDefender\\2.6.1562.220\\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\\BrowserDefender.exe -- (BrowserDefendert)
SRV - [2012/12/07 18:27:50 | 000,167,424 | ---- | M] () [Auto | Running] -- C:\\Program Files\\HTC\\Internet Pass-Through\\PassThruSvr.exe -- (PassThru Service)
SRV - [2012/11/19 17:03:24 | 000,489,256 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Steam\\SteamService.exe -- (Steam Client Service)
SRV - [2010/08/16 15:51:30 | 000,061,440 | ---- | M] () [Auto | Running] -- C:\\Program Files\\D-Link\\DWA-123\\ALPBCSVC.exe -- (D-Link DWA-123_PBC_WPS)
SRV - [2005/04/05 11:17:22 | 000,206,552 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Symantec Shared\\SNDSrvc.exe -- (SNDSrvc)
SRV - [2005/01/26 15:30:04 | 000,053,337 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Sony Shared\\AVLib\\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - [2005/01/26 15:25:34 | 000,053,337 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Sony Shared\\AVLib\\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2005/01/26 15:20:14 | 000,069,718 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Sony Shared\\AVLib\\SPTISRV.exe -- (SPTISRV)
SRV - [2005/01/24 18:36:52 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Sony Shared\\AVLib\\SSScsiSV.exe -- (SSScsiSV)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\RTL8139.SYS -- (rtl8139)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- E:\\INSTALL\\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\\Program Files\\Garena Plus\\Room\\safedrv.sys -- (GGSAFERDriver)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/07/07 21:08:40 | 000,029,411 | ---- | M] () [Kernel | Auto | Running] -- C:\\WINDOWS\\system32\\ANPD.SYS -- (ANPD)
DRV - [2012/12/07 18:27:50 | 000,021,248 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\htcnprot.sys -- (htcnprot)
DRV - [2012/01/06 10:23:10 | 001,224,384 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\Drt2870.sys -- (rt2870)
DRV - [2008/04/24 00:30:33 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\pfc.sys -- (pfc)
DRV - [2007/10/18 18:28:52 | 000,052,224 | R--- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\\WINDOWS\\system32\\drivers\\ViPrt.sys -- (ViPrt)
DRV - [2007/10/18 18:28:30 | 000,016,896 | R--- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\\WINDOWS\\system32\\drivers\\ViBus.sys -- (ViBus)
DRV - [2007/10/16 18:38:30 | 004,615,168 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2007/09/21 17:49:10 | 000,009,216 | R--- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\\WINDOWS\\system32\\drivers\\videX32.sys -- (videX32)
DRV - [2007/07/11 13:08:46 | 000,714,240 | ---- | M] (S3 Graphics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\S3gIGPm.sys -- (S3GIGP)
DRV - [2006/01/03 15:31:44 | 000,117,408 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\\Program Files\\Symantec\\SYMEVENT.SYS -- (SymEvent)
DRV - [2005/04/05 11:17:02 | 000,267,192 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\\WINDOWS\\system32\\drivers\\symtdi.sys -- (SYMTDI)
DRV - [2005/04/05 11:17:00 | 000,017,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\symredrv.sys -- (SYMREDRV)
DRV - [2005/03/23 11:00:57 | 001,034,752 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\ati2mtag.sys -- (ati2mtag)
DRV - [2005/03/16 14:23:54 | 000,013,696 | R--- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\\WINDOWS\\system32\\drivers\\BIOS.sys -- (BIOS)
DRV - [2005/03/04 12:02:20 | 001,066,278 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\AGRSM.sys -- (AgereSoftModem)
DRV - [2004/09/21 19:53:18 | 002,278,784 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\ALCXWDM.SYS -- (ALCXWDM)
DRV - [2004/09/01 08:00:00 | 000,012,160 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\\WINDOWS\\system32\\drivers\\fsvga.sys -- (FsVga)
DRV - [2004/04/13 20:14:12 | 000,070,144 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\Rtlnicxp.sys -- (RTL8023xp)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\\..\\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\\..\\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\\..\\SearchScopes,DefaultScope = {B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2}
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: \"Google\"
FF - HKLM\\Software\\MozillaPlugins\\@iqiyi.com/npclient: C:\\Program Files\\iQIYI\\npclient.dll ()
