Advertisement
Guest User

Untitled

a guest
Jan 21st, 2017
409
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 83.65 KB | None | 0 0
  1. OTL logfile created on: 1/21/2017 8:23:22 PM - Run 1
  2. OTL by OldTimer - Version 3.2.69.0 Folder = D:\Download\Wala
  3. 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
  4. Internet Explorer (Version = 8.0.7600.16385)
  5. Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
  6.  
  7. 3.47 Gb Total Physical Memory | 2.46 Gb Available Physical Memory | 71.11% Memory free
  8. 6.93 Gb Paging File | 5.85 Gb Available in Paging File | 84.41% Paging File free
  9. Paging file location(s): ?:\pagefile.sys [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 172.69 Gb Total Space | 129.74 Gb Free Space | 75.13% Space Free | Partition Type: NTFS
  13. Drive D: | 292.97 Gb Total Space | 173.06 Gb Free Space | 59.07% Space Free | Partition Type: NTFS
  14. Drive E: | 7.21 Gb Total Space | 4.16 Gb Free Space | 57.66% Space Free | Partition Type: FAT32
  15.  
  16. Computer Name: INTER-X | User Name: STAR | Logged in as Administrator.
  17. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
  18. Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
  19.  
  20. [color=#E56717]========== Processes (SafeList) ==========[/color]
  21.  
  22. PRC - D:\Download\Wala\OTL.exe (OldTimer Tools)
  23. PRC - C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe (Google Inc.)
  24. PRC - C:\Program Files (x86)\Garena Plus\ggdllhost.exe ()
  25. PRC - C:\Windows\SysWOW64\SASrv.exe (Conexant Systems, Inc.)
  26. PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
  27.  
  28.  
  29. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  30.  
  31. MOD - C:\Program Files (x86)\Garena Plus\ggspawn.dll ()
  32. MOD - C:\Program Files (x86)\Garena Plus\ggdllhost.exe ()
  33.  
  34.  
  35. [color=#E56717]========== Services (SafeList) ==========[/color]
  36.  
  37. SRV:[b]64bit:[/b] - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
  38. SRV:[b]64bit:[/b] - (CxAudMsg) -- C:\Windows\SysNative\CxAudMsg64.exe (Conexant Systems Inc.)
  39. SRV:[b]64bit:[/b] - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
  40. SRV:[b]64bit:[/b] - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
  41. SRV - (PAExec) -- C:\Windows\PAExec.exe (Power Admin LLC)
  42. SRV - (tbaseprovisioning) -- C:\Windows\SysWOW64\tbaseprovisioning.exe (Advanced Micro Devices, Inc.)
  43. SRV - (SAService) -- C:\Windows\SysWOW64\SASrv.exe (Conexant Systems, Inc.)
  44. SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Windows (R) Win 7 DDK provider)
  45. SRV - (ZAtheros Bt and Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
  46. SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
  47. SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
  48.  
  49.  
  50. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  51.  
  52. DRV:[b]64bit:[/b] - (ACPIVPC) -- C:\Windows\SysNative\drivers\AcpiVpc.sys (Lenovo Corporation)
  53. DRV:[b]64bit:[/b] - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
  54. DRV:[b]64bit:[/b] - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
  55. DRV:[b]64bit:[/b] - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
  56. DRV:[b]64bit:[/b] - (amdpsp) -- C:\Windows\SysNative\drivers\amdpsp.sys (Advanced Micro Devices, Inc. )
  57. DRV:[b]64bit:[/b] - (amdkmcsp) -- C:\Windows\SysNative\drivers\amdkmcsp.sys (Advanced Micro Devices, Inc. )
  58. DRV:[b]64bit:[/b] - (APXACC) -- C:\Windows\SysNative\drivers\appexDrv.sys (AppEx Networks Corporation)
  59. DRV:[b]64bit:[/b] - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronics Corp.)
  60. DRV:[b]64bit:[/b] - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Qualcomm Atheros)
  61. DRV:[b]64bit:[/b] - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Qualcomm Atheros)
  62. DRV:[b]64bit:[/b] - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Qualcomm Atheros)
  63. DRV:[b]64bit:[/b] - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Qualcomm Atheros)
  64. DRV:[b]64bit:[/b] - (btath_avdt) -- C:\Windows\SysNative\drivers\btath_avdt.sys (Qualcomm Atheros)
  65. DRV:[b]64bit:[/b] - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Qualcomm Atheros)
  66. DRV:[b]64bit:[/b] - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Qualcomm Atheros)
  67. DRV:[b]64bit:[/b] - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Qualcomm Atheros)
  68. DRV:[b]64bit:[/b] - (CnxtHdAudService) -- C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
  69. DRV:[b]64bit:[/b] - (rtsuvc) -- C:\Windows\SysNative\drivers\rtsuvc.sys (Realtek Semiconductor Corp.)
  70. DRV:[b]64bit:[/b] - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Qualcomm Atheros Communications, Inc.)
  71. DRV:[b]64bit:[/b] - (RSUSBVSTOR) -- C:\Windows\SysNative\drivers\RtsUVStor.sys (Realtek Semiconductor Corp.)
  72. DRV:[b]64bit:[/b] - (amdkmpfd) -- C:\Windows\SysNative\drivers\amdkmpfd.sys (Advanced Micro Devices, Inc.)
  73. DRV:[b]64bit:[/b] - (amd_sata) -- C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices)
  74. DRV:[b]64bit:[/b] - (amd_xata) -- C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices)
  75. DRV:[b]64bit:[/b] - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
  76. DRV:[b]64bit:[/b] - (amdxhc) -- C:\Windows\SysNative\drivers\amdxhc.sys (Advanced Micro Devices, INC.)
  77. DRV:[b]64bit:[/b] - (amdhub30) -- C:\Windows\SysNative\drivers\amdhub30.sys (Advanced Micro Devices, INC.)
  78. DRV:[b]64bit:[/b] - (Revoflt) -- C:\Windows\SysNative\drivers\revoflt.sys (VS Revo Group)
  79. DRV:[b]64bit:[/b] - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
  80. DRV:[b]64bit:[/b] - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
  81. DRV:[b]64bit:[/b] - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
  82. DRV:[b]64bit:[/b] - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
  83. DRV:[b]64bit:[/b] - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
  84. DRV:[b]64bit:[/b] - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
  85. DRV:[b]64bit:[/b] - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
  86. DRV:[b]64bit:[/b] - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
  87. DRV:[b]64bit:[/b] - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
  88. DRV:[b]64bit:[/b] - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
  89. DRV:[b]64bit:[/b] - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
  90. DRV:[b]64bit:[/b] - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
  91. DRV - (HWiNFO32) -- C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS (REALiX(tm))
  92. DRV - (ISODrive) -- C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys (EZB Systems, Inc.)
  93. DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
  94.  
  95.  
  96. [color=#E56717]========== Standard Registry (All) ==========[/color]
  97.  
  98.  
  99. [color=#E56717]========== Internet Explorer ==========[/color]
  100.  
  101. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
  102. IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  103. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  104. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
  105. IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  106. IE - HKLM\..\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  107.  