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WPF,version=3.5: c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.5\\Windows Presentation Foundation\\NPWPF.dll (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@qvod.com/QvodInsert: C:\\Program Files\\QvodPlayer\\npQvodInsert.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKLM\\Software\\MozillaPlugins\\@qvod.com/QvodShare: C:\\Program Files\\QvodPlayer\\npShareModule.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKLM\\Software\\MozillaPlugins\\@t.garena.com/garenatalk: C:\\Program Files\\Garena Plus\\bbtalk\\plugins\\npPlugin\\npGarenaTalkPlugin.dll ( Garena)
FF - HKLM\\Software\\MozillaPlugins\\Adobe Reader: C:\\Program Files\\Adobe\\Reader 10.0\\Reader\\AIR\\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\\Software\\MozillaPlugins\\@qvod.com/QvodInsert: C:\\Program Files\\QvodPlayer\\npQvodInsert.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\\Software\\MozillaPlugins\\KuaiWanInsert: C:\\Program Files\\QvodPlayer\\AddIn\\KWWebgame\\npKWWebGame.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKCU\\Software\\MozillaPlugins\\kwcheck: C:\\Program Files\\Kuaiwan\\npKWCheck.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKCU\\Software\\MozillaPlugins\\KwFlashGame: C:\\Program Files\\Kuaiwan\\npKWFlashGame.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 4.0\\extensions\\\\Components: C:\\Program Files\\Mozilla Firefox\\components [2007/12/21 06:46:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 4.0\\extensions\\\\Plugins: C:\\Program Files\\Mozilla Firefox\\plugins [2013/07/07 08:10:52 | 000,000,000 | ---D | M]
[2007/12/21 06:46:12 | 000,000,000 | ---D | M] (No name found) -- C:\\Documents and Settings\\Windows xp\\Application Data\\Mozilla\\Extensions
[2013/09/06 20:13:44 | 000,000,000 | ---D | M] (No name found) -- C:\\Documents and Settings\\Windows xp\\Application Data\\Mozilla\\Firefox\\Profiles\\7cuu0kyg.default\\extensions
[2011/03/10 18:07:46 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\\Documents and Settings\\Windows xp\\Application Data\\Mozilla\\Firefox\\Profiles\\7cuu0kyg.default\\extensions\\{20a82645-c095-46ed-80e3-08825760534b}
[2013/08/26 20:11:22 | 000,000,000 | ---D | M] (No name found) -- C:\\Documents and Settings\\Windows xp\\Application Data\\Mozilla\\Firefox\\Profiles\\7cuu0kyg.default\\extensions\\
[email protected][2013/08/26 20:11:29 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\\Documents and Settings\\Windows xp\\Application Data\\Mozilla\\Firefox\\Profiles\\7cuu0kyg.default\\extensions\\
[email protected][2013/09/06 20:13:44 | 000,000,000 | ---D | M] (HDvid Codec 3) -- C:\\Documents and Settings\\Windows xp\\Application Data\\Mozilla\\Firefox\\Profiles\\7cuu0kyg.default\\extensions\\
[email protected][2013/06/30 16:44:04 | 000,233,016 | ---- | M] () (No name found) -- C:\\Documents and Settings\\Windows xp\\Application Data\\Mozilla\\Firefox\\Profiles\\7cuu0kyg.default\\extensions\\
[email protected][2007/12/21 06:42:25 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files\\Mozilla Firefox\\extensions
File not found (No name found) -- C:\\PROGRAM FILES\\KASPERSKY LAB\\KASPERSKY ANTI-VIRUS 2012\\FFEXT\\
[email protected]File not found (No name found) -- C:\\PROGRAM FILES\\MOZILLA FIREFOX\\EXTENSIONS\\
[email protected][2011/03/19 01:53:24 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\\Program Files\\mozilla firefox\\components\\browsercomps.dll
[2004/06/09 16:03:02 | 000,832,728 | ---- | M] () -- C:\\Program Files\\mozilla firefox\\plugins\\NPSWF32.dll
[2010/01/01 16:00:00 | 000,002,252 | ---- | M] () -- C:\\Program Files\\mozilla firefox\\searchplugins\\bing.xml
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage:
CHR - Extension: No name found = C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\aaaajabnoiehionljhjpclogplgillib\\21.51087_0\\
CHR - Extension: No name found = C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\apdfllckaahabafndbhieahigkjlhalf\\6.3_1\\
CHR - Extension: No name found = C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_1\\
CHR - Extension: No name found = C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_1\\
CHR - Extension: No name found = C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\eooncjejnppfjjklapaamhcdmjbilmde\\1.4_0\\
CHR - Extension: No name found = C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\0.0.4.10_1\\
CHR - Extension: No name found = C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_0\\
O1 HOSTS File: ([2004/09/01 08:00:00 | 000,000,734 | ---- | M]) - C:\\WINDOWS\\system32\\drivers\\etc\\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HDvid Codec V1) - {11111111-1111-1111-1111-110311431162} - C:\\Program Files\\HDvid Codec V1\\HDvid Codec V1-bho.dll (installdaddy)
O2 - BHO: (Reg Error: Value error.) - {53707962-6F74-2D53-2644-206D7942484F} - C:\\Program Files\\Spybot - Search & Destroy\\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (QvodGameExtend) - {94C3E4BB-A261-4A83-B437-EA6F7A28CA68} - C:\\Program Files\\Kuaiwan\\QvodGameExtend.dll (Shenzhen QVOD Technology Co.,Ltd)
O2 - BHO: (A4A90076-33D2-E65C-558E-75B41A2B8C68 Class) - {A4A90076-33D2-E65C-558E-75B41A2B8C68} - C:\\Program Files\\addr\\{A4A90076-33D2-E65C-558E-75B41A2B8C68}\\AddressBar.dll ()
O2 - BHO: (QvodExtend) - {A8502600-B272-4F68-A67B-A0305D46D297} - C:\\Program Files\\QvodPlayer\\QvodExtend\\5.0.95.0\\QvodExtend.dll (Shenzhen QVOD Technology Co.,Ltd)
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\\Program Files\\Delta\\delta\\1.8.24.6\\bh\\delta.dll (Delta-search.com)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\\Program Files\\EPSON\\EPSON Web-To-Page\\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\\..\\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\\Program Files\\Delta\\delta\\1.8.24.6\\deltaTlbr.dll (Delta-search.com)
O3 - HKLM\\..\\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\\Program Files\\EPSON\\EPSON Web-To-Page\\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\\..\\Toolbar\\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\\Program Files\\EPSON\\EPSON Web-To-Page\\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\\Run: [EPSON Stylus C45 Series] C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I3T1.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\\Run: [PHIME2002A] C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName File not found
O4 - HKLM..\\Run: [PHIME2002ASync] C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC File not found
O4 - HKCU..\\Run: [NTRedirect] C:\\Documents and Settings\\Windows xp\\Application Data\\BabSolution\\Shared\\enhancedNT.dll ()
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoCDBurning = 0
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: 使用快播按图找片 - C:\\Program Files\\QvodPlayer\\AddIn\\ImgSeed.htm ()
O15 - HKCU\\..Trusted Domains: pps.tv ([]http in Trusted sites)
O15 - HKCU\\..Trusted Domains: ppstream.com ([]http in Trusted sites)
O15 - HKCU\\..Trusted Domains: webscache.com ([]http in Trusted sites)
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B44AD91F-9084-47ED-BFD0-4C5FEE5FCF25}: DhcpNameServer = 192.168.1.1
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B44AD91F-9084-47ED-BFD0-4C5FEE5FCF25}: NameServer = 202.188.0.133,202.188.1.5
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DBF7827C-2DE6-48DD-BFC5-D8B619D1E10C}: NameServer = 202.188.0.133,202.188.1.5
O18 - Protocol\\Handler\\kuwo - No CLSID value found
O18 - Protocol\\Handler\\textwareilluminatorbase {CE5CD329-1650-414A-8DB0-4CBF72FAED87} - C:\\WINDOWS\\system32\\textwareilluminatorbaseProtocol.dll ()
O20 - AppInit_DLLs: (c:\\docume~1\\alluse~1\\applic~1\\browse~1\\261562~1.220\\{c16c1~1\\browse~1.dll) - c:\\Documents and Settings\\All Users\\Application Data\\BrowserDefender\\2.6.1562.220\\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\\BrowserDefender.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\\WINDOWS\\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\\WINDOWS\\system32\\userinit.exe) - C:\\WINDOWS\\system32\\userinit.exe (Microsoft Corporation)
O20 - Winlogon\\Notify\\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\\WINDOWS\\System32\\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Microsoft\\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\Microsoft\\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/15 10:19:01 | 000,000,000 | ---- | M] () - C:\\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2011/04/17 20:23:41 | 000,000,041 | R--- | M] () - E:\\autorun.inf -- [ CDFS ]
O33 - MountPoints2\\{9d816648-00ac-11e3-b730-00e04d6dd155}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{9d816648-00ac-11e3-b730-00e04d6dd155}\\Shell\\AutoRun - \"\" = Auto&Play
O33 - MountPoints2\\{9d816648-00ac-11e3-b730-00e04d6dd155}\\Shell\\AutoRun\\command - \"\" = G:\\HTC_Sync_Manager_PC.exe
O33 - MountPoints2\\{a44f9654-1165-11dd-86cd-806d6172696f}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{a44f9654-1165-11dd-86cd-806d6172696f}\\Shell\\AutoRun - \"\" = Auto&Play
O33 - MountPoints2\\{a44f9654-1165-11dd-86cd-806d6172696f}\\Shell\\AutoRun\\command - \"\" = E:\\start.exe -- [2011/04/17 20:27:36 | 002,672,720 | R--- | M] (Macromedia, Inc.)