  108. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
  109. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  110. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
  111. IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  112. IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  113. IE - HKCU\..\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
  114. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  115.  
  116. [color=#E56717]========== FireFox ==========[/color]
  117.  
  118. FF - prefs.js..browser.search.countryCode: "ID"
  119. FF - prefs.js..browser.search.hiddenOneOffs: "Yahoo,Bing,Twitter"
  120. FF - prefs.js..browser.search.region: "ID"
  121. FF - prefs.js..browser.search.suggest.enabled: false
  122. FF - prefs.js..browser.search.update: false
  123. FF - prefs.js..browser.startup.homepage: "www.google.com/"
  124. FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:50.1.0
  125. FF - user.js - File not found
  126.  
  127. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
  128. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
  129. FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
  130. FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
  131. FF - HKLM\Software\MozillaPlugins\@t.garena.com/garenatalk: C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena)
  132. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll (Google Inc.)
  133. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll (Google Inc.)
  134. FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
  135.  
  136.  
  137. [2016/11/08 12:32:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\STAR\AppData\Roaming\Mozilla\Extensions
  138. [2017/01/15 14:00:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\STAR\AppData\Roaming\Mozilla\Firefox\Profiles\wjkodrl9.default\extensions
  139. [2017/01/15 13:28:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
  140.  
  141. [color=#E56717]========== Chrome ==========[/color]
  142.  
  143. CHR - plugin: Error reading preferences file
  144. CHR - Extension: No name found = C:\Users\STAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcnofaichneijfbkdkghmhjjbepjmble\1.22_0\
  145. CHR - Extension: No name found = C:\Users\STAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\gagfkmknmijppikpcikmbbkdkhggcmge\1.115_0\
  146. CHR - Extension: No name found = C:\Users\STAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgblnfidahcdcjddiepkckcfdhpknnjh\1.384_0\
  147. CHR - Extension: No name found = C:\Users\STAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\omghfjlpggmjjaagoclmmobgdodcjboh\3.9.0_0\
  148. CHR - Extension: No name found = C:\Users\STAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\
  149.  
  150. O1 HOSTS File: ([2016/12/12 01:46:05 | 000,000,826 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  151. O2:[b]64bit:[/b] - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
  152. O2:[b]64bit:[/b] - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
  153. O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
  154. O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - No CLSID value found.
  155. O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
  156. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  157. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
  158. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
  159. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
  160. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: BtvStack = "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" (Qualcomm®Atheros®)
  161. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
  162. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  163. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
  164. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
  165. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
  166. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
  167. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
  168. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
  169. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
  170. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
  171. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
  172. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
  173. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
  174. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
  175. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
  176. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
  177. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
  178. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
  179. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
  180. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
  181. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
  182. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
  183. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
  184. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
  185. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
  186. O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
  187. O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
  188. O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
  189. O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
  190. O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
  191. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
  192. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  193. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
  194. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
  195. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  196. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  197. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
  198. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  199. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  200. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  201. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  202. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  203. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  204. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  205. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  206. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  207. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  208. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  209. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  210. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  211. O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
  212. O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  213. O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
  214. O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
  215. O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  216. O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  217. O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
  218. O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  219. O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  220. O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  221. O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  222. O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  223. O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  224. O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  225. O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  226. O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  227. O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  228. O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  229. O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  230. O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  231. O13[b]64bit:[/b] - gopher Prefix: missing
  232. O13 - gopher Prefix: missing
  233. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 180.250.13.50 180.250.13.54
  234. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF9EC984-A0B1-467B-9AA2-297EE3E264ED}: DhcpNameServer = 180.250.13.50 180.250.13.54
  235. O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  236. O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  237. O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  238. O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  239. O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  240. O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
  241. O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  242. O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  243. O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  244. O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  245. O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  246. O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  247. O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
  248. O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  249. O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
  250. O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  251. O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  252. O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  253. O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  254. O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
  255. O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  256. O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  257. O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  258. O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  259. O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  260. O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
  261. O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  262. O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  263. O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  264. O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  265. O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  266. O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  267. O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
  268. O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  269. O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
  270. O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  271. O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  272. O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  273. O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  274. O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
  275. O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  276. O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  277. O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  278. O18:[b]64bit:[/b] - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  279. O18:[b]64bit:[/b] - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  280. O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
  281. O18:[b]64bit:[/b] - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
  282. O18:[b]64bit:[/b] - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
  283. O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  284. O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  285. O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  286. O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  287. O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  288. O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
  289. O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
  290. O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
  291. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
  292. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  293. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
  294. O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
  295. O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
  296. O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
  297. O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  298. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  299. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No CLSID value found.
  300. O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
  301. O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
  302. O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
  303. O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
  304. O30:[b]64bit:[/b] - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
  305. O30:[b]64bit:[/b] - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
  306. O30:[b]64bit:[/b] - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
  307. O30:[b]64bit:[/b] - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
  308. O30:[b]64bit:[/b] - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
  309. O30:[b]64bit:[/b] - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
  310. O30:[b]64bit:[/b] - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
  311. O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
  312. O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
  313. O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
  314. O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
  315. O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
  316. O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
  317. O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
  318. O31 - SafeBoot: AlternateShell - cmd.exe
  319. O32 - HKLM CDRom: AutoRun - 1
  320. O32 - AutoRun File - [2017/01/09 15:51:14 | 000,000,000 | RHSD | M] - E:\autorun.inf -- [ FAT32 ]
  321. O33 - MountPoints2\{305234bf-74f8-11e6-ac09-507b9d50ce90}\Shell - "" = AutoRun
  322. O33 - MountPoints2\{305234bf-74f8-11e6-ac09-507b9d50ce90}\Shell\AutoRun\command - "" = E:\autorun.exe
  323. O33 - MountPoints2\{69961ff1-983d-11e6-9507-3052cb63af2e}\Shell - "" = AutoRun
  324. O33 - MountPoints2\{69961ff1-983d-11e6-9507-3052cb63af2e}\Shell\AutoRun\command - "" = E:\Lenovo_Suite.exe
  325. O34 - HKLM BootExecute: (autocheck autochk *)
  326. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  327. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  328. O35 - HKLM\..comfile [open] -- "%1" %*
  329. O35 - HKLM\..exefile [open] -- "%1" %*
  330. O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
  331. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  332. O37 - HKLM\...com [@ = comfile] -- "%1" %*
  333. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  334. O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
  335. O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
  336. O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
  337.  
  338. [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
  339.  
  340. [2017/01/20 15:37:06 | 000,000,000 | ---D | C] -- C:\Users\STAR\Documents\KONAMI
  341. [2017/01/20 15:09:18 | 000,000,000 | ---D | C] -- C:\ProgramData\KONAMI
  342. [2017/01/20 15:09:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KONAMI
  343. [2017/01/20 14:57:05 | 000,000,000 | ---D | C] -- C:\Users\STAR\Documents\TecmoKoei
  344. [2017/01/20 14:57:05 | 000,000,000 | ---D | C] -- C:\Users\STAR\Documents\NFS Most Wanted
  345. [2017/01/20 14:57:05 | 000,000,000 | ---D | C] -- C:\Users\STAR\Documents\My Games
  346. [2017/01/20 14:55:15 | 000,000,000 | ---D | C] -- C:\AdwCleaner
  347. [2017/01/20 14:50:44 | 000,000,000 | ---D | C] -- C:\Users\STAR\Documents\Bluetooth Folder
  348. [2017/01/19 21:50:41 | 000,000,000 | ---D | C] -- C:\Users\STAR\AppData\Local\FSOFT_Installer_Company_E
  349. [2017/01/19 20:31:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Logs
  350. [2017/01/19 20:31:09 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
  351. [2017/01/17 20:04:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Qualcomm Atheros
  352. [2017/01/17 20:04:06 | 004,060,672 | ---- | C] (Qualcomm Atheros Communications, Inc.) -- C:\Windows\SysNative\drivers\athrx.sys
  353. [2017/01/17 20:04:06 | 004,060,672 | ---- | C] (Qualcomm Atheros Communications, Inc.) -- C:\Windows\SysNative\athrx.sys
  354. [2017/01/17 20:04:06 | 000,000,000 | ---D | C] -- C:\Windows\Options
  355. [2017/01/17 20:03:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Qualcomm Atheros
  356. [2017/01/15 23:20:47 | 000,594,432 | ---- | C] (Realtek Semiconductor Corp. ) -- C:\Windows\SysNative\Rtlihvs.dll
  357. [2017/01/15 23:20:41 | 000,454,360 | ---- | C] (Realtek) -- C:\Windows\SwUSB.exe
  358. [2017/01/15 13:28:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
  359. [2017/01/13 19:34:42 | 000,000,000 | ---D | C] -- C:\Users\STAR\AppData\Local\CEF
  360. [2017/01/13 19:18:22 | 000,992,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ucrtbase.dll
  361. [2017/01/13 19:18:22 | 000,921,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ucrtbase.dll
  362. [2017/01/10 21:07:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\USB 7908 Wheel
  363. [2017/01/10 21:05:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
  364. [2017/01/10 21:05:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\USB Vibration
  365. [2017/01/01 14:10:55 | 000,000,000 | ---D | C] -- C:\Windows\Migration
  366. [2017/01/01 11:41:20 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe
  367. [2017/01/01 11:41:20 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe
  368. [2017/01/01 09:05:39 | 005,503,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
  369. [2017/01/01 09:05:39 | 003,963,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
  370. [2017/01/01 09:05:39 | 003,908,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
  371. [2017/01/01 09:05:39 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
  372. [2017/01/01 09:05:38 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
  373. [2017/01/01 09:05:38 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
  374. [2017/01/01 09:02:37 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EOSNotify.exe
  375. [2016/12/31 18:52:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
  376. [2016/12/31 18:51:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
  377. [2016/12/31 18:50:11 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIRibbonRes.dll
  378. [2016/12/31 18:50:11 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIRibbonRes.dll
  379. [2016/12/31 18:50:10 | 003,860,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIRibbon.dll
  380. [2016/12/31 18:50:10 | 002,983,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIRibbon.dll
  381. [2016/12/31 18:48:08 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
  382. [2016/12/31 18:48:08 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
  383. [2016/12/31 18:48:07 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
  384. [2016/12/31 18:48:07 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
  385. [2016/12/31 18:48:07 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
  386. [2016/12/31 18:48:06 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
  387. [2016/12/31 18:48:06 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
  388. [2016/12/31 18:06:40 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
  389. [2016/12/31 18:06:40 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
  390. [2016/12/31 18:06:40 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
  391. [2016/12/31 18:06:34 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
  392. [2016/12/31 18:06:34 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
  393. [2016/12/31 18:06:34 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
  394. [2016/12/31 18:06:29 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
  395. [2016/12/31 18:06:29 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
  396. [2016/12/31 17:53:31 | 000,000,000 | ---D | C] -- C:\Users\STAR\AppData\Local\Windows Live
  397. [2016/12/31 17:53:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
  398. [2016/12/25 12:43:00 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
  399. [2016/12/25 12:36:22 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
  400. [2016/12/25 12:35:02 | 000,000,000 | ---D | C] -- C:\Users\STAR\AppData\Roaming\Macromedia
  401. [8 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
  402. [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
  403.  
  404. [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
  405.  
  406. [2017/01/21 19:59:26 | 000,016,944 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  407. [2017/01/21 19:59:26 | 000,016,944 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  408. [2017/01/21 19:59:24 | 000,783,218 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
  409. [2017/01/21 19:59:24 | 000,661,894 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
  410. [2017/01/21 19:59:24 | 000,121,730 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
  411. [2017/01/21 19:52:13 | 016,563,698 | ---- | M] () -- C:\Windows\SysWow64\rootpa.e2e
  412. [2017/01/21 19:52:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
  413. [2017/01/21 19:52:02 | 2790,547,456 | -HS- | M] () -- C:\hiberfil.sys
  414. [2017/01/21 13:27:42 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\spu_storage.bin
  415. [2017/01/20 19:02:09 | 000,001,760 | ---- | M] () -- C:\Users\STAR\Desktop\settings - Shortcut.lnk
  416. [2017/01/20 15:30:50 | 000,001,745 | ---- | M] () -- C:\Users\STAR\Desktop\pes2013 - Shortcut.lnk
  417. [2017/01/19 17:52:50 | 000,007,606 | ---- | M] () -- C:\Users\STAR\AppData\Local\Resmon.ResmonCfg
  418. [2017/01/18 11:56:37 | 000,000,526 | RHS- | M] () -- C:\ProgramData\ntuser.pol
  419. [2017/01/15 13:45:48 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
  420. [2017/01/15 13:28:06 | 000,001,143 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
  421. [2017/01/13 19:18:19 | 000,992,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ucrtbase.dll
  422. [2017/01/13 19:18:19 | 000,921,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ucrtbase.dll
  423. [2017/01/13 19:11:41 | 000,000,359 | ---- | M] () -- C:\Users\STAR\Desktop\Recycle Bin - Shortcut.lnk
  424. [2017/01/12 15:15:30 | 000,001,362 | ---- | M] () -- C:\Users\STAR\Desktop\AIMP3 - Shortcut.lnk
  425. [2017/01/09 08:27:59 | 000,000,755 | ---- | M] () -- C:\Users\STAR\Desktop\SBK2001 - Shortcut.lnk
  426. [2017/01/01 16:00:13 | 000,412,296 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
  427. [2016/12/31 19:07:51 | 000,001,305 | ---- | M] () -- C:\Users\STAR\Desktop\Movie Maker.lnk
  428. [2016/12/31 18:52:16 | 000,000,020 | ---- | M] () -- C:\Windows\¸õ'
  429. [2016/12/25 12:55:42 | 000,000,923 | ---- | M] () -- C:\Users\STAR\Desktop\Adobe InDesign CC 2015.lnk
  430. [2016/12/23 22:21:11 | 000,001,121 | ---- | M] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
  431. [2016/12/23 22:21:11 | 000,000,942 | ---- | M] () -- C:\Users\Public\Desktop\AMD Quick Stream.lnk
  432. [2016/12/23 22:21:11 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
  433. [8 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
  434. [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
  435.  