O33 - MountPoints2\\{a57f384f-fa5f-11dc-bfa5-0011092af42d}\\Shell\\AutoRun\\command - \"\" = G:\\password_viewer.exe %1
O33 - MountPoints2\\{a57f384f-fa5f-11dc-bfa5-0011092af42d}\\Shell\\Explore\\command - \"\" = G:\\password_viewer.exe %1
O33 - MountPoints2\\{a57f384f-fa5f-11dc-bfa5-0011092af42d}\\Shell\\Open\\command - \"\" = G:\\password_viewer.exe %1
O33 - MountPoints2\\{ce524938-dd83-11d9-bde8-806d6172696f}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{ce524938-dd83-11d9-bde8-806d6172696f}\\Shell\\AutoRun - \"\" = Auto&Play
O33 - MountPoints2\\{ce524938-dd83-11d9-bde8-806d6172696f}\\Shell\\AutoRun\\command - \"\" = E:\\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\\..comfile [open] -- \"%1\" %*
O35 - HKLM\\..exefile [open] -- \"%1\" %*
O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*
O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2107/12/21 17:14:47 | 000,000,000 | R--D | C] -- C:\\Documents and Settings\\Windows xp\\My Documents\\My Pictures
[2013/09/11 01:00:15 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Documents and Settings\\Windows xp\\Desktop\\OTL.exe
[2013/09/11 00:22:34 | 000,000,000 | ---D | C] -- C:\\Program Files\\Trend Micro
[2013/09/11 00:22:34 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Windows xp\\Start Menu\\Programs\\HiJackThis
[2013/09/10 18:37:11 | 000,000,000 | -H-D | C] -- C:\\Documents and Settings\\All Users\\Device
[2013/09/10 18:37:01 | 000,000,000 | --SD | C] -- C:\\KuaiwanGames
[2013/09/10 14:35:00 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\快播软件
[2013/09/10 14:34:20 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\快玩游戏盒
[2013/09/10 14:34:12 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\快玩小游戏
[2013/09/10 14:34:12 | 000,000,000 | ---D | C] -- C:\\Program Files\\KuaiwanWebsite
[2013/09/10 14:33:47 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\影视搜索
[2013/09/10 14:33:43 | 000,000,000 | ---D | C] -- C:\\Program Files\\QMovie
[2013/09/10 14:33:43 | 000,000,000 | ---D | C] -- C:\\Program Files\\Kuaiwan
[2013/09/10 14:33:43 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\KuaiWan
[2013/09/10 14:33:38 | 000,000,000 | ---D | C] -- C:\\Program Files\\QvodPlayer
[2013/09/10 14:33:38 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\QvodPlayer
[2013/09/07 15:13:11 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\LocalStorage
[2013/09/06 20:14:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\AskPartnerNetwork
[2013/09/06 20:14:58 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\AskPartnerNetwork
[2013/09/06 20:14:01 | 000,000,000 | ---D | C] -- C:\\Program Files\\HDvid Codec V1
[2013/09/06 20:13:43 | 000,000,000 | ---D | C] -- C:\\Program Files\\HDvidCodec.com
[2013/09/06 20:12:59 | 000,000,000 | ---D | C] -- C:\\Program Files\\FreeHDSport.TV
[2013/09/06 20:12:51 | 000,000,000 | ---D | C] -- C:\\Program Files\\HDPlayer
[2013/09/06 20:12:51 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Windows xp\\Start Menu\\Programs\\HDPlayer
[2013/09/06 20:00:06 | 000,000,000 | ---D | C] -- C:\\qiyi
[2013/09/06 19:59:51 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\爱奇艺视频
[2013/09/06 19:59:51 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Windows xp\\Application Data\\Qiyi
[2013/09/06 19:59:39 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\QiYi
[2013/09/06 19:59:39 | 000,000,000 | ---D | C] -- C:\\Program Files\\iQIYI
[2013/09/06 19:53:40 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Windows xp\\Application Data\\baiduAddr