  436. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  437.  
  438. [2017/01/20 19:02:09 | 000,001,760 | ---- | C] () -- C:\Users\STAR\Desktop\settings - Shortcut.lnk
  439. [2017/01/20 15:30:50 | 000,001,745 | ---- | C] () -- C:\Users\STAR\Desktop\pes2013 - Shortcut.lnk
  440. [2017/01/17 20:04:06 | 000,643,699 | ---- | C] () -- C:\Windows\SysNative\netathrx.inf
  441. [2017/01/17 20:04:06 | 000,091,822 | ---- | C] () -- C:\Windows\SysNative\athrextx.cat
  442. [2017/01/15 23:20:41 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
  443. [2017/01/15 23:20:41 | 000,044,760 | ---- | C] () -- C:\Windows\runSW.exe
  444. [2017/01/15 13:28:06 | 000,001,143 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
  445. [2017/01/13 21:20:14 | 000,007,606 | ---- | C] () -- C:\Users\STAR\AppData\Local\Resmon.ResmonCfg
  446. [2017/01/13 19:11:41 | 000,000,359 | ---- | C] () -- C:\Users\STAR\Desktop\Recycle Bin - Shortcut.lnk
  447. [2017/01/12 15:15:30 | 000,001,362 | ---- | C] () -- C:\Users\STAR\Desktop\AIMP3 - Shortcut.lnk
  448. [2017/01/09 08:27:59 | 000,000,755 | ---- | C] () -- C:\Users\STAR\Desktop\SBK2001 - Shortcut.lnk
  449. [2016/12/31 19:07:51 | 000,001,305 | ---- | C] () -- C:\Users\STAR\Desktop\Movie Maker.lnk
  450. [2016/12/31 18:56:12 | 000,001,305 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
  451. [2016/12/31 18:56:05 | 000,001,374 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
  452. [2016/12/31 18:52:15 | 000,000,020 | ---- | C] () -- C:\Windows\¸õ'
  453. [2016/12/25 12:55:42 | 000,000,923 | ---- | C] () -- C:\Users\STAR\Desktop\Adobe InDesign CC 2015.lnk
  454. [2016/12/25 12:42:45 | 000,000,923 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign CC 2015.lnk
  455. [2016/12/25 12:36:15 | 000,001,526 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
  456. [2016/11/16 18:49:40 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
  457. [2016/09/27 04:05:17 | 000,000,021 | ---- | C] () -- C:\Windows\SysWow64\Config.ini
  458. [2016/08/16 11:09:31 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
  459. [2016/08/14 22:31:20 | 000,000,526 | RHS- | C] () -- C:\ProgramData\ntuser.pol
  460. [2016/08/12 20:55:33 | 000,758,128 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
  461. [2016/03/21 20:54:22 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
  462. [2016/03/21 20:54:22 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
  463. [2016/03/21 20:49:46 | 000,186,368 | ---- | C] () -- C:\Windows\SysWow64\GameManager32.dll
  464. [2016/03/21 20:49:44 | 000,145,408 | ---- | C] () -- C:\Windows\SysWow64\atieah32.exe
  465. [2016/03/21 20:49:42 | 000,189,952 | ---- | C] () -- C:\Windows\SysWow64\amdgfxinfo32.dll
  466. [2016/03/21 20:44:14 | 000,174,592 | ---- | C] () -- C:\Windows\SysWow64\hsa-thunk.dll
  467. [2016/02/10 05:20:18 | 000,002,473 | ---- | C] () -- C:\Windows\SysWow64\tbaseprovisioning.exe.config
  468.  
  469. [color=#E56717]========== ZeroAccess Check ==========[/color]
  470.  
  471. [2009/07/14 11:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
  472.  
  473. [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  474.  
  475. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  476.  
  477. [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
  478.  
  479. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  480.  
  481. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  482. "" = C:\Windows\SysNative\shell32.dll -- [2009/07/14 08:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
  483. "ThreadingModel" = Apartment
  484.  
  485. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  486. "" = %SystemRoot%\system32\shell32.dll -- [2009/07/14 08:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
  487. "ThreadingModel" = Apartment
  488.  
  489. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
  490. "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 08:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
  491. "ThreadingModel" = Free
  492.  
  493. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
  494. "" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 08:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
  495. "ThreadingModel" = Free
  496.  
  497. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
  498. "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 08:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
  499. "ThreadingModel" = Both
  500.  
  501. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
  502.  
  503. [color=#E56717]========== LOP Check ==========[/color]
  504.  
  505. [2016/12/11 12:47:39 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\AIMP3
  506. [2016/09/24 17:17:00 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\BANDISOFT
  507. [2016/10/02 18:59:16 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\DMCache
  508. [2016/11/15 07:32:06 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\Foxit Software
  509. [2016/10/02 20:38:48 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\Garena
  510. [2017/01/18 13:19:45 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\GarenaPlus
  511. [2016/08/14 21:33:46 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\library_dir
  512. [2016/08/22 22:53:26 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\Milestone
  513. [2016/09/14 21:15:03 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\Smadav
  514. [2016/11/27 19:57:16 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\Sony
  515. [2016/08/22 22:53:22 | 000,000,000 | ---D | M] -- C:\Users\STAR\AppData\Roaming\Steam
  516.  
  517. [color=#E56717]========== Purity Check ==========[/color]
  518.  
  519.  
  520.  
  521. < End of report >
  522. OTL Extras logfile created on: 1/21/2017 8:23:22 PM - Run 1
  523. OTL by OldTimer - Version 3.2.69.0 Folder = D:\Download\Wala
  524. 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
  525. Internet Explorer (Version = 8.0.7600.16385)
  526. Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
  527.  
  528. 3.47 Gb Total Physical Memory | 2.46 Gb Available Physical Memory | 71.11% Memory free
  529. 6.93 Gb Paging File | 5.85 Gb Available in Paging File | 84.41% Paging File free
  530. Paging file location(s): ?:\pagefile.sys [binary data]
  531.  
  532. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  533. Drive C: | 172.69 Gb Total Space | 129.74 Gb Free Space | 75.13% Space Free | Partition Type: NTFS
  534. Drive D: | 292.97 Gb Total Space | 173.06 Gb Free Space | 59.07% Space Free | Partition Type: NTFS
  535. Drive E: | 7.21 Gb Total Space | 4.16 Gb Free Space | 57.66% Space Free | Partition Type: FAT32
  536.  
  537. Computer Name: INTER-X | User Name: STAR | Logged in as Administrator.
  538. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
  539. Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
  540.  
  541. [color=#E56717]========== Extra Registry (SafeList) ==========[/color]
  542.  
  543.  
  544. [color=#E56717]========== File Associations ==========[/color]
  545.  
  546. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
  547. .html[@ = htmlfile] -- Reg Error: Key error. File not found
  548. .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
  549.  
  550. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
  551. .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
  552. .html [@ = htmlfile] -- Reg Error: Key error. File not found
  553.  
  554. [color=#E56717]========== Shell Spawning ==========[/color]
  555.  
  556. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
  557. batfile [open] -- "%1" %*
  558. cmdfile [open] -- "%1" %*
  559. comfile [open] -- "%1" %*
  560. exefile [open] -- "%1" %*
  561. helpfile [open] -- Reg Error: Key error.
  562. htmlfile [open] -- Reg Error: Key error.
  563. htmlfile [opennew] -- Reg Error: Key error.
  564. http [open] -- Reg Error: Key error.
  565. https [open] -- Reg Error: Key error.
  566. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
  567. InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
  568. InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
  569. piffile [open] -- "%1" %*
  570. regfile [merge] -- Reg Error: Key error.
  571. scrfile [config] -- "%1"
  572. scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
  573. scrfile [open] -- "%1" /S
  574. txtfile [edit] -- Reg Error: Key error.
  575. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
  576. Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
  577. Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
  578. Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  579. Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
  580. Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  581. Folder [explore] -- Reg Error: Value error.
  582. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  583. Applications\iexplore.exe [open] -- Reg Error: Key error.
  584. CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
  585.  
  586. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
  587. batfile [open] -- "%1" %*
  588. cmdfile [open] -- "%1" %*
  589. comfile [open] -- "%1" %*
  590. cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
  591. exefile [open] -- "%1" %*
  592. helpfile [open] -- Reg Error: Key error.
  593. htmlfile [open] -- Reg Error: Key error.
  594. htmlfile [opennew] -- Reg Error: Key error.
  595. http [open] -- Reg Error: Key error.
  596. https [open] -- Reg Error: Key error.
  597. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
  598. piffile [open] -- "%1" %*
  599. regfile [merge] -- Reg Error: Key error.
  600. scrfile [config] -- "%1"
  601. scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
  602. scrfile [open] -- "%1" /S
  603. txtfile [edit] -- Reg Error: Key error.
  604. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
  605. Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
  606. Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
  607. Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  608. Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
  609. Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  610. Folder [explore] -- Reg Error: Value error.
  611. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  612. Applications\iexplore.exe [open] -- Reg Error: Key error.
  613. CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
  614.  
  615. [color=#E56717]========== Security Center Settings ==========[/color]
  616.  
  617. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
  618. "cval" = 1
  619.  
  620. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
  621.  
  622. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
  623. "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
  624. "AntiVirusOverride" = 0
  625. "AntiSpywareOverride" = 0
  626. "FirewallOverride" = 0
  627.  
  628. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
  629.  
  630. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
  631.  
  632. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
  633.  
  634. [color=#E56717]========== Firewall Settings ==========[/color]
  635.  
  636. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
  637. "DisableNotifications" = 0
  638. "EnableFirewall" = 1
  639.  
  640. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
  641. "DisableNotifications" = 0
  642. "EnableFirewall" = 0
  643. "DoNotAllowExceptions" = 0
  644.  
  645. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
  646. "DisableNotifications" = 0
  647. "EnableFirewall" = 0
  648.  
  649. [color=#E56717]========== Authorized Applications List ==========[/color]
  650.  
  651.  
  652. [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]
  653.  
  654. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
  655. "{10D05D5F-24A2-4C06-AAC1-DDF01E1EA21D}" = rport=138 | protocol=17 | dir=out | app=system |
  656. "{35AF9DA6-616F-401B-BFD5-601AAD9A96D5}" = rport=139 | protocol=6 | dir=out | app=system |
  657. "{39D28322-42F5-4506-8E54-C25876C1A201}" = lport=445 | protocol=6 | dir=in | app=system |
  658. "{4E77837C-2652-4626-A92A-D8CEC0380723}" = lport=137 | protocol=17 | dir=in | app=system |
  659. "{5A5C9964-0A1E-4B72-9CCD-18E9DC902363}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
  660. "{A364244F-01E2-4B75-BEDD-998C3FF73333}" = lport=139 | protocol=6 | dir=in | app=system |
  661. "{C144D56E-6B4B-47A7-A328-A79A76A0A252}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
  662. "{C4E43DC3-30B0-4CF8-8211-034D0FD5E601}" = rport=445 | protocol=6 | dir=out | app=system |
  663. "{D6A52E2F-9EDE-44FD-A7DF-08DCF3F46AF6}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
  664. "{D87982B4-983F-44D3-958B-DE4FCFDBEB35}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
  665. "{DD4C8CDC-AA97-4A44-A1B2-6D9B075A0F89}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
  666. "{E7FE149E-7BEF-450C-92E2-56144FF0404E}" = rport=137 | protocol=17 | dir=out | app=system |
  667. "{F3EEA665-84DD-49FD-B5BD-33B1025B55EF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
  668. "{F7C9F9B9-3551-48B1-B4AF-00F656F511E1}" = lport=138 | protocol=17 | dir=in | app=system |
  669. "{FC1F8285-27E8-4CB7-B3C8-7967F6A58895}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
  670.  
  671. [color=#E56717]========== Vista Active Application Exception List ==========[/color]
  672.  
  673. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
  674. "{085BE3C0-DBC6-4B07-8820-A4FFB9590FA9}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
  675. "{15E2BE85-CBFF-4BBF-A7D8-20377582515B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
  676. "{1A81B0E1-AC36-4B91-8316-2D09BEB87533}" = dir=in | app=c:\program files (x86)\formatfactory\formatfactory.exe |
  677. "{1DFA6AC4-F282-45D7-99CB-E335F36A9CE3}" = dir=in | app=c:\program files (x86)\formatfactory\formatfactory.exe |
  678. "{2E2DE798-6C81-4EC4-A4E4-724CD6F1A681}" = dir=in | app=c:\program files (x86)\formatfactory\ffmodules\encoder\doc\ebookcodec.exe |
  679. "{384DDD15-CB28-4A4E-A4A1-3FEC355DFADC}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
  680. "{3C4A2A2D-C2C0-46AF-9E97-9AF077BA0F26}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
  681. "{5EE6998B-E7FA-4E63-8959-73C1515A9A38}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
  682. "{8612CC40-E149-4900-A270-F0DD2E85DFE2}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
  683. "{8A49F839-9EAC-40F0-AFFA-6E69AC888BB7}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
  684. "{A5C3257C-63BF-484E-99D6-7AE9D7F3F0E4}" = dir=in | app=c:\program files (x86)\formatfactory\ffmodules\package\ptinstonline.exe |
  685. "{AD29D1FA-BF6D-46CD-9C21-B9AF9B9BC782}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
  686. "{BC6E7806-448A-49B0-AC06-3D3914D5D9B5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
  687. "{C26DF17C-3928-4695-9D14-6B304C1BC079}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
  688. "{DCB2E38F-8AD5-477A-858D-2F21F0046002}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
  689. "{E395444F-7F83-4285-B2C5-41876382D946}" = dir=in | app=c:\program files (x86)\formatfactory\ffmodules\encoder\doc\ebookcodec.exe |
  690.  
  691. [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
  692.  