[2013/09/06 19:53:40 | 000,000,000 | ---D | C] -- C:\\Program Files\\Baidu
[2013/09/06 19:53:35 | 000,000,000 | ---D | C] -- C:\\Program Files\\addr
[2013/09/06 19:53:27 | 000,000,000 | ---D | C] -- C:\\Program Files\\PPSGame
[2013/09/06 19:52:38 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Documents\\ppstream
[2013/09/06 19:52:38 | 000,000,000 | ---D | C] -- C:\\ppsfile
[2013/09/06 19:52:37 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\PPStream
[2013/09/06 19:52:26 | 000,000,000 | ---D | C] -- C:\\Program Files\\PPStream
[2013/08/27 20:55:29 | 000,000,000 | ---D | C] -- C:\\WINDOWS\\System32\\LogFiles
[2013/08/26 20:11:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Delta
[2013/08/26 20:11:23 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Windows xp\\Application Data\\Delta
[2013/08/26 20:11:00 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\avgchrome
[2013/08/26 20:10:45 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Windows xp\\Start Menu\\Programs\\BrowserDefender
[2013/08/26 20:09:36 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\BrowserDefender
[2013/08/26 20:08:29 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Windows xp\\Application Data\\BabSolution
[2013/08/26 20:08:09 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\Babylon
[2013/08/26 20:07:43 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Windows xp\\Application Data\\SwvUpdater
[2013/08/26 20:02:11 | 000,000,000 | ---D | C] -- C:\\Program Files\\dumps
[2013/08/26 20:00:21 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Steam
[2013/08/26 20:00:19 | 000,000,000 | ---D | C] -- C:\\Program Files\\Steam
[2013/08/26 20:00:19 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Steam
[2013/08/21 14:33:23 | 000,000,000 | ---D | C] -- C:\\Program Files\\Free Video Converter
[2013/08/17 22:39:55 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\APN
[2 C:\\WINDOWS\\*.tmp files -> C:\\WINDOWS\\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2113/03/08 09:08:19 | 000,000,432 | -H-- | M] () -- C:\\WINDOWS\\tasks\\User_Feed_Synchronization-{36D868C8-689F-4EB6-B057-451A314795A9}.job
[2107/12/21 20:36:54 | 1005,076,480 | ---- | M] () -- C:\\WINDOWS\\MEMORY.DMP
[2013/09/11 01:14:01 | 000,000,296 | ---- | M] () -- C:\\WINDOWS\\tasks\\BrowserDefendert.job
[2013/09/11 01:10:41 | 000,000,998 | ---- | M] () -- C:\\WINDOWS\\tasks\\GoogleUpdateTaskUserS-1-5-21-527237240-287218729-725345543-1003UA.job
[2013/09/11 01:01:10 | 001,037,278 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Desktop\\adwcleaner.exe
[2013/09/11 01:00:21 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Documents and Settings\\Windows xp\\Desktop\\OTL.exe
[2013/09/11 00:22:34 | 000,001,994 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Desktop\\HiJackThis.lnk
[2013/09/11 00:13:55 | 000,000,211 | -HS- | M] () -- C:\\boot.ini
[2013/09/11 00:13:47 | 000,001,210 | ---- | M] () -- C:\\WINDOWS\\tasks\\HDvid Codec V1-updater.job
[2013/09/11 00:13:44 | 000,002,206 | ---- | M] () -- C:\\WINDOWS\\System32\\wpa.dbl
[2013/09/11 00:13:42 | 000,000,416 | ---- | M] () -- C:\\WINDOWS\\tasks\\AmiUpdXp.job
[2013/09/11 00:13:41 | 000,001,204 | ---- | M] () -- C:\\WINDOWS\\tasks\\HDvid Codec V1-codedownloader.job
[2013/09/11 00:13:36 | 000,001,114 | ---- | M] () -- C:\\WINDOWS\\tasks\\HDvid Codec V1-enabler.job
[2013/09/11 00:13:13 | 000,002,048 | --S- | M] () -- C:\\WINDOWS\\bootstat.dat
[2013/09/11 00:13:11 | 1005,047,808 | -HS- | M] () -- C:\\hiberfil.sys
[2013/09/11 00:13:05 | 000,000,921 | ---- | M] () -- C:\\WINDOWS\\PSNetwork.ini