  693. 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
  694. "{02896948-D46A-3B60-9700-2A2BD94B729E}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23725 False
  695. "{02A39130-2CF3-30CA-8623-30F6071A4221}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
  696. "{04918523-F4D6-EABC-54A8-C66B575E3F92}" = Catalyst Control Center Next Localization PL
  697. "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable - x64 8.0.56336 False
  698. "{092D3585-7D69-E4E2-09CF-01112B1FEDCA}" = Catalyst Control Center Next Localization DE
  699. "{0D3E9E15-DE7A-300B-96F1-B4AF12B96488}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23026 False
  700. "{12A2F80A-9598-FF88-3299-4B34C49950E3}" = Catalyst Control Center Next Localization SV
  701. "{18B55E30-984B-99A6-8F1A-8450EF4046E1}" = Catalyst Control Center Next Localization HU
  702. "{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}" = Microsoft .NET Framework 4.5
  703. "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219
  704. "{1DEF7544-8B09-EB60-5A62-18DDFD4DAD7B}" = Catalyst Control Center Next Localization DA
  705. "{26EDA845-F642-9AEF-5CA3-F71B61171B84}" = Catalyst Control Center Next Localization TH
  706. "{2DFD8316-9EF1-3210-908C-4CB61961C1AC}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.0 False
  707. "{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 False
  708. "{2F2039FD-8F16-C88F-8A17-5C5CF388401C}" = Catalyst Control Center Next Localization CHS
  709. "{30BB8D4E-ED05-EBB8-16C4-E3081753B473}" = Catalyst Control Center Next Localization ES
  710. "{3300B9C3-E57A-97E5-8C3A-C5ADDBEB7200}" = AMD Wireless Display v3.0
  711. "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 False
  712. "{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
  713. "{3C28BFD4-90C7-3138-87EF-418DC16E9598}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 False
  714. "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 False
  715. "{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 False
  716. "{51D587F8-761D-1615-7E03-38C690EFEE77}" = AMD Install Manager
  717. "{52E56CE8-7EE5-9E6D-76A0-B11C8CAD6A16}" = Catalyst Control Center Next Localization FI
  718. "{5AF4E09F-5C9B-3AAF-B731-544D3DC821DD}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 False
  719. "{5CBC7592-303E-3F1B-AB4A-41BEE3D23391}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23829 False
  720. "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
  721. "{632072AD-805F-7B17-596F-5A0A2E24CC50}" = Catalyst Control Center Next Localization BR
  722. "{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 3.1.7
  723. "{68016585-4209-40EC-A3F8-5A5B0DD72BDC}" = AMD Radeon Settings
  724. "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable - x64 8.0.59192 False
  725. "{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable - x64 8.0.50727.42 False
  726. "{705287FE-F66C-8B2E-2144-BF20E3646B9E}" = Catalyst Control Center Next Localization RU
  727. "{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 False
  728. "{78ACE60E-0CB7-4935-BCD4-F33422105607}" = AMD Settings - Branding
  729. "{7B50D081-E670-3B43-A460-0E2CDB5CE984}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23918
  730. "{80E64FDE-029B-11E2-A955-F04DA23A5C58}" = MSVCRT Redists
  731. "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 False
  732. "{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.5570 False
  733. "{8A825D0E-A918-6140-BAEE-CFCE939FDBD2}" = Catalyst Control Center Next Localization IT
  734. "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
  735. "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
  736. "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
  737. "{91415F19-4C22-3609-A105-92ED3522D83C}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4048 False
  738. "{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
  739. "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
  740. "{94BFDEF9-D91D-4B5D-8A60-08514C7191AF}" = AMD Steady Video Plug-In
  741. "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
  742. "{9DDE7A62-EC12-E773-4ED3-E813CADCEA64}" = Catalyst Control Center Next Localization JA
  743. "{A1C31BA5-5438-3A07-9EEE-A5FB2D0FDE36}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23506 False
  744. "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 False
  745. "{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
  746. "{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64)
  747. "{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable - x64 8.0.51011 False
  748. "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 False
  749. "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000
  750. "{AF4EC442-E1ED-31F1-B082-16F34FD6A97B}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23829 False
  751. "{B0B194F8-E0CE-33FE-AA11-636428A4B73D}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23506 False
  752. "{B4DBE717-BFB3-94BA-478C-032CA537D232}" = Catalyst Control Center Next Localization TR
  753. "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 Redistributable - x64 8.0.50727.4053 False
  754. "{B877D0F8-BE30-EB1F-CA98-14FC7D24B7C6}" = Catalyst Control Center Next Localization CHT
  755. "{BBBE35B2-9349-3C48-BD3D-F574B17C7924}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.218 False
  756. "{BC958BD2-5DAC-3862-BB1A-C1BE0790438D}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23026 False
  757. "{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
  758. "{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
  759. "{D04659D1-EB2D-3DE5-A833-837A623CCCF7}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.0 False
  760. "{D283CABB-2896-B7CE-07FF-E7AD3D4290B5}" = Catalyst Control Center Next Localization FR
  761. "{D716F34D-48F3-6EA4-0F9D-B45FC4DBB8E1}" = Catalyst Control Center Next Localization NO
  762. "{D93AC9C8-B6CF-391E-BD2F-48AF4727476C}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30411 False
  763. "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 Redistributable - x64 10.0.30319 False
  764. "{DC50AC79-764F-6844-D818-755DC1994385}" = Catalyst Control Center Next Localization CS
  765. "{DFFEB619-5455-3697-B145-243D936DB95B}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23918
  766. "{E83CF0B0-CDBB-7F1B-E287-3E8C94B2B43D}" = AMD Drag and Drop Transcoding
  767. "{E903B978-A3E0-FB72-B6F1-CA73A645988A}" = Catalyst Control Center Next Localization NL
  768. "{E993B27E-AB21-3C44-A472-39F1AD3CC78C}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23725 False
  769. "{E9EED4AE-682B-4501-9574-D09A21717599}_is1" = AMD Quick Stream
  770. "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
  771. "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148.0 False
  772. "{f0cbd694-71ce-4391-9690-5da93b2f0445}" = Microsoft Visual C++ 2005 Redistributable - x64 8.0.57102 False
  773. "{f45b48a7-f616-4211-b927-17cab6a96613}" = Microsoft Visual C++ 2005 Redistributable - x64 8.0.58298 False
  774. "{F73A10DC-3F0E-6EFF-6A0D-DD78866196A6}" = Catalyst Control Center Next Localization KO
  775. "{FE015140-7E94-2E3A-9BF2-FA952DEF7950}" = Catalyst Control Center Next Localization EL
  776. "AMD Catalyst Install Manager" = AMD Install Manager
  777. "CCleaner" = CCleaner
  778. "CNXT_AUDIO_HDA" = Conexant HD Audio
  779. "VLC media player" = VLC media player
  780.  
  781. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
  782. "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148.0 False
  783. "{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}" = Windows Live UX Platform
  784. "{01db25f3-1b76-4d97-88c8-1c90634d88fb}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 False
  785. "{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 False Eng
  786. "{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable - x86 8.0.58299 False
  787. "{07AAB66E-4718-422D-9218-4AFB3C922A71}" = Photo Gallery
  788. "{0f12c81f-93ef-46ec-bc94-d952c1a775d4}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 False
  789. "{1045AB6F-6151-3634-8C2C-EE308AA1A6A7}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23506 False
  790. "{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
  791. "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 False Eng
  792. "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 Redistributable - x86 10.0.30319 False
  793. "{1a63c099-febd-4eaf-83ad-a82ea4fdac49}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
  794. "{1ADB5065-6053-412D-9E6C-8A62FE6704B8}" = AyoDance
  795. "{1BBDD6C0-ED6F-43C3-8A9C-84E3249A5615}" = Twin USB Vibration Gamepad
  796. "{1C8C353D-498B-3B8B-A3DC-41519413F733}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23725 False
  797. "{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}" = Windows Live Photo Common
  798. "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 False
  799. "{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 False Eng
  800. "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros Client Installation Program
  801. "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 False
  802. "{3039577D-975E-42fc-89FC-2F1FF42F3FCA}_is1" = Aiseesoft HD Video Converter 8.2.6
  803. "{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 False Eng
  804. "{35459b22-19a6-44ec-8d34-27eb3131acac}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 False
  805. "{38F03569-A636-4CF3-BDDE-032C8C251304}" = Movie Maker
  806. "{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 False
  807. "{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 False
  808. "{41C61308-6CFD-4D54-AB6A-7136ED08A18E}" = Windows Live Communications Platform
  809. "{4999B2F1-3E74-409A-B8B5-E94448AA9EA6}" = USB Vibration Joystick
  810. "{4AA8C8A9-FEE7-5FD6-FCCA-4A89CC9EC9D3}" = OEM Application Profile
  811. "{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.0 False
  812. "{5B1F2843-B379-3FF2-B0D3-64DD143ED53A}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048 False
  813. "{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}" = Realtek Card Reader
  814. "{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 False
  815. "{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
  816. "{615bc16d-60f5-482e-91b3-b51d8130963b}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 False
  817. "{6522F5F9-411B-4513-A75B-CEA00395F032}" = Windows Live UX Platform Language Pack
  818. "{659CB81C-B54E-4DF1-B618-F35777393A54}" = Windows Live Installer
  819. "{65AD78AD-D23D-3A1E-9305-3AE65CD522C2}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23506 False
  820. "{66B5819D-DE70-42BE-B40F-978FBA12452E}" = Windows Live Essentials
  821. "{6ADA7E88-8D16-4D0D-BC90-2B93AC5E56DA}" = LenovoUtility
  822. "{6C772996-BFF3-3C8C-860B-B3D48FF05D65}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 False
  823. "{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 False
  824. "{6e8f74e0-43bd-4dce-8477-6ff6828acc07}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 False Eng
  825. "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001
  826. "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable - x86 8.0.56336 False
  827. "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 Redistributable - x86 8.0.50727.4053 False
  828. "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable - x86 8.0.59193 False
  829. "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.5570 False
  830. "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
  831. "{8BE670DF-EA47-3A15-88CC-00FFCA1FFA12}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23829 False
  832. "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
  833. "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
  834. "{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 False Eng
  835. "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
  836. "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
  837. "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
  838. "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
  839. "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
  840. "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
  841. "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
  842. "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
  843. "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
  844. "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
  845. "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
  846. "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
  847. "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
  848. "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
  849. "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
  850. "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
  851. "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
  852. "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
  853. "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
  854. "{9436D9AB-3BB9-3A1B-84AE-6F29B2098BD0}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23725 False
  855. "{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 False Eng
  856. "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 False
  857. "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
  858. "{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - x86 8.0.51011 False
  859. "{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 False Eng
  860. "{a2199617-3609-410f-a8e8-e8806c73545b}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
  861. "{A2563E55-3BEC-3828-8D67-E5E8B9E8B675}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026 False
  862. "{A483F88A-41E9-45B2-AAC9-A823DD9B4873}" = PS TO PC CONVERTER
  863. "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable - x86 8.0.50727.42 False
  864. "{AC768037-7079-4658-AC24-2897650E0ABE}" = Energy Manager
  865. "{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
  866. "{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}" = Windows Live PIMT Platform
  867. "{b55f7208-e02b-4828-ac78-59c73ddf5bc7}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
  868. "{B5FC62F5-A367-37A5-9FD2-A6E137C0096F}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23918
  869. "{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}" = Dolby Advanced Audio v2
  870. "{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
  871. "{BD9CFD69-EB91-354E-9C98-D439E6091932}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23918
  872. "{BE960C1C-7BAD-3DE6-8B1A-2616FE532845}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026 False
  873. "{C2523AE6-F335-4D0B-BC15-1C07E4ACE629}" = Pro Evolution Soccer 2013
  874. "{C992FFE0-AC32-4FA9-BC9A-F1637B9E655D}" = Photo Gallery
  875. "{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 False Eng
  876. "{CAA0F57A-BA8C-4AD8-AA03-F32B0E4F5623}" = Photo Common
  877. "{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}" = Windows Live SOXE
  878. "{D1495983-5903-358E-8C91-62A6731C1ED6}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23829 False
  879. "{D1893000-EA77-493C-8DDD-E262436E959B}" = Windows Live SOXE Definitions
  880. "{D5778AE9-6376-4CE6-AD4A-8712F4EC3302}" = USB Force Wheel
  881. "{d8fea624-4f2c-432d-9a54-6eee9cd1a77e}" = Microsoft Visual C++ 2005 Redistributable - x86 8.0.57103 False
  882. "{DBFD0312-6E55-1014-8952-E78D43BC0147}" = Adobe InDesign CC 2015
  883. "{DCB46B42-723F-350E-B18A-449BC6C21636}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.0 False
  884. "{DD67BE4B-7E62-4215-AFA3-F123A800A389}" = Movie Maker
  885. "{dde2682b-961a-41ea-8d44-6005991b7947}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 False
  886. "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
  887. "{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}" = Lenovo EasyCamera
  888. "{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 False
  889. "{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 False
  890. "{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 False
  891. "{E9CE0867-D39A-F2BE-C328-D1FCC32EED4D}" = AMD Settings
  892. "{f0080ca2-80ae-4958-b6eb-e8fa916d744a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
  893. "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
  894. "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219
  895. "{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 False Eng
  896. "{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
  897. "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 False
  898. "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 False
  899. "AIMP3" = AIMP3
  900. "Bandicam" = Bandicam
  901. "BandiMPEG1" = Bandisoft MPEG-1 Decoder
  902. "ENTERPRISE" = Microsoft Office Enterprise 2007
  903. "FormatFactory" = FormatFactory 3.9.5.0
  904. "Foxit Reader_is1" = Foxit Reader 5.0
  905. "im" = Garena+
  906. "InstallShield_{6ADA7E88-8D16-4D0D-BC90-2B93AC5E56DA}" = LenovoUtility
  907. "InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}" = Energy Manager
  908. "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.2.1.1043
  909. "MotoGP 15_is1" = MotoGP 15
  910. "Mozilla Firefox 50.1.0 (x86 en-US)" = Mozilla Firefox 50.1.0 (x86 en-US)
  911. "UltraISO_is1" = UltraISO Premium V9.36
  912. "Uplay" = Uplay
  913. "WinLiveSuite" = Windows Live Essentials
  914.  