[2013/09/10 19:11:38 | 000,000,374 | ---- | M] () -- C:\\WINDOWS\\tasks\\Symantec NetDetect.job
[2013/09/10 14:35:00 | 000,001,598 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\快播.lnk
[2013/09/10 14:35:00 | 000,001,586 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Desktop\\快播.lnk
[2013/09/10 14:34:20 | 000,001,572 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\快玩游戏盒.lnk
[2013/09/10 14:34:20 | 000,001,566 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Desktop\\快玩游戏盒.lnk
[2013/09/10 14:33:49 | 000,000,672 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\影视搜索.lnk
[2013/09/10 14:33:45 | 000,000,000 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Desktop\\影视搜索.qvd
[2013/09/10 14:19:13 | 000,000,921 | ---- | M] () -- C:\\WINDOWS\\PowerPlayer.ini
[2013/09/10 14:19:13 | 000,000,148 | ---- | M] () -- C:\\WINDOWS\\PPStream.ini
[2013/09/10 14:19:12 | 000,000,675 | ---- | M] () -- C:\\WINDOWS\\powerlist.ini
[2013/09/07 17:09:03 | 000,000,946 | ---- | M] () -- C:\\WINDOWS\\tasks\\GoogleUpdateTaskUserS-1-5-21-527237240-287218729-725345543-1003Core.job
[2013/09/06 20:12:51 | 000,000,505 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Desktop\\HDPlayer.lnk
[2013/09/06 19:53:31 | 000,000,702 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\PPS游戏.lnk
[2013/09/06 19:52:58 | 000,000,049 | ---- | M] () -- C:\\WINDOWS\\phw.ini
[2013/09/06 19:52:36 | 000,001,136 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Desktop\\百度视频.lnk
[2013/09/06 19:52:36 | 000,000,746 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\PPS影音.lnk
[2013/09/06 19:52:36 | 000,000,728 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Desktop\\PPS影音.lnk
[2013/09/06 18:06:20 | 000,000,282 | ---- | M] () -- C:\\WINDOWS\\tasks\\EPUpdater.job
[2013/09/05 19:48:14 | 000,045,194 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\room_v3.dat
[2013/09/05 17:19:55 | 000,002,341 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\Google Chrome.lnk
[2013/09/05 17:19:54 | 000,002,323 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Desktop\\Google Chrome.lnk
[2013/08/26 20:00:23 | 000,000,664 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Desktop\\Steam.lnk
[2013/08/26 19:59:55 | 001,669,632 | ---- | M] () -- C:\\Documents and Settings\\Windows xp\\Desktop\\SteamInstall.msi
[2013/08/16 13:19:06 | 000,001,374 | ---- | M] () -- C:\\WINDOWS\\imsins.BAK
[2013/08/16 13:09:49 | 000,434,126 | ---- | M] () -- C:\\WINDOWS\\System32\\perfh009.dat
[2013/08/16 13:09:49 | 000,068,412 | ---- | M] () -- C:\\WINDOWS\\System32\\perfc009.dat
[2 C:\\WINDOWS\\*.tmp files -> C:\\WINDOWS\\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/09/11 01:01:23 | 001,037,278 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Desktop\\adwcleaner.exe
[2013/09/11 00:22:34 | 000,001,994 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Desktop\\HiJackThis.lnk
[2013/09/11 00:13:27 | 000,000,296 | ---- | C] () -- C:\\WINDOWS\\tasks\\BrowserDefendert.job
[2013/09/10 14:35:00 | 000,001,598 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\快播.lnk
[2013/09/10 14:35:00 | 000,001,586 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Desktop\\快播.lnk
[2013/09/10 14:34:20 | 000,001,572 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\快玩游戏盒.lnk
[2013/09/10 14:34:20 | 000,001,566 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Desktop\\快玩游戏盒.lnk
[2013/09/10 14:33:49 | 000,000,672 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\影视搜索.lnk
[2013/09/10 14:33:45 | 000,000,000 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Desktop\\影视搜索.qvd
[2013/09/06 20:15:15 | 000,001,210 | ---- | C] () -- C:\\WINDOWS\\tasks\\HDvid Codec V1-updater.job
[2013/09/06 20:15:12 | 000,001,114 | ---- | C] () -- C:\\WINDOWS\\tasks\\HDvid Codec V1-enabler.job
[2013/09/06 20:15:03 | 000,001,204 | ---- | C] () -- C:\\WINDOWS\\tasks\\HDvid Codec V1-codedownloader.job
[2013/09/06 20:12:51 | 000,000,505 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Desktop\\HDPlayer.lnk
[2013/09/06 19:53:31 | 000,000,702 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\PPS游戏.lnk
[2013/09/06 19:53:31 | 000,000,690 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\PPS 游戏.lnk
[2013/09/06 19:53:12 | 000,000,675 | ---- | C] () -- C:\\WINDOWS\\powerlist.ini
[2013/09/06 19:52:58 | 000,000,049 | ---- | C] () -- C:\\WINDOWS\\phw.ini
[2013/09/06 19:52:37 | 000,000,734 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\PPS 影音.lnk
[2013/09/06 19:52:36 | 000,001,136 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Desktop\\百度视频.lnk
[2013/09/06 19:52:36 | 000,000,746 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\PPS影音.lnk
[2013/09/06 19:52:36 | 000,000,728 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Desktop\\PPS影音.lnk
[2013/09/06 19:52:35 | 000,000,148 | ---- | C] () -- C:\\WINDOWS\\PPStream.ini
[2013/09/06 19:52:26 | 000,000,921 | ---- | C] () -- C:\\WINDOWS\\PSNetwork.ini
[2013/09/06 19:52:26 | 000,000,921 | ---- | C] () -- C:\\WINDOWS\\PowerPlayer.ini
[2013/08/26 20:08:29 | 000,000,282 | ---- | C] () -- C:\\WINDOWS\\tasks\\EPUpdater.job
[2013/08/26 20:07:43 | 000,000,416 | ---- | C] () -- C:\\WINDOWS\\tasks\\AmiUpdXp.job
[2013/08/26 20:00:23 | 000,000,664 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Desktop\\Steam.lnk
[2013/08/26 19:59:35 | 001,669,632 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Desktop\\SteamInstall.msi
[2013/08/08 15:42:36 | 000,045,194 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Application Data\\room_v3.dat
[2013/07/07 21:08:40 | 000,073,728 | ---- | C] () -- C:\\WINDOWS\\System32\\ANPDApi.dll
[2013/07/07 21:08:40 | 000,048,640 | ---- | C] () -- C:\\WINDOWS\\System32\\ANPD64.SYS
[2013/07/07 21:08:40 | 000,029,411 | ---- | C] () -- C:\\WINDOWS\\System32\\ANPD.SYS
[2013/07/07 21:08:36 | 000,014,119 | ---- | C] () -- C:\\WINDOWS\\System32\\RaCoInst.dat
[2013/07/07 08:14:10 | 000,003,072 | ---- | C] () -- C:\\WINDOWS\\System32\\iacenc.dll
[2013/06/28 11:40:52 | 000,000,021 | ---- | C] () -- C:\\WINDOWS\\KwYlx.dat
[2007/12/21 00:27:18 | 000,017,408 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\WebpageIcons.db
[2005/06/15 17:39:48 | 000,049,664 | ---- | C] () -- C:\\Documents and Settings\\Windows xp\\Local Settings\\Application Data\\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2010/04/29 22:31:04 | 000,000,227 | RHS- | M] () -- C:\\WINDOWS\\assembly\\Desktop.ini
[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]
[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32]
[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]
\"\" = %SystemRoot%\\system32\\shdocvw.dll -- [2008/04/14 08:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Apartment
[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32]
\"\" = C:\\WINDOWS\\system32\\wbem\\fastprox.dll -- [2009/02/09 20:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Free
[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32]
\"\" = C:\\WINDOWS\\system32\\wbem\\wbemess.dll -- [2008/04/14 08:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Both
< End of report >