  915. [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
  916.  
  917. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
  918.  
  919. [color=#E56717]========== Last 20 Event Log Errors ==========[/color]
  920.  
  921. [ Application Events ]
  922. Error - 1/20/2017 4:35:17 AM | Computer Name = Inter-X | Source = Application Error | ID = 1000
  923. Description = Faulting application name: tbaseprovisioning.exe, version: 1.0.0.0,
  924. time stamp: 0x56b4dcb7 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
  925. time stamp: 0x4a5bdbdf Exception code: 0xe0434352 Fault offset: 0x0000b727 Faulting
  926. process id: 0x140 Faulting application start time: 0x01d272f81a29db8b Faulting application
  927. path: C:\Windows\SysWOW64\tbaseprovisioning.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
  928. Report
  929. Id: 5e40dbe7-deeb-11e6-8777-3052cb63af2e
  930.  
  931. Error - 1/20/2017 6:03:11 AM | Computer Name = Inter-X | Source = Application Error | ID = 1000
  932. Description = Faulting application name: pes2013.exe, version: 1.4.0.0, time stamp:
  933. 0x515cba25 Faulting module name: ntdll.dll, version: 6.1.7600.16385, time stamp:
  934. 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x0002de64 Faulting process id:
  935. 0x268 Faulting application start time: 0x01d272fb99bf86e0 Faulting application path:
  936. C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2013\pes2013.exe Faulting module
  937. path: C:\Windows\SysWOW64\ntdll.dll Report Id: a6263460-def7-11e6-8777-3052cb63af2e
  938.  
  939. Error - 1/20/2017 7:42:46 AM | Computer Name = Inter-X | Source = .NET Runtime | ID = 1026
  940. Description =
  941.  
  942. Error - 1/20/2017 7:42:59 AM | Computer Name = Inter-X | Source = Application Error | ID = 1000
  943. Description = Faulting application name: tbaseprovisioning.exe, version: 1.0.0.0,
  944. time stamp: 0x56b4dcb7 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
  945. time stamp: 0x4a5bdbdf Exception code: 0xe0434352 Fault offset: 0x0000b727 Faulting
  946. process id: 0x148 Faulting application start time: 0x01d273125142817a Faulting application
  947. path: C:\Windows\SysWOW64\tbaseprovisioning.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
  948. Report
  949. Id: 971441c9-df05-11e6-8234-3052cb63af2e
  950.  
  951. Error - 1/20/2017 7:43:19 AM | Computer Name = Inter-X | Source = Windows Search Service | ID = 1019
  952. Description =
  953.  
  954. Error - 1/21/2017 1:16:44 AM | Computer Name = Inter-X | Source = .NET Runtime | ID = 1026
  955. Description =
  956.  
  957. Error - 1/21/2017 1:16:55 AM | Computer Name = Inter-X | Source = Application Error | ID = 1000
  958. Description = Faulting application name: tbaseprovisioning.exe, version: 1.0.0.0,
  959. time stamp: 0x56b4dcb7 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
  960. time stamp: 0x4a5bdbdf Exception code: 0xe0434352 Fault offset: 0x0000b727 Faulting
  961. process id: 0x144 Faulting application start time: 0x01d273a58dfd4039 Faulting application
  962. path: C:\Windows\SysWOW64\tbaseprovisioning.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
  963. Report
  964. Id: d27cfd20-df98-11e6-9084-3052cb63af2e
  965.  
  966. Error - 1/21/2017 1:20:34 AM | Computer Name = Inter-X | Source = Windows Search Service | ID = 1019
  967. Description =
  968.  
  969. Error - 1/21/2017 8:52:13 AM | Computer Name = INTER-X | Source = .NET Runtime | ID = 1026
  970. Description =
  971.  
  972. Error - 1/21/2017 8:52:25 AM | Computer Name = Inter-X | Source = Application Error | ID = 1000
  973. Description = Faulting application name: tbaseprovisioning.exe, version: 1.0.0.0,
  974. time stamp: 0x56b4dcb7 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
  975. time stamp: 0x4a5bdbdf Exception code: 0xe0434352 Fault offset: 0x0000b727 Faulting
  976. process id: 0x148 Faulting application start time: 0x01d273e52f89b39e Faulting application
  977. path: C:\Windows\SysWOW64\tbaseprovisioning.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
  978. Report
  979. Id: 74664631-dfd8-11e6-9030-3052cb63af2e
  980.  
  981. [ System Events ]
  982. Error - 1/21/2017 1:16:47 AM | Computer Name = Inter-X | Source = Service Control Manager | ID = 7003
  983. Description = The Net.Tcp Listener Adapter service depends the following service:
  984. was. This service might not be installed.
  985.  
  986. Error - 1/21/2017 1:16:53 AM | Computer Name = Inter-X | Source = Service Control Manager | ID = 7026
  987. Description = The following boot-start or system-start driver(s) failed to load:
  988. cdrom
  989.  
  990. Error - 1/21/2017 1:16:55 AM | Computer Name = Inter-X | Source = RemoteAccess | ID = 20152
  991. Description = The currently configured authentication provider failed to load and
  992. initialize successfully. The requested name is valid, but no data of the requested
  993. type was found.
  994.  
  995. Error - 1/21/2017 1:16:55 AM | Computer Name = Inter-X | Source = Service Control Manager | ID = 7034
  996. Description = The tbaseprovisioning service terminated unexpectedly. It has done
  997. this 1 time(s).
  998.  
  999. Error - 1/21/2017 1:16:57 AM | Computer Name = Inter-X | Source = Service Control Manager | ID = 7024
  1000. Description = The Routing and Remote Access service terminated with service-specific
  1001. error %%11004.
  1002.  
  1003. Error - 1/21/2017 8:52:16 AM | Computer Name = Inter-X | Source = Service Control Manager | ID = 7003
  1004. Description = The Net.Msmq Listener Adapter service depends the following service:
  1005. msmq. This service might not be installed.
  1006.  
  1007. Error - 1/21/2017 8:52:16 AM | Computer Name = Inter-X | Source = Service Control Manager | ID = 7003
  1008. Description = The Net.Pipe Listener Adapter service depends the following service:
  1009. was. This service might not be installed.
  1010.  
  1011. Error - 1/21/2017 8:52:16 AM | Computer Name = Inter-X | Source = Service Control Manager | ID = 7003
  1012. Description = The Net.Tcp Listener Adapter service depends the following service:
  1013. was. This service might not be installed.
  1014.  
  1015. Error - 1/21/2017 8:52:22 AM | Computer Name = Inter-X | Source = Service Control Manager | ID = 7026
  1016. Description = The following boot-start or system-start driver(s) failed to load:
  1017. cdrom
  1018.  
  1019. Error - 1/21/2017 8:52:25 AM | Computer Name = Inter-X | Source = Service Control Manager | ID = 7034
  1020. Description = The tbaseprovisioning service terminated unexpectedly. It has done
  1021. this 1 time(s).
  1022.  
  1023.  
  1024. < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement