TheTechGuide Forum

General Category => Tech Clinic => Topic started by: faraz on July 24, 2013, 09:38:29 AM

Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 09:38:29 AM

My system got infected with viruses 


 


& hijack no producing the log got the error see the attachment 


 


and i have doubts some one had put his script in my system  as he his hacking my system & email ids


 


******************************************************************************************************************************************************************


 


Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 7:33:56 PM, on 24/Jul/13

Platform: Windows 7  (WinNT 6.00.3504)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

 

Running processes:

C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe

C:\\Program Files (x86)\\Nitro\\Pro 8\\NitroPdfThumbnailHelper.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\klwtblfs.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Trend Micro\\HiJackThis\\HiJackThis.exe

 

R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant = 

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch = 

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

R1 - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings,ProxyOverride = local

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName = 

R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)

R3 - URLSearchHook: (no name) - {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - (no file)

R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll

R3 - URLSearchHook: (no name) - {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - (no file)

R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbhelper.dll (file missing)

F2 - REG:system.ini: UserInit=userinit.exe,

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll (file missing)

O2 - BHO: Conduit Engine  - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll (file missing)

O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll

O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll

O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll

O2 - BHO: HelloWorldBHO - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll (file missing)

O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\\Users\\Faraz\\AppData\\Roaming\\DefaultTab\\DefaultTab\\DefaultTabBHO.dll (file missing)

O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll

O2 - BHO: ssafEE- saVae - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll (file missing)

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll (file missing)

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\\PROGRA~2\\MICROS~3\\Office14\\URLREDIR.DLL

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll (file missing)

O2 - BHO: Hotspot Shield - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll

O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll

O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\\Program Files (x86)\\Hotspot Shield\\HssIE\\HssIE.dll

O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll (file missing)

O3 - Toolbar: Conduit Engine  - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll (file missing)

O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll

O3 - Toolbar: ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll (file missing)

O4 - HKLM\\..\\Run: [AVP] \"C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe\"

O4 - HKCU\\..\\Run: [uTorrent] \"C:\\Program Files (x86)\\uTorrent\\uTorrent.exe\"  /MINIMIZED

O4 - HKCU\\..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot

O4 - HKCU\\..\\Run: [Sidebar] C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun

O4 - HKUS\\S-1-5-19\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /autoRun (User \'LOCAL SERVICE\')

O4 - HKUS\\S-1-5-19\\..\\RunOnce: [mctadmin] C:\\Windows\\System32\\mctadmin.exe (User \'LOCAL SERVICE\')

O4 - HKUS\\S-1-5-20\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /autoRun (User \'NETWORK SERVICE\')

O4 - HKUS\\S-1-5-20\\..\\RunOnce: [mctadmin] C:\\Windows\\System32\\mctadmin.exe (User \'NETWORK SERVICE\')

O4 - HKUS\\S-1-5-18\\..\\Run: [Mobile Partner] C:\\Program Files (x86)\\VIVA WiFi\\VIVA WiFi (User \'SYSTEM\')

O4 - HKUS\\.DEFAULT\\..\\Run: [Mobile Partner] C:\\Program Files (x86)\\VIVA WiFi\\VIVA WiFi (User \'Default user\')

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm


O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\Reference Titles\\eddefine.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll

O9 - Extra \'Tools\' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll

O9 - Extra button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll

O9 - Extra button: ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll (file missing)

O9 - Extra \'Tools\' menuitem: ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll (file missing)

O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll

O9 - Extra \'Tools\' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll (file missing)

O9 - Extra \'Tools\' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~2\\MICROS~3\\Office12\\REFIEBAR.DLL

O9 - Extra button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll (file missing)

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\PROGRA~2\\COMMON~1\\Skype\\SKYPE4~1.DLL

O20 - AppInit_DLLs: c:\\windows\\syswow64\\nvinit.dll   C:\\Windows\\SysWOW64\\guard32.dll

O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe

O23 - Service: @%systemroot%\\system32\\CISVC.EXE,-1 (CISVC) - Unknown owner - C:\\Windows\\system32\\CISVC.EXE (file missing)

O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe

O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe

O23 - Service: @%SystemRoot%\\system32\\efssvc.dll,-100 (EFS) - Unknown owner - C:\\Windows\\System32\\lsass.exe (file missing)

O23 - Service: @%systemroot%\\system32\\fxsresm.dll,-118 (Fax) - Unknown owner - C:\\Windows\\system32\\fxssvc.exe (file missing)

O23 - Service: Hotspot Shield Service (hshld) - Unknown owner - C:\\Program Files (x86)\\Hotspot Shield\\bin\\cmw_srv.exe (file missing)

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\\Windows\\System32\\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\\System32\\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe

O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\\Windows\\SysWOW64\\NLSSRV32.EXE

O23 - Service: @%systemroot%\\system32\\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: @%systemroot%\\system32\\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\\Windows\\system32\\locator.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\samsrv.dll,-1 (SamSs) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\\Windows\\System32\\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\\system32\\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\\Windows\\System32\\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\\Windows\\system32\\sppsvc.exe (file missing)

O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

O23 - Service: UDisk Monitor - Unknown owner - C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe

O23 - Service: @%SystemRoot%\\system32\\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\\Windows\\system32\\UI0Detect.exe (file missing)

O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

O23 - Service: @%SystemRoot%\\system32\\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\vds.exe,-100 (vds) - Unknown owner - C:\\Windows\\System32\\vds.exe (file missing)

O23 - Service: VIVA Broadband. OUC (VIVA Broadband. RunOuc) - Unknown owner - C:\\Program Files (x86)\\VIVA Broadband\\UpdateDog\\ouc.exe (file missing)

O23 - Service: @%systemroot%\\system32\\vssvc.exe,-102 (VSS) - Unknown owner - C:\\Windows\\system32\\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\Wat\\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\\Windows\\system32\\Wat\\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\\system32\\wbengine.exe,-104 (wbengine) - Unknown owner - C:\\Windows\\system32\\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\\system32\\wbem\\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\\Windows\\system32\\wbem\\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\\Windows Media Player\\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\\Program Files (x86)\\Windows Media Player\\wmpnetwk.exe (file missing)

 

--

End of file - 13996 bytes

 

Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 09:59:47 AM
OTL logfile created on: 24/Jul/13 7:40:59 PM - Run 2

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 1.72 Gb Available Physical Memory | 43.98% Memory free

7.82 Gb Paging File | 5.44 Gb Available in Paging File | 69.65% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.88 Gb Free Space | 12.06% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2012/09/18 14:28:30 | 000,081,928 | ---- | M] (Nitro PDF) -- C:\\Program Files (x86)\\Nitro\\Pro 8\\NitroPDFThumbnailHelper.exe

PRC - [2012/08/17 21:38:34 | 000,128,440 | ---- | M] (Kaspersky Lab ZAO) -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\klwtblfs.exe

PRC - [2011/10/28 17:19:26 | 001,700,600 | ---- | M] (Comodo) -- C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2013/06/12 21:24:12 | 016,033,160 | ---- | M] () -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll

MOD - [2012/08/17 21:38:56 | 000,479,160 | ---- | M] () -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\dblite.dll

MOD - [2011/10/28 17:19:26 | 001,097,480 | ---- | M] () -- C:\\Program Files (x86)\\Comodo\\Dragon\\avcodec-53.dll

MOD - [2011/10/28 17:19:26 | 000,189,192 | ---- | M] () -- C:\\Program Files (x86)\\Comodo\\Dragon\\avformat-53.dll

MOD - [2011/10/28 17:19:26 | 000,121,608 | ---- | M] () -- C:\\Program Files (x86)\\Comodo\\Dragon\\avutil-51.dll

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/21 06:11:32 | 000,078,512 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Hotspot Shield\\bin\\HssTrayService.exe -- (HssTrayService)

SRV - [2013/06/21 05:51:32 | 000,548,136 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Hotspot Shield\\bin\\hsswd.exe -- (HssWd)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

IE - HKLM\\..\\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\..\\SearchScopes\\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3080215

IE - HKLM\\..\\SearchScopes\\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: \"URL\" = http://websearch.searchdwebs.info/?l=1&q={searchTerms}&pid=914&r=2013/07/01&hid=3788853739&lg=EN&cc=PK&unqvl=22

IE - HKLM\\..\\SearchScopes\\{d3f22a84-2a84-49eb-91e6-5dadaaf0165d}: \"URL\" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRxdm487YYpk&ptnrS=GRxdm487YYpk&ptb=3441ED52-4C0A-496E-A90E-9AA1CA0EDFEB&ind=2012090111&n=77ee0eff&psa=&st=sb&searchfor={searchTerms}

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

IE - HKCU\\..\\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - SOFTWARE\\Classes\\CLSID\\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\\InprocServer32 File not found

IE - HKCU\\..\\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: \"URL\" = http://www2.delta-search.com/?q={searchTerms}&affID=121240&tt=gc_&babsrc=SP_ss&mntrId=64A300FFB4E1DD84

IE - HKCU\\..\\SearchScopes\\{7902DE1C-DFB2-426C-A5A1-F87FD90FBEEB}: \"URL\" = http://www.mysearchresults.com/search?c=3513&t=07&q={searchTerms}

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\..\\SearchScopes\\{95B7759C-8C7F-4BF1-B163-73684A933233}: \"URL\" = http://isearch.avg.com/search?cid={A63E2781-B870-42D9-82C8-A06075A35400}&mid=c81a7d7c81e747d0925b369700e81b25-db1903c4b38bb4be805b7f9e83a77cc34f33ade3&lang=en&ds=gm011&pr=sa&d=2012-04-26 23:17:58&v=11.0.0.9&sap=dsp&q={searchTerms}

IE - HKCU\\..\\SearchScopes\\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3080215

IE - HKCU\\..\\SearchScopes\\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: \"URL\" = http://websearch.searchdwebs.info/?l=1&q={searchTerms}&pid=914&r=2013/07/01&hid=3788853739&lg=EN&cc=PK&unqvl=22

IE - HKCU\\..\\SearchScopes\\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: \"URL\" = http://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}

IE - HKCU\\..\\SearchScopes\\{d3f22a84-2a84-49eb-91e6-5dadaaf0165d}: \"URL\" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRxdm487YYpk&ptnrS=GRxdm487YYpk&ptb=3441ED52-4C0A-496E-A90E-9AA1CA0EDFEB&ind=2012090111&n=77ee0eff&psa=&st=sb&searchfor={searchTerms}

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.search.order.1: \"WebSearch\"

FF - prefs.js..browser.search.defaulturl: \"http://websearch.searchdwebs.info/?pid=914&r=2013/07/01&hid=3788853739&lg=EN&cc=PK&unqvl=22&l=1&q=\"

FF - prefs.js..browser.search.order.1,S: S\", \"WebSearch\"

FF - prefs.js..browser.search.defaultenginename,S: S\", \"WebSearch\"

FF - prefs.js..browser.search.selectedEngine,S: S\", \"WebSearch\"

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"

FF - prefs.js..keyword.URL: \"http://us.search.yahoo.com/search?fr=ytff-comodo&p=\"

FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

 

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/03 16:10:18 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/01 22:41:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\staged

[2013/05/12 03:01:32 | 000,006,505 | ---- | M] () -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\firefox\\profiles\\3ajw8v5r.default\\searchplugins\\babylon.xml

[2013/05/12 03:02:06 | 000,001,294 | ---- | M] () -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\firefox\\profiles\\3ajw8v5r.default\\searchplugins\\delta.xml

[2013/07/01 21:18:32 | 000,000,637 | ---- | M] () -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\firefox\\profiles\\3ajw8v5r.default\\searchplugins\\WebSearch.xml

[2013/07/16 14:24:26 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

[2012/04/26 23:00:15 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\[email protected]

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/07/10 00:45:35 | 000,003,769 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\avg-secure-search.xml

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: ChatZum.com -  Easy Pictures zoom = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jbpcjmidkkgldeplajgnbpjkfpmpeepb\\1.0.9_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\\Program Files (x86)\\Hotspot Shield\\HssIE\\HssIE_64.dll (AnchorFree Inc.)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\\Users\\Faraz\\AppData\\Roaming\\DefaultTab\\DefaultTab\\DefaultTabBHO.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\\Program Files (x86)\\Hotspot Shield\\HssIE\\HssIE.dll (AnchorFree Inc.)

O2 - BHO: (XBTBPos00 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O3 - HKLM\\..\\Toolbar: (ChatSend Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O3 - HKLM\\..\\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll File not found

O3 - HKLM\\..\\Toolbar: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (ChatSend Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O3 - HKCU\\..\\Toolbar\\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll ⠀砀㠀㘀⤀ File not found

O3 - HKCU\\..\\Toolbar\\WebBrowser: (Hotspot Shield Toolbar) - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra Button: ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O9 - Extra \'Tools\' menuitem : ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O9 - Extra \'Tools\' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.21.2)

O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{D6CF1441-3187-48F4-915E-017B35738A78}: NameServer = 10.0.1.1 192.168.7.2

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\Pr
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 10:01:55 AM

couldn\'t locate the extras.log of otl scan & it also didn\'t popped up


Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: guestolo on July 24, 2013, 11:17:11 AM
-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.

Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Delete.
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next answer.
You can find the logfile at C:\\AdwCleaner[S1].txt as well.

-Junkware-Removal-Tool-

Please download Junkware Removal Tool to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select \"Run as Administrator\".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system\'s specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

Reopen OTL.exe Select \'Use Safelist\' under Extra Registry then choose to Run a Scan, when done, post the log that opens>> OTL.txt and also Extras.txt
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 08:24:30 PM

# AdwCleaner v2.306 - Logfile created 07/25/2013 at 04:36:30


# Updated 19/07/2013 by Xplode

# Operating system : Windows 7 Ultimate  (64 bits)

# User : Faraz - SLAIN

# Boot Mode : Normal

# Running from : C:\\Users\\Faraz\\Desktop\\AdwCleaner.exe

# Option [Delete]

 

 

***** [Services] *****

 

 

***** [Files / Folders] *****

 

Deleted on reboot : C:\\Program Files (x86)\\Hotspot Shield

File Deleted : C:\\Program Files (x86)\\Mozilla Firefox\\searchplugins\\avg-secure-search.xml

File Deleted : C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\chrome-extension_jbpcjmidkkgldeplajgnbpjkfpmpeepb_0.localstorage

File Deleted : C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\chrome-extension_jbpcjmidkkgldeplajgnbpjkfpmpeepb_0.localstorage-journal

File Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\searchplugins\\Babylon.xml

File Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\searchplugins\\delta.xml

File Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\searchplugins\\WebSearch.xml

File Deleted : C:\\Windows\\SysWOW64\\conduitEngine.tmp

Folder Deleted : C:\\Program Files (x86)\\Hotspot_Shield

Folder Deleted : C:\\Program Files (x86)\\Mozilla Firefox\\Extensions\\[email protected]

Folder Deleted : C:\\ProgramData\\Hotspot Shield

Folder Deleted : C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Hotspot Shield

Folder Deleted : C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jbpcjmidkkgldeplajgnbpjkfpmpeepb

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\Conduit

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\ConduitEngine

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\delta

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\Hotspot_Shield

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\PriceGong

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\Toolbar4

Folder Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Babylon

Folder Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\staged

Folder Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\OpenCandy

Folder Deleted : C:\\Windows\\SysWOW64\\Hotspot Shield

 

***** [Registry] *****

 

Key Deleted : HKCU\\Software\\1ClickDownload

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\conduitEngine

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\ConduitSearchScopes

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\Crossrider

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\Hotspot_Shield

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\PriceGong

Key Deleted : HKCU\\Software\\AppDataLow\\SProtector

Key Deleted : HKCU\\Software\\AppDataLow\\Toolbar

Key Deleted : HKCU\\Software\\BI

Key Deleted : HKCU\\Software\\Conduit

Key Deleted : HKCU\\Software\\Headlight

Key Deleted : HKCU\\Software\\IGearSettings

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{A42F6A7C-B5FA-4565-AC08-ECB439C4342D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{07FCE05F-98B6-4017-8DCE-DCC5823B7678}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{C522512A-9C2C-4DE5-9F63-976B560FEF14}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{79A765E1-C399-405B-85AF-466F52E918B0}

Key Deleted : HKCU\\Software\\Optimizer Pro

Key Deleted : HKCU\\Software\\Softonic

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{C99FDC39-A1AE-4B24-8D71-E5274F8D7C54}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{D3F22A84-2A84-49EB-91E6-5DADAAF0165D}

Key Deleted : HKLM\\Software\\Babylon

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\{4CE516A7-F7AC-4628-B411-8F886DC5733E}

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\{628F3201-34D0-49C0-BB9A-82A26AEFB291}

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\DefaultTabBHO.DLL

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\TbCommonUtils.DLL

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\TbHelper.EXE

Key Deleted : HKLM\\SOFTWARE\\Classes\\bhoclass.bho.bhoclass.bho

Key Deleted : HKLM\\SOFTWARE\\Classes\\bhoclass.bho.bhoclass.bho.1.0

Key Deleted : HKLM\\SOFTWARE\\Classes\\ComObject.DeskbarEnabler

Key Deleted : HKLM\\SOFTWARE\\Classes\\ComObject.DeskbarEnabler.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Conduit.Engine

Key Deleted : HKLM\\SOFTWARE\\Classes\\DefaultTabBHO.DefaultTabBrowser

Key Deleted : HKLM\\SOFTWARE\\Classes\\DefaultTabBHO.DefaultTabBrowser.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\DefaultTabBHO.DefaultTabBrowserActiveX

Key Deleted : HKLM\\SOFTWARE\\Classes\\DefaultTabBHO.DefaultTabBrowserActiveX.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Prod.cap

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbCommonUtils.CommonUtils

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbCommonUtils.CommonUtils.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbDownloadManager

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbDownloadManager.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbPropertyManager

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbPropertyManager.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbRequest

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbRequest.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbTask

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbTask.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.ToolbarHelper

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.ToolbarHelper.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TBSB00001.IEToolbar

Key Deleted : HKLM\\SOFTWARE\\Classes\\TBSB00001.IEToolbar.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TBSB00001.TBSB00001

Key Deleted : HKLM\\SOFTWARE\\Classes\\TBSB00001.TBSB00001.3

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar.CT1561552

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar.CT2786678

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar.CT3031607

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar.CT3080215

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.ContextMenuNotifier

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.ContextMenuNotifier.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.CustomInternetSecurityImpl

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.CustomInternetSecurityImpl.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.SearchProviderManager

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.SearchProviderManager.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.XBTBPos00

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.XBTBPos00.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{4509D3CC-B642-4745-B030-645B79522C6D}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{B87F8B63-7274-43FD-87FA-09D3B7496148}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{E2343056-CC08-46AC-B898-BFC7ACF4E755}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}

Key Deleted : HKLM\\SOFTWARE\\Classes\\URLSearchHook.ToolbarURLSearchHook

Key Deleted : HKLM\\SOFTWARE\\Classes\\URLSearchHook.ToolbarURLSearchHook.1

Key Deleted : HKLM\\Software\\Conduit

Key Deleted : HKLM\\Software\\conduitEngine

Key Deleted : HKLM\\Software\\Hotspot_Shield

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Tracing\\MyBabylontb_RASAPI32

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Tracing\\MyBabylontb_RASMANCS

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\PreApproved\\{07FCE05F-98B6-4017-8DCE-DCC5823B7678}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\PreApproved\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKLM\\Software\\SP Global

Key Deleted : HKLM\\Software\\SProtector

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{07FCE05F-98B6-4017-8DCE-DCC5823B7678}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{57CADC46-58FF-4105-B733-5A9F3FC9783C}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{A42F6A7C-B5FA-4565-AC08-ECB439C4342D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{C339D489-FABC-41DD-B39D-276101667C70}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{CA3EB689-8F09-4026-AA10-B9534C691CE0}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{D89031C2-10DA-4C90-9A62-FCED012BC46B}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{01221FCC-4BFB-461C-B08C-F6D2DF309921}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{03E2A1F3-4402-4121-8B35-733216D61217}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{0FA32667-9A8A-4E9C-902F-CA3323180003}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{2A42D13C-D427-4787-821B-CF6973855778}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{452AE416-9A97-44CA-93DA-D0F15C36254F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{45CDA4F7-594C-49A0-AAD1-8224517FE979}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{4897BBA6-48D9-468C-8EFA-846275D7701B}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{6B458F62-592F-4B25-8967-E6A350A59328}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{81E852CC-1FD5-4004-8761-79A48B975E29}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{B9F43021-60D4-42A6-A065-9BA37F38AC47}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{D2F39980-399F-492E-8D88-5FF7CCB3B47F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{1ADA9BAD-CD7C-46EE-8DED-2DC3A6D8949D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{219168C6-531A-4FD7-87DD-ABB6C223EE27}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{45188CF8-B603-48DF-A71A-F55D3C918753}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{628F3201-34D0-49C0-BB9A-82A26AEFB291}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SearchScopes\\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SearchScopes\\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SearchScopes\\{D3F22A84-2A84-49EB-91E6-5DADAAF0165D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{2EF17083-57D4-4D64-AE4F-55F32A2C4571}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Conduit Engine 

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Hotspot_Shield Toolbar

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Optimizer Pro_is1

Key Deleted : HKLM\\SOFTWARE\\Classes\\CLSID\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{01221FCC-4BFB-461C-B08C-F6D2DF309921}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{03E2A1F3-4402-4121-8B35-733216D61217}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{0FA32667-9A8A-4E9C-902F-CA3323180003}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{2263BE11-ACB7-49D9-8313-6B1D5CC42FAA}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{23119123-0854-469D-807A-171568457991}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{2A42D13C-D427-4787-821B-CF6973855778}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{452AE416-9A97-44CA-93DA-D0F15C36254F}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{45CDA4F7-594C-49A0-AAD1-8224517FE979}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{4897BBA6-48D9-468C-8EFA-846275D7701B}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{6B458F62-592F-4B25-8967-E6A350A59328}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{81E852CC-1FD5-4004-8761-79A48B975E29}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{97FC5555-8BDC-40EA-8DE2-B1E46B9EA629}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{B9F43021-60D4-42A6-A065-9BA37F38AC47}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{BBA74401-6D6F-4BBD-9F65-E8623814F3BB}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{D2F39980-399F-492E-8D88-5FF7CCB3B47F}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Shared Tools\\MSConfig\\startupreg\\ApnUpdater

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Optimizer Pro_is1

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser [{1BB22D38-A411-4B13-A746-C2A4F4EC7344}]

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\URLSearchHooks [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\URLSearchHooks [{CA3EB689-8F09-4026-AA10-B9534C691CE0}]

Value Deleted : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]

Value Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Toolbar [{1BB22D38-A411-4B13-A746-C2A4F4EC7344}]

Value Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]

Value Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Toolbar [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]

 

***** [Internet Browsers] *****

 

-\\\\ Internet Explorer v9.0.8112.16421

 

[OK] Registry is clean.

 

-\\\\ Mozilla Firefox v11.0 (en-US)

 

File : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\prefs.js

 

C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\user.js ... Deleted !

 

Deleted : user_pref(\"extensions.delta.admin\", false);

Deleted : user_pref(\"extensions.delta.aflt\", \"babsst\");

Deleted : user_pref(\"extensions.delta.appId\", \"{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}\");

Deleted : user_pref(\"extensions.delta.autoRvrt\", \"false\");

Deleted : user_pref(\"extensions.delta.dfltLng\", \"en\");

Deleted : user_pref(\"extensions.delta.excTlbr\", false);

Deleted : user_pref(\"extensions.delta.ffxUnstlRst\", true);

Deleted : user_pref(\"extensions.delta.id\", \"64a3dba0000000000000000000000000\");

Deleted : user_pref(\"extensions.delta.instlDay\", \"15836\");

Deleted : user_pref(\"extensions.delta.instlRef\", \"sst\");

Deleted : user_pref(\"extensions.delta.newTab\", false);

Deleted : user_pref(\"extensions.delta.prdct\", \"delta\");

Deleted : user_pref(\"extensions.delta.prtnrId\", \"delta\");

Deleted : user_pref(\"extensions.delta.rvrt\", \"false\");

Deleted : user_pref(\"extensions.delta.smplGrp\", \"none\");

Deleted : user_pref(\"extensions.delta.tlbrId\", \"base\");

Deleted : user_pref(\"extensions.delta.tlbrSrchUrl\", \"\");

Deleted : user_pref(\"extensions.delta.vrsn\", \"1.8.16.16\");

Deleted : user_pref(\"extensions.delta.vrsnTs\", \"1.8.16.163:02:05\");

Deleted : user_pref(\"extensions.delta.vrsni\", \"1.8.16.16\");

Deleted : user_pref(\"browser.search.order.1\", \"WebSearch\");


Deleted : user_pref(\"browser.search.order.1,S\", \"WebSearch\");

Deleted : user_pref(\"browser.search.defaultenginename,S\", \"WebSearch\");

Deleted : user_pref(\"browser.search.selectedEngine,S\", \"WebSearch\");

 

-\\\\ Google Chrome v28.0.1500.72

 

File : C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Preferences

 


 

-\\\\ Opera v11.50.1074.0

 

File : C:\\Users\\Faraz\\AppData\\Roaming\\Opera\\Opera\\operaprefs.ini

 

[OK] File is clean.

 

*************************

 

AdwCleaner[S1].txt - [22687 octets] - [25/07/2013 04:36:30]

 

########## EOF - C:\\AdwCleaner[S1].txt - [22748 octets] ##########
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 08:26:03 PM
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 5.2.2 (07.22.2013:2)

OS: Windows 7 Ultimate x64

Ran by Faraz on 25/Jul/13 at  4:49:55.16

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

~~~ Services

 

Successfully stopped: [Service] hshld 

Successfully deleted: [Service] hshld 

Successfully stopped: [Service] hsstrayservice 

Successfully deleted: [Service] hsstrayservice 

Successfully stopped: [Service] hsswd 

Successfully deleted: [Service] hsswd 

 

 

 

~~~ Registry Values

 

 

 

~~~ Registry Keys

 

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\anchorfree

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\hotspotshield

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\hotspotshield

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\tracing\\apnstub_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\tracing\\apnstub_rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\tracing\\askpartnercobrandingtool_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\tracing\\askpartnercobrandingtool_rasmancs

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{7902DE1C-DFB2-426C-A5A1-F87FD90FBEEB}

 

 

 

~~~ Files

 

 

 

~~~ Folders

 

Successfully deleted: [Folder] \"C:\\ProgramData\\codecc\"

Successfully deleted: [Folder] \"C:\\Users\\Faraz\\appdata\\locallow\\codecc\"

 

 

 

~~~ Event Viewer Logs were cleared

 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on 25/Jul/13 at  5:42:55.18

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 08:27:14 PM
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"

FF - prefs.js..keyword.URL: \"http://us.search.yahoo.com/search?fr=ytff-comodo&p=\"

FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.21.2)

O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 08:31:59 PM
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"

FF - prefs.js..keyword.URL: \"http://us.search.yahoo.com/search?fr=ytff-comodo&p=\"

FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.21.2)

O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 08:33:01 PM
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"

FF - prefs.js..keyword.URL: \"http://us.search.yahoo.com/search?fr=ytff-comodo&p=\"

FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.21.2)

O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 08:34:51 PM
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"

FF - prefs.js..keyword.URL: \"http://us.search.yahoo.com/search?fr=ytff-comodo&p=\"

FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.21.2)

O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on July 24, 2013, 08:36:10 PM
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"

FF - prefs.js..keyword.URL: \"http://us.search.yahoo.com/search?fr=ytff-comodo&p=\"

FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.21.2)

O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: guestolo on July 25, 2013, 10:44:18 AM
Can you do the following:
You appear to be running 2 antivirus software, both battling against each other possibly even do more harm than good
I see
COMODO Internet Security
and
Kaspersky Anti-Virus 2013

Why don\'t you uninstall one of them, keep the one your happiest with
NOTE: It may be best to disable the Protection of the one your going to keep so it
won\'t interfere with the uninstall process
Reboot the computer afterwards

Back in Windows. Temporarily keep your AV protection disable
Run another scan with OTL.exe and post the log that opens afterwards
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on August 03, 2013, 02:21:35 PM
OTL logfile created on: 03/Aug/13 11:38:56 PM - Run 4

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 58.89% Memory free

7.82 Gb Paging File | 6.15 Gb Available in Paging File | 78.69% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 7.81 Gb Free Space | 16.03% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.40 Gb Free Space | 4.92% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 32.71 Gb Free Space | 8.89% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/20 17:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2010/11/20 17:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2010/11/20 17:18:03 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/20 18:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2010/11/20 16:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\TsUsbFlt.sys -- (TsUsbFlt)

DRV:64bit: - [2010/11/20 16:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\rdpvideominiport.sys -- (RdpVideoMiniport)

DRV:64bit: - [2010/11/20 15:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"

FF - prefs.js..keyword.URL: \"http://us.search.yahoo.com/search?fr=ytff-comodo&p=\"

FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.21.2)

O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O18 - Protocol\\Filter\\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\\PROGRA~2\\COMMON~1\\MICROS~1\\OFFICE12\\MSOXMLMF.DLL File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2013/08/01 23:20:32 | 000,000,000 | ---D | C] -- C:\\Windows\\SysNative\\SPReview

[2013/08/01 23:19:26 | 000,000,000 | ---D | C] -- C:\\Windows\\SysNative\\EventProviders

[2013/08/01 23:19:14 | 000,000,000 | ---D | C] -- C:\\3ca1477372be1ce35eb66ac4b2

[2013/07/29 11:51:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\T

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

 

========== Files - Modified Within 30 Days ==========

 

[2013/08/03 23:35:53 | 000,019,184 | -H-- | M] () -- C:\\Windows\\SysNative\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2013/08/03 23:35:53 | 000,019,184 | -H-- | M] () -- C:\\Windows\\SysNative\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2013/08/03 23:30:30 | 000,067,584 | --S- | M] () -- C:\\Windows\\bootstat.dat

[2013/08/03 23:30:23 | 3148,218,368 | -HS- | M] () -- C:\\hiberfil.sys

[2013/08/03 23:22:06 | 000,000,830 | ---- | M] () -- C:\\Windows\\tasks\\Adobe Flash Player Updater.job

[2013/08/03 23:08:28 | 000,986,742 | ---- | M] () -- C:\\Windows\\SysNative\\PerfStringBackup.INI

[2013/08/03 23:08:28 | 000,815,680 | ---- | M] () -- C:\\Windows\\SysNative\\perfh009.dat

[2013/08/03 23:08:28 | 000,169,078 | ---- | M] () -- C:\\Windows\\SysNative\\perfc009.dat

[2013/08/03 23:07:02 | 000,000,908 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000UA.job

[2013/08/03 22:00:15 | 000,000,928 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000UA.job

[2013/08/03 11:55:03 | 000,000,856 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000Core.job

[2013/08/03 01:00:02 | 000,000,906 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000Core.job

[2013/08/02 22:21:22 | 000,002,361 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Google Chrome.lnk

[2013/08/02 21:17:57 | 000,344,816 | ---- | M] () -- C:\\Windows\\SysNative\\FNTCACHE.DAT

[2013/08/01 23:41:46 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\msclmd.dll

[2013/08/01 23:41:45 | 000,175,616 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msclmd.dll

[2013/07/25 04:38:36 | 000,000,105 | ---- | M] () -- C:\\Windows\\DeleteOnReboot.bat

[2013/07/25 04:20:28 | 000,666,633 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\AdwCleaner.exe

[2013/07/25 04:19:54 | 000,560,934 | ---- | M] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,002,975 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\HiJackThis.lnk

[2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,866 | ---- | M] () -- C:\\Users\\Public\\Desktop\\EVDO BROADBAND PTCL.lnk

[2013/07/20 10:48:19 | 000,000,600 | ---- | M] () -- C:\\Users\\Faraz\\PUTTY.RND

[2013/07/20 10:23:20 | 000,580,227 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\How To Hack Any Email Account.pdf

[2013/07/20 09:03:30 | 000,242,310 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\[Tutorial] Disinfecting and Hacking a Keylogger ~ Software Zone.pdf

[2013/07/19 17:23:55 | 001,474,832 | ---- | M] () -- C:\\Windows\\SysNative\\drivers\\sfi.dat

[2013/07/19 16:51:11 | 000,222,725 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Untitled.jpg

[2013/07/18 00:54:17 | 000,441,269 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Q\'s Blog.pdf

[2013/07/16 16:29:58 | 000,174,956 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\HR Q & A.pdf

[2013/07/12 02:14:50 | 001,501,408 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Understanding The Differ..._ Simple Small Business.pdf

[2013/07/12 01:59:48 | 000,644,296 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Markup vs. Margin. What ...rence_ – Consero Global.pdf

[2013/07/12 01:54:42 | 002,197,905 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Gross margin .pdf

[2013/07/10 23:38:42 | 000,001,922 | ---- | M] () -- C:\\Users\\Public\\Desktop\\Nitro Pro 8.lnk

 

========== Files Created - No Company Name ==========

 

[2013/07/25 04:36:43 | 000,000,105 | ---- | C] () -- C:\\Windows\\DeleteOnReboot.bat

[2013/07/25 04:33:26 | 000,666,633 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\AdwCleaner.exe

[2013/07/24 19:03:10 | 000,002,975 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\HiJackThis.lnk

[2013/07/21 00:18:49 | 000,000,866 | ---- | C] () -- C:\\Users\\Public\\Desktop\\EVDO BROADBAND PTCL.lnk

[2013/07/20 10:23:20 | 000,580,227 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\How To Hack Any Email Account.pdf

[2013/07/20 09:03:23 | 000,242,310 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\[Tutorial] Disinfecting and Hacking a Keylogger ~ Software Zone.pdf

[2013/07/18 00:52:53 | 000,441,269 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Q\'s Blog.pdf

[2013/07/16 16:29:21 | 000,174,956 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\HR Q & A.pdf

[2013/07/15 16:16:24 | 002,197,905 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Gross margin .pdf

[2013/07/15 16:16:24 | 001,501,408 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Understanding The Differ..._ Simple Small Business.pdf

[2013/07/15 16:16:24 | 000,644,296 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Markup vs. Margin. What ...rence_ – Consero Global.pdf

[2013/06/27 12:18:04 | 000,033,576 | ---- | C] () -- C:\\Windows\\SysWow64\\BCGPOleAcc.dll

[2013/06/17 14:22:10 | 000,003,441 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\lgr

[2013/06/16 20:21:28 | 000,000,884 | RHS- | C] () -- C:\\Users\\Faraz\\ntuser.pol

[2013/05/31 12:10:39 | 000,007,605 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Local\\Resmon.ResmonCfg

[2013/03/29 14:37:29 | 000,000,004 | ---- | C] () -- C:\\Windows\\vx86036.dat

[2013/03/29 14:36:01 | 000,000,054 | ---- | C] () -- C:\\Windows\\Crypkey.ini

[2013/03/29 14:35:58 | 000,011,776 | ---- | C] () -- C:\\Windows\\Ckrfresh.exe

[2013/03/09 00:05:20 | 000,000,009 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\WinAcc.EML

[2013/03/08 23:59:52 | 000,017,920 | ---- | C] () -- C:\\Windows\\SysWow64\\implode.dll

[2012/08/26 01:49:44 | 000,000,022 | ---- | C] () -- C:\\Windows\\Wininit.ini

[2012/08/05 21:58:10 | 000,002,016 | -HS- | C] () -- C:\\Windows\\SysWow64\\win_fp_sys.dat

[2012/08/05 21:47:33 | 000,000,000 | -HS- | C] () -- C:\\Windows\\SysWow64\\win_fp_app.dat

[2012/08/05 21:47:30 | 000,007,168 | ---- | C] () -- C:\\Windows\\SysWow64\\FPService.exe

[2012/08/05 21:47:29 | 000,116,944 | ---- | C] () -- C:\\Windows\\Secure.dll

[2012/08/05 21:47:29 | 000,110,800 | ---- | C] () -- C:\\Windows\\Secure64.dll

[2012/08/05 21:47:29 | 000,035,840 | ---- | C] () -- C:\\Windows\\SysWow64\\WinFPdrv.sys

[2012/08/05 21:47:29 | 000,008,064 | -HS- | C] () -- C:\\Windows\\SysWow64\\win_fp_config.dat

[2012/08/04 22:11:41 | 000,000,327 | ---- | C] () -- C:\\Windows\\dvdcreator.INI

[2012/08/04 22:07:20 | 000,014,496 | ---- | C] () -- C:\\Windows\\SysWow64\\VDI08X.DAT

[2012/08/04 22:04:00 | 000,135,168 | ---- | C] () -- C:\\Windows\\SysWow64\\VDProductInfoEx.dll

[2012/08/02 01:37:56 | 000,149,504 | ---- | C] () -- C:\\Windows\\SysWow64\\UNWISE.EXE

[2011/10/12 01:02:54 | 000,006,656 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Local\\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011/10/10 23:25:18 | 000,000,000 | ---- | C] () -- C:\\Windows\\SysWow64\\cd.dat

[2011/09/27 00:18:38 | 000,037,647 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\Debut.dmp

[2011/09/01 17:06:21 | 000,000,600 | ---- | C] () -- C:\\Users\\Faraz\\PUTTY.RND

[2011/08/13 23:07:15 | 000,000,990 | -HS- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\systemfl.$dk

 

========== ZeroAccess Check ==========

 

[2011/11/17 12:14:10 | 000,002,048 | -HS- | M] () -- C:\\Windows\\Installer\\{7c0eee1f-7b7e-6235-9f22-0f2dea83d0ae}\\@

[2013/07/03 16:10:09 | 000,000,000 | -HSD | M] -- C:\\Windows\\Installer\\{7c0eee1f-7b7e-6235-9f22-0f2dea83d0ae}\\L

[2013/04/19 11:30:38 | 000,000,000 | -HSD | M] -- C:\\Windows\\Installer\\{7c0eee1f-7b7e-6235-9f22-0f2dea83d0ae}\\U

[2009/07/14 09:55:00 | 000,000,227 | RHS- | M] () -- C:\\Windows\\assembly\\Desktop.ini

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32] /64

 

[HKEY_CURRENT_USER\\Software\\Classes\\Wow6432node\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32] /64

 

[HKEY_CURRENT_USER\\Software\\Classes\\Wow6432node\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32]

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32] /64

\"\" = C:\\Windows\\SysNative\\shell32.dll -- [2012/06/09 10:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Apartment

 

[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

\"\" = %SystemRoot%\\system32\\shell32.dll -- [2012/06/09 09:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Apartment

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32] /64

\"\" = C:\\Windows\\SysNative\\wbem\\fastprox.dll -- [2009/07/14 06:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Free

 

[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32]

\"\" = %systemroot%\\system32\\wbem\\fastprox.dll -- [2010/11/20 17:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Free

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32] /64

\"\" = C:\\Windows\\SysNative\\wbem\\wbemess.dll -- [2009/07/14 06:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Both

 

[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32]

 

< End of report >

 

Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on August 03, 2013, 02:23:28 PM

Again the Extras.txt didn\'t popped up & also it is not on desktop 


 


what should i do ?


Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: guestolo on August 04, 2013, 12:28:05 AM

Don\'t worry about Extra.txt


It wasn\'t needed or asked to popup... We\'ll set OTL to run it if needed


 


Right click on OTL.exe and choose to \"Run as Admin....\" allow to run



On startup, Allow OTL to run if prompted

A log should open, can you post it please

A copy of this log can also be found in

C:\\_OTL\\Moved Files folder


 


 


Let me know how things are running please


Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on August 04, 2013, 08:42:26 AM
All processes killed

========== OTL ==========

Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08d6b0b4-c132-470d-a8e2-aa2e9c3851c9}\\ not found.

Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\\ not found.

Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{c34bfb11-eff0-4123-a7a5-79051ef24cf5} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{c34bfb11-eff0-4123-a7a5-79051ef24cf5}\\ not found.

64bit-Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.

64bit-Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{98ED5451-2AA6-96DB-7012-46C7C9673C57}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{98ED5451-2AA6-96DB-7012-46C7C9673C57}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{C08DF07A-3E49-4E25-9AB0-D3882835F153}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C08DF07A-3E49-4E25-9AB0-D3882835F153}\\ deleted successfully.

Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08D6B0B4-C132-470D-A8E2-AA2E9C3851C9}\\ not found.

Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}\\ not found.

Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{C34BFB11-EFF0-4123-A7A5-79051EF24CF5} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C34BFB11-EFF0-4123-A7A5-79051EF24CF5}\\ not found.

Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\IDMan deleted successfully.

64bit-Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download all links with IDM\\ deleted successfully.

64bit-Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download with IDM\\ deleted successfully.

64bit-Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\QuickDefine\\ deleted successfully.

C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm moved successfully.

Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download all links with IDM\\ not found.

Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download with IDM\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ not found.

File I:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ not found.

File G:\\Setup.exe /Auto not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

File H:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ not found.

File I:\\AutoRun.exe not found.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: All Users

 

User: AppData

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 56466 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

 

User: Faraz

->Temp folder emptied: 13298084 bytes

->Temporary Internet Files folder emptied: 1482353368 bytes

->Java cache emptied: 23858 bytes

->FireFox cache emptied: 66979817 bytes

->Google Chrome cache emptied: 0 bytes

->Opera cache emptied: 0 bytes

->Flash cache emptied: 14912678 bytes

 

User: Public

 

User: UpdatusUser

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\\System32 .tmp files removed: 0 bytes

%systemroot%\\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\\System32\\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 63117321 bytes

%systemroot%\\sysnative\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files folder emptied: 100669 bytes

RecycleBin emptied: 0 bytes

 

Total Files Cleaned = 1,565.00 mb

 

 

OTL by OldTimer - Version 3.2.69.0 log created on 08042013_174319

 

Files\\Folders moved on Reboot...

C:\\Users\\Faraz\\AppData\\Local\\Temp\\FXSAPIDebugLogFile.txt moved successfully.

 

PendingFileRenameOperations files...

 

Registry entries deleted on Reboot...
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on August 04, 2013, 08:49:13 AM

system seems to be running good now........ but 


 


  1. i have doubts of some keylogger or hacking backdoor file presence on my system,as my system got hacked recently & he stole all my personal files and after that he hacked all my working email ids 



       

    have you found any such traces on my system after these logs.....  


       

     


       

       

  2.    
  3. and i am also seeing some hidden desktop.ini files in almost each folder & dektop ....what is this ? 

Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: guestolo on August 04, 2013, 09:51:42 AM

and i am also seeing some hidden desktop.ini files in almost each folder & dektop ....

 You probably have windows set to show hidden files/folders
Not a big worry, we\'ll deal with that in a bit
 
You can open Adwcleaner and click the Uninstall button
 
Can you temporarily disable your Spyware/Virus protections
Let\'s run a couple more tools
Download TDSSKiller:
http://support.kaspersky.com/downloads/utils/tdsskiller.exe
Save it to your desktop then double click on it to run it

Click the START SCAN, when done
If TDSSKiller alerts you that the system needs to reboot, please consent.
When done, a log file should be created on your C: drive named \"TDSSKiller.txt\" please copy and paste the contents in your next reply.
 
In addition:
Download ComboFix from the following location

Link 1
Save it ONLY to your Desktop

Double click on ComboFix to run it, follow the prompts
Click on Yes, to continue scanning for malware if prompted

When finished, it shall produce a log for you. Please include the C:\\ComboFix.txt in your next reply

NOTE: Do not mouseclick inside ComboFix window as it\'s running, it may cause it to stall
ComboFix will/may run again on startup, it will prompt that it\'s creating a log
This process could take up to 10 minutes, let it run uninterrupted please
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on August 07, 2013, 08:15:55 AM

sorry Guestolo m late on response 


 


but i had changed my laptop password & forget it unfortunately


 


can you please first guide me how to remove the password  i have checked & done some tutorials form internet but failed to do so ...


 


 


please its off the topic but guide me to remove the pasword so i could perform your asked steps from last post


 


Thanks


Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: guestolo on August 07, 2013, 06:27:51 PM

Do you have another Admin account on the computer you can login to and remove the password on your account?


We may have to enable the hidden Admin account and use it to remove the password


This is your computer right?

Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on August 09, 2013, 04:45:18 PM
02:08:26.0181 2420  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42

02:08:26.0337 2420  ============================================================

02:08:26.0337 2420  Current date / time: 2013/08/10 02:08:26.0337

02:08:26.0337 2420  SystemInfo:

02:08:26.0337 2420  

02:08:26.0337 2420  OS Version: 6.1.7601 ServicePack: 1.0

02:08:26.0337 2420  Product type: Workstation

02:08:26.0337 2420  ComputerName: SLAIN

02:08:26.0337 2420  UserName: Faraz

02:08:26.0337 2420  Windows directory: C:\\Windows

02:08:26.0337 2420  System windows directory: C:\\Windows

02:08:26.0337 2420  Running under WOW64

02:08:26.0337 2420  Processor architecture: Intel x64

02:08:26.0337 2420  Number of processors: 4

02:08:26.0337 2420  Page size: 0x1000

02:08:26.0337 2420  Boot type: Normal boot

02:08:26.0337 2420  ============================================================

02:08:30.0698 2420  Drive \\Device\\Harddisk0\\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type \'K0\', Flags 0x00000040

02:08:30.0714 2420  ============================================================

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0:

02:08:30.0714 2420  MBR partitions:

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0\\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0\\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x6176000

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0\\Partition3: MBR, Type 0x7, StartLBA 0x61A8800, BlocksNum 0x61A8000

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0\\Partition4: MBR, Type 0x7, StartLBA 0xC350800, BlocksNum 0x2E035000

02:08:30.0714 2420  ============================================================

02:08:30.0730 2420  C: <-> \\Device\\Harddisk0\\DR0\\Partition2

02:08:30.0776 2420  D: <-> \\Device\\Harddisk0\\DR0\\Partition3

02:08:30.0808 2420  E: <-> \\Device\\Harddisk0\\DR0\\Partition4

02:08:30.0808 2420  ============================================================

02:08:30.0808 2420  Initialize success

02:08:30.0808 2420  ============================================================

02:09:02.0054 4208  ============================================================

02:09:02.0054 4208  Scan started

02:09:02.0054 4208  Mode: Manual; 

02:09:02.0054 4208  ============================================================

02:09:03.0068 4208  ================ Scan system memory ========================

02:09:03.0068 4208  System memory - ok

02:09:03.0068 4208  ================ Scan services =============================

02:09:03.0209 4208  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\\Windows\\system32\\drivers\\1394ohci.sys

02:09:03.0224 4208  1394ohci - ok

02:09:03.0256 4208  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\\Windows\\system32\\drivers\\ACPI.sys

02:09:03.0256 4208  ACPI - ok

02:09:03.0287 4208  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi         C:\\Windows\\system32\\drivers\\acpipmi.sys

02:09:03.0287 4208  AcpiPmi - ok

02:09:03.0396 4208  [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe

02:09:03.0412 4208  AdobeFlashPlayerUpdateSvc - ok

02:09:03.0458 4208  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx         C:\\Windows\\system32\\DRIVERS\\adp94xx.sys

02:09:03.0490 4208  adp94xx - ok

02:09:03.0505 4208  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci         C:\\Windows\\system32\\DRIVERS\\adpahci.sys

02:09:03.0521 4208  adpahci - ok

02:09:03.0536 4208  [ E109549C90F62FB570B9540C4B148E54 ] adpu320         C:\\Windows\\system32\\DRIVERS\\adpu320.sys

02:09:03.0552 4208  adpu320 - ok

02:09:03.0583 4208  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc     C:\\Windows\\System32\\aelupsvc.dll

02:09:03.0599 4208  AeLookupSvc - ok

02:09:03.0630 4208  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD             C:\\Windows\\system32\\drivers\\afd.sys

02:09:03.0677 4208  AFD - ok

02:09:03.0708 4208  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\\Windows\\system32\\drivers\\agp440.sys

02:09:03.0708 4208  agp440 - ok

02:09:03.0739 4208  [ 3290D6946B5E30E70414990574883DDB ] ALG             C:\\Windows\\System32\\alg.exe

02:09:03.0739 4208  ALG - ok

02:09:03.0770 4208  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\\Windows\\system32\\drivers\\aliide.sys

02:09:03.0770 4208  aliide - ok

02:09:03.0770 4208  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\\Windows\\system32\\drivers\\amdide.sys

02:09:03.0786 4208  amdide - ok

02:09:03.0802 4208  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8           C:\\Windows\\system32\\DRIVERS\\amdk8.sys

02:09:03.0802 4208  AmdK8 - ok

02:09:03.0833 4208  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\\Windows\\system32\\DRIVERS\\amdppm.sys

02:09:03.0833 4208  AmdPPM - ok

02:09:03.0864 4208  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata         C:\\Windows\\system32\\drivers\\amdsata.sys

02:09:03.0880 4208  amdsata - ok

02:09:03.0895 4208  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\\Windows\\system32\\DRIVERS\\amdsbs.sys

02:09:03.0911 4208  amdsbs - ok

02:09:03.0926 4208  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata         C:\\Windows\\system32\\drivers\\amdxata.sys

02:09:03.0926 4208  amdxata - ok

02:09:03.0942 4208  apcrybwd - ok

02:09:03.0989 4208  [ 24ED0EB2B2558970176ECEE680F8F806 ] ApfiltrService  C:\\Windows\\system32\\DRIVERS\\Apfiltr.sys

02:09:04.0004 4208  ApfiltrService - ok

02:09:04.0067 4208  [ 59D01FA91962C9C1E9B4022B2D3B46DB ] AppHostSvc      C:\\Windows\\system32\\inetsrv\\apphostsvc.dll

02:09:04.0067 4208  AppHostSvc - ok

02:09:04.0114 4208  [ 89A69C3F2F319B43379399547526D952 ] AppID           C:\\Windows\\system32\\drivers\\appid.sys

02:09:04.0129 4208  AppID - ok

02:09:04.0160 4208  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\\Windows\\System32\\appidsvc.dll

02:09:04.0160 4208  AppIDSvc - ok

02:09:04.0192 4208  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo         C:\\Windows\\System32\\appinfo.dll

02:09:04.0192 4208  Appinfo - ok

02:09:04.0223 4208  [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt         C:\\Windows\\System32\\appmgmts.dll

02:09:04.0238 4208  AppMgmt - ok

02:09:04.0270 4208  [ C484F8CEB1717C540242531DB7845C4E ] arc             C:\\Windows\\system32\\DRIVERS\\arc.sys

02:09:04.0270 4208  arc - ok

02:09:04.0285 4208  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\\Windows\\system32\\DRIVERS\\arcsas.sys

02:09:04.0301 4208  arcsas - ok

02:09:04.0348 4208  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\\Windows\\system32\\DRIVERS\\asyncmac.sys

02:09:04.0348 4208  AsyncMac - ok

02:09:04.0379 4208  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi           C:\\Windows\\system32\\drivers\\atapi.sys

02:09:04.0379 4208  atapi - ok

02:09:04.0410 4208  [ CBE61B4494165F458BD87E37181EE934 ] AthBTPort       C:\\Windows\\system32\\DRIVERS\\btath_flt.sys

02:09:04.0410 4208  AthBTPort - ok

02:09:04.0488 4208  [ 67B8BD46E8626C348688930244761DAB ] Atheros Bt&Wlan Coex Agent C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe

02:09:04.0722 4208  Atheros Bt&Wlan Coex Agent - ok

02:09:04.0784 4208  [ 8430ED17CEF0D7878B25776E02508957 ] AtherosSvc      C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\adminservice.exe

02:09:04.0784 4208  AtherosSvc - ok

02:09:04.0878 4208  [ 782D36BAD8DDBF008D02E055DBE70F82 ] athr            C:\\Windows\\system32\\DRIVERS\\athrx.sys

02:09:04.0956 4208  athr - ok

02:09:05.0034 4208  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\\Windows\\System32\\Audiosrv.dll

02:09:05.0065 4208  AudioEndpointBuilder - ok

02:09:05.0096 4208  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\\Windows\\System32\\Audiosrv.dll

02:09:05.0112 4208  AudioSrv - ok

02:09:05.0143 4208  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\\Windows\\System32\\AxInstSV.dll

02:09:05.0159 4208  AxInstSV - ok

02:09:05.0190 4208  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv         C:\\Windows\\system32\\DRIVERS\\bxvbda.sys

02:09:05.0221 4208  b06bdrv - ok

02:09:05.0252 4208  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\\Windows\\system32\\DRIVERS\\b57nd60a.sys

02:09:05.0252 4208  b57nd60a - ok

02:09:05.0284 4208  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\\Windows\\System32\\bdesvc.dll

02:09:05.0299 4208  BDESVC - ok

02:09:05.0315 4208  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\\Windows\\system32\\drivers\\Beep.sys

02:09:05.0315 4208  Beep - ok

02:09:05.0377 4208  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE             C:\\Windows\\System32\\bfe.dll

02:09:05.0408 4208  BFE - ok

02:09:05.0440 4208  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\\Windows\\System32\\qmgr.dll

02:09:05.0502 4208  BITS - ok

02:09:05.0518 4208  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\\Windows\\system32\\DRIVERS\\blbdrive.sys

02:09:05.0533 4208  blbdrive - ok

02:09:05.0627 4208  [ 093B1B419EF25B15D3A1CA6953F41AFB ] Bluetooth Device Monitor C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe

02:09:05.0674 4208  Bluetooth Device Monitor - ok

02:09:05.0736 4208  [ 03A7341E94ACD92E0831336D4F3ACE92 ] Bluetooth Media Service C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe

02:09:06.0064 4208  Bluetooth Media Service - ok

02:09:06.0110 4208  [ A2EBF384ED105FED7D05C5465500EF2E ] Bluetooth OBEX Service C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe

02:09:06.0422 4208  Bluetooth OBEX Service - ok

02:09:06.0485 4208  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\\Windows\\system32\\DRIVERS\\bowser.sys

02:09:06.0485 4208  bowser - ok

02:09:06.0516 4208  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\\Windows\\system32\\DRIVERS\\BrFiltLo.sys

02:09:06.0516 4208  BrFiltLo - ok

02:09:06.0532 4208  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\\Windows\\system32\\DRIVERS\\BrFiltUp.sys

02:09:06.0532 4208  BrFiltUp - ok

02:09:06.0563 4208  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser         C:\\Windows\\System32\\browser.dll

02:09:06.0594 4208  Browser - ok

02:09:06.0625 4208  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid         C:\\Windows\\System32\\Drivers\\Brserid.sys

02:09:06.0625 4208  Brserid - ok

02:09:06.0641 4208  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\\Windows\\System32\\Drivers\\BrSerWdm.sys

02:09:06.0656 4208  BrSerWdm - ok

02:09:06.0672 4208  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\\Windows\\System32\\Drivers\\BrUsbMdm.sys

02:09:06.0672 4208  BrUsbMdm - ok

02:09:06.0672 4208  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\\Windows\\System32\\Drivers\\BrUsbSer.sys

02:09:06.0688 4208  BrUsbSer - ok

02:09:06.0766 4208  [ 227C8F308DE4AF4808E587465CEAB838 ] BTATH_A2DP      C:\\Windows\\system32\\drivers\\btath_a2dp.sys

02:09:06.0766 4208  BTATH_A2DP - ok

02:09:06.0781 4208  [ A83A91D07D1FE6BBE7A9DB46CA00434B ] BTATH_BUS       C:\\Windows\\system32\\DRIVERS\\btath_bus.sys

02:09:06.0781 4208  BTATH_BUS - ok

02:09:06.0812 4208  [ C864FF85EE16D61C2BDD5EF76824625F ] BTATH_HCRP      C:\\Windows\\system32\\DRIVERS\\btath_hcrp.sys

02:09:06.0828 4208  BTATH_HCRP - ok

02:09:06.0844 4208  [ 0DEA505EFB5D771826D177EF8B8A208F ] BTATH_LWFLT     C:\\Windows\\system32\\DRIVERS\\btath_lwflt.sys

02:09:06.0844 4208  BTATH_LWFLT - ok

02:09:06.0859 4208  [ 724C8088C96EFE7A3E63FEC21D4681C0 ] BTATH_RCP       C:\\Windows\\system32\\DRIVERS\\btath_rcp.sys

02:09:06.0859 4208  BTATH_RCP - ok

02:09:06.0906 4208  [ 486720DA2B3BB13D1080C83140C18B56 ] BtFilter        C:\\Windows\\system32\\DRIVERS\\btfilter.sys

02:09:06.0922 4208  BtFilter - ok

02:09:06.0953 4208  [ CF98190A94F62E405C8CB255018B2315 ] BthEnum         C:\\Windows\\system32\\drivers\\BthEnum.sys

02:09:06.0968 4208  BthEnum - ok

02:09:06.0984 4208  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\\Windows\\system32\\DRIVERS\\bthmodem.sys

02:09:07.0000 4208  BTHMODEM - ok

02:09:07.0031 4208  [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan          C:\\Windows\\system32\\DRIVERS\\bthpan.sys

02:09:07.0031 4208  BthPan - ok

02:09:07.0062 4208  [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT         C:\\Windows\\System32\\Drivers\\BTHport.sys

02:09:07.0093 4208  BTHPORT - ok

02:09:07.0124 4208  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv         C:\\Windows\\system32\\bthserv.dll

02:09:07.0124 4208  bthserv - ok

02:09:07.0156 4208  [ F188B7394D81010767B6DF3178519A37 ] BTHUSB          C:\\Windows\\System32\\Drivers\\BTHUSB.sys

02:09:07.0156 4208  BTHUSB - ok

02:09:07.0171 4208  [ 16C1BAC9760C9FA85A30F3FA0FBB1B7A ] btmaux          C:\\Windows\\system32\\DRIVERS\\btmaux.sys

02:09:07.0187 4208  btmaux - ok

02:09:07.0202 4208  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\\Windows\\system32\\DRIVERS\\cdfs.sys

02:09:07.0218 4208  cdfs - ok

02:09:07.0265 4208  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom           C:\\Windows\\system32\\DRIVERS\\cdrom.sys

02:09:07.0265 4208  cdrom - ok

02:09:07.0312 4208  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc     C:\\Windows\\System32\\certprop.dll

02:09:07.0327 4208  CertPropSvc - ok

02:09:07.0358 4208  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\\Windows\\system32\\DRIVERS\\circlass.sys

02:09:07.0358 4208  circlass - ok

02:09:07.0390 4208  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\\Windows\\system32\\CLFS.sys

02:09:07.0405 4208  CLFS - ok

02:09:07.0514 4208  [ 882E3973505C441CE000133C821D0EDD ] CLPSLS          C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe

02:09:07.0546 4208  CLPSLS - ok

02:09:07.0608 4208  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe

02:09:07.0608 4208  clr_optimization_v2.0.50727_32 - ok

02:09:07.0655 4208  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe

02:09:07.0670 4208  clr_optimization_v2.0.50727_64 - ok

02:09:07.0702 4208  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\\Windows\\system32\\DRIVERS\\CmBatt.sys

02:09:07.0717 4208  CmBatt - ok

02:09:07.0795 4208  [ 65FB5097D9EE7E3A99E932CFA0E4B344 ] cmdAgent        C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe

02:09:07.0842 4208  cmdAgent - ok

02:09:07.0858 4208  [ 2D6DC31AA55BFF702519235DEF0DA68E ] cmderd          C:\\Windows\\system32\\DRIVERS\\cmderd.sys

02:09:07.0873 4208  cmderd - ok

02:09:07.0904 4208  [ 919ACCC22ABDC1C3CA68326C0E5DEAF9 ] cmdGuard        C:\\Windows\\system32\\DRIVERS\\cmdguard.sys

02:09:07.0904 4208  cmdGuard - ok

02:09:07.0936 4208  [ F8FECE0F1D44C4A58778083B00EEADAC ] cmdHlp          C:\\Windows\\system32\\DRIVERS\\cmdhlp.sys

02:09:07.0936 4208  cmdHlp - ok

02:09:07.0967 4208  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\\Windows\\system32\\drivers\\cmdide.sys

02:09:07.0967 4208  cmdide - ok

02:09:08.0014 4208  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG             C:\\Windows\\system32\\Drivers\\cng.sys

02:09:08.0045 4208  CNG - ok

02:09:08.0076 4208  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\\Windows\\system32\\DRIVERS\\compbatt.sys

02:09:08.0076 4208  Compbatt - ok

02:09:08.0123 4208  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\\Windows\\system32\\drivers\\CompositeBus.sys

02:09:08.0123 4208  CompositeBus - ok

02:09:08.0138 4208  COMSysApp - ok

02:09:08.0170 4208  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk         C:\\Windows\\system32\\DRIVERS\\crcdisk.sys

02:09:08.0170 4208  crcdisk - ok

02:09:08.0232 4208  [ 2177A0F611584BCA1DFDD7EEB35C0224 ] CrypKey License C:\\Windows\\system32\\crypserv.exe

02:09:08.0482 4208  CrypKey License - ok

02:09:08.0528 4208  [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc        C:\\Windows\\system32\\cryptsvc.dll

02:09:08.0544 4208  CryptSvc - ok

02:09:08.0575 4208  [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC             C:\\Windows\\system32\\drivers\\csc.sys

02:09:08.0606 4208  CSC - ok

02:09:08.0638 4208  [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService      C:\\Windows\\System32\\cscsvc.dll

02:09:08.0669 4208  CscService - ok

02:09:08.0700 4208  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\\Windows\\system32\\rpcss.dll

02:09:08.0747 4208  DcomLaunch - ok

02:09:08.0778 4208  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc       C:\\Windows\\System32\\defragsvc.dll

02:09:08.0809 4208  defragsvc - ok

02:09:08.0840 4208  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\\Windows\\system32\\Drivers\\dfsc.sys

02:09:08.0840 4208  DfsC - ok

02:09:08.0872 4208  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\\Windows\\system32\\dhcpcore.dll

02:09:08.0887 4208  Dhcp - ok

02:09:08.0918 4208  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\\Windows\\system32\\drivers\\discache.sys

02:09:08.0918 4208  discache - ok

02:09:08.0965 4208  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\\Windows\\system32\\DRIVERS\\disk.sys

02:09:08.0965 4208  Disk - ok

02:09:08.0996 4208  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\\Windows\\System32\\dnsrslvr.dll

02:09:09.0012 4208  Dnscache - ok

02:09:09.0059 4208  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc         C:\\Windows\\System32\\dot3svc.dll

02:09:09.0090 4208  dot3svc - ok

02:09:09.0121 4208  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS             C:\\Windows\\system32\\dps.dll

02:09:09.0137 4208  DPS - ok

02:09:09.0168 4208  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud         C:\\Windows\\system32\\drivers\\drmkaud.sys

02:09:09.0184 4208  drmkaud - ok

02:09:09.0215 4208  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl         C:\\Windows\\System32\\drivers\\dxgkrnl.sys

02:09:09.0246 4208  DXGKrnl - ok

02:09:09.0277 4208  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost         C:\\Windows\\System32\\eapsvc.dll

02:09:09.0293 4208  EapHost - ok

02:09:09.0433 4208  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv           C:\\Windows\\system32\\DRIVERS\\evbda.sys

02:09:09.0527 4208  ebdrv - ok

02:09:09.0542 4208  [ C118A82CD78818C29AB228366EBF81C3 ] EFS             C:\\Windows\\System32\\lsass.exe

02:09:09.0574 4208  EFS - ok

02:09:09.0667 4208  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr         C:\\Windows\\ehome\\ehRecvr.exe

02:09:09.0683 4208  ehRecvr - ok

02:09:09.0730 4208  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched         C:\\Windows\\ehome\\ehsched.exe

02:09:09.0730 4208  ehSched - ok

02:09:09.0761 4208  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor         C:\\Windows\\system32\\DRIVERS\\elxstor.sys

02:09:09.0792 4208  elxstor - ok

02:09:09.0823 4208  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\\Windows\\system32\\drivers\\errdev.sys

02:09:09.0823 4208  ErrDev - ok

02:09:09.0886 4208  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem     C:\\Windows\\system32\\es.dll

02:09:09.0901 4208  EventSystem - ok

02:09:09.0979 4208  [ 2B831232C7F57FD675C9AFCA82A5CC24 ] ewusbmbb        C:\\Windows\\system32\\DRIVERS\\ewusbwwan.sys

02:09:10.0010 4208  ewusbmbb - ok

02:09:10.0026 4208  ewusbnet - ok

02:09:10.0057 4208  [ 86F7951BBCEE4A86E79A97306BD14318 ] ew_hwusbdev     C:\\Windows\\system32\\DRIVERS\\ew_hwusbdev.sys

02:09:10.0057 4208  ew_hwusbdev - ok

02:09:10.0088 4208  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat           C:\\Windows\\system32\\drivers\\exfat.sys

02:09:10.0104 4208  exfat - ok

02:09:10.0120 4208  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat         C:\\Windows\\system32\\drivers\\fastfat.sys

02:09:10.0135 4208  fastfat - ok

02:09:10.0182 4208  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax             C:\\Windows\\system32\\fxssvc.exe

02:09:10.0229 4208  Fax - ok

02:09:10.0260 4208  [ 240FF3619817B039198CDCD1E8DAE921 ] fcdabus         C:\\Windows\\system32\\DRIVERS\\fcdabus.sys

02:09:10.0260 4208  fcdabus - ok

02:09:10.0291 4208  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc             C:\\Windows\\system32\\DRIVERS\\fdc.sys

02:09:10.0291 4208  fdc - ok

02:09:10.0322 4208  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost         C:\\Windows\\system32\\fdPHost.dll

02:09:10.0338 4208  fdPHost - ok

02:09:10.0354 4208  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\\Windows\\system32\\fdrespub.dll

02:09:10.0385 4208  FDResPub - ok

02:09:10.0400 4208  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\\Windows\\system32\\drivers\\fileinfo.sys

02:09:10.0400 4208  FileInfo - ok

02:09:10.0416 4208  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace       C:\\Windows\\system32\\drivers\\filetrace.sys

02:09:10.0432 4208  Filetrace - ok

02:09:10.0447 4208  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\\Windows\\system32\\DRIVERS\\flpydisk.sys

02:09:10.0447 4208  flpydisk - ok

02:09:10.0510 4208  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\\Windows\\system32\\drivers\\fltmgr.sys

02:09:10.0541 4208  FltMgr - ok

02:09:10.0619 4208  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache       C:\\Windows\\system32\\FntCache.dll

02:09:10.0666 4208  FontCache - ok

02:09:10.0712 4208  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe

02:09:10.0915 4208  FontCache3.0.0.0 - ok

02:09:10.0946 4208  fqtirfym - ok

02:09:10.0962 4208  [ D43703496149971890703B4B1B723EAC ] FsDepends       C:\\Windows\\system32\\drivers\\FsDepends.sys

02:09:10.0978 4208  FsDepends - ok

02:09:10.0993 4208  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\\Windows\\system32\\drivers\\Fs_Rec.sys

02:09:10.0993 4208  Fs_Rec - ok

02:09:11.0040 4208  [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol          C:\\Windows\\system32\\DRIVERS\\fvevol.sys

02:09:11.0056 4208  fvevol - ok

02:09:11.0087 4208  [ C4AE69B476A40C165B6E99D10E814D0F ] FVXSCSI         C:\\Windows\\system32\\DRIVERS\\fvxscsi.sys

02:09:11.0087 4208  FVXSCSI - ok

02:09:11.0134 4208  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\\Windows\\system32\\DRIVERS\\gagp30kx.sys

02:09:11.0134 4208  gagp30kx - ok

02:09:11.0149 4208  gnfjuabb - ok

02:09:11.0212 4208  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc           C:\\Windows\\System32\\gpsvc.dll

02:09:11.0258 4208  gpsvc - ok

02:09:11.0274 4208  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\\Windows\\system32\\drivers\\hcw85cir.sys

02:09:11.0274 4208  hcw85cir - ok

02:09:11.0336 4208  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\\Windows\\system32\\drivers\\HdAudio.sys

02:09:11.0352 4208  HdAudAddService - ok

02:09:11.0368 4208  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\\Windows\\system32\\drivers\\HDAudBus.sys

02:09:11.0383 4208  HDAudBus - ok

02:09:11.0399 4208  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt         C:\\Windows\\system32\\DRIVERS\\HidBatt.sys

02:09:11.0399 4208  HidBatt - ok

02:09:11.0414 4208  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\\Windows\\system32\\DRIVERS\\hidbth.sys

02:09:11.0430 4208  HidBth - ok

02:09:11.0446 4208  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr           C:\\Windows\\system32\\DRIVERS\\hidir.sys

02:09:11.0446 4208  HidIr - ok

02:09:11.0477 4208  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv         C:\\Windows\\system32\\hidserv.dll

02:09:11.0492 4208  hidserv - ok

02:09:11.0508 4208  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\\Windows\\system32\\drivers\\hidusb.sys

02:09:11.0508 4208  HidUsb - ok

02:09:11.0555 4208  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\\Windows\\system32\\kmsvc.dll

02:09:11.0570 4208  hkmsvc - ok

02:09:11.0617 4208  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\\Windows\\system32\\ListSvc.dll

02:09:11.0664 4208  HomeGroupListener - ok

02:09:11.0695 4208  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\\Windows\\system32\\provsvc.dll

02:09:11.0726 4208  HomeGroupProvider - ok

02:09:11.0758 4208  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\\Windows\\system32\\drivers\\HpSAMD.sys

02:09:11.0773 4208  HpSAMD - ok

02:09:11.0804 4208  [ 26B05FFD8FB5E70EB501A610E3425341 ] HssDRV6         C:\\Windows\\system32\\DRIVERS\\hssdrv6.sys

02:09:11.0820 4208  HssDRV6 - ok

02:09:11.0914 4208  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\\Windows\\system32\\drivers\\HTTP.sys

02:09:11.0960 4208  HTTP - ok

02:09:11.0992 4208  [ 91971BCD780D6063DF90DE4F1DF10C2F ] huawei_cdcacm   C:\\Windows\\system32\\DRIVERS\\ew_jucdcacm.sys

02:09:12.0007 4208  huawei_cdcacm - ok

02:09:12.0038 4208  [ 53D3E56CB36C9DDE9B7CDB5447DA0E80 ] huawei_cdcecm   C:\\Windows\\system32\\DRIVERS\\ew_jucdcecm.sys

02:09:12.0038 4208  huawei_cdcecm - ok

02:09:12.0070 4208  [ CCE3DB0BA3C615CAA321EB1301532688 ] huawei_enumerator C:\\Windows\\system32\\DRIVERS\\ew_jubusenum.sys

02:09:12.0085 4208  huawei_enumerator - ok

02:09:12.0101 4208  [ C4BC37B9E5E54A50B2AA458F1FCA428C ] huawei_ext_ctrl C:\\Windows\\system32\\DRIVERS\\ew_juextctrl.sys

02:09:12.0101 4208  huawei_ext_ctrl - ok

02:09:12.0148 4208  [ CE93B8AF848FE2AA44455A4769C1BC8A ] hwdatacard      C:\\Windows\\system32\\DRIVERS\\ewusbmdm.sys

02:09:12.0163 4208  hwdatacard - ok

02:09:12.0241 4208  [ E90DA42B87D684DEBFB73B38A718A006 ] HWDeviceService64.exe C:\\ProgramData\\DatacardService\\HWDeviceService64.exe

02:09:12.0257 4208  HWDeviceService64.exe - ok

02:09:12.0288 4208  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\\Windows\\system32\\drivers\\hwpolicy.sys

02:09:12.0304 4208  hwpolicy - ok

02:09:12.0319 4208  hwusbdev - ok

02:09:12.0366 4208  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\\Windows\\system32\\drivers\\i8042prt.sys

02:09:12.0366 4208  i8042prt - ok

02:09:12.0413 4208  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV         C:\\Windows\\system32\\drivers\\iaStorV.sys

02:09:12.0444 4208  iaStorV - ok

02:09:12.0491 4208  [ 2A63036283B36B3B68CDC6F85A7D53ED ] IDMWFP          C:\\Windows\\system32\\DRIVERS\\idmwfp.sys

02:09:12.0491 4208  IDMWFP - ok

02:09:12.0538 4208  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc           C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe

02:09:12.0569 4208  idsvc - ok

02:09:13.0052 4208  [ 795C99DC4F574C97C03D0BB39CF099EE ] igfx            C:\\Windows\\system32\\DRIVERS\\igdkmd64.sys

02:09:13.0364 4208  igfx - ok

02:09:13.0411 4208  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp           C:\\Windows\\system32\\DRIVERS\\iirsp.sys

02:09:13.0411 4208  iirsp - ok

02:09:13.0474 4208  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\\Windows\\System32\\ikeext.dll

02:09:13.0505 4208  IKEEXT - ok

02:09:13.0552 4208  [ C4E67D3037DC79E39D7136581A947F50 ] inspect         C:\\Windows\\system32\\DRIVERS\\inspect.sys

02:09:13.0552 4208  inspect - ok

02:09:13.0583 4208  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\\Windows\\system32\\drivers\\intelide.sys

02:09:13.0598 4208  intelide - ok

02:09:13.0630 4208  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\\Windows\\system32\\DRIVERS\\intelppm.sys

02:09:13.0630 4208  intelppm - ok

02:09:13.0661 4208  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum       C:\\Windows\\system32\\ipbusenum.dll

02:09:13.0676 4208  IPBusEnum - ok

02:09:13.0708 4208  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\\Windows\\system32\\DRIVERS\\ipfltdrv.sys

02:09:13.0723 4208  IpFilterDriver - ok

02:09:13.0770 4208  [ A34A587FFFD45FA649FBA6D03784D257 ] IpHlpSvc        C:\\Windows\\System32\\iphlpsvc.dll

02:09:13.0848 4208  IpHlpSvc - ok

02:09:13.0879 4208  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV         C:\\Windows\\system32\\drivers\\IPMIDrv.sys

02:09:13.0895 4208  IPMIDRV - ok

02:09:13.0926 4208  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT           C:\\Windows\\system32\\drivers\\ipnat.sys

02:09:13.0926 4208  IPNAT - ok

02:09:13.0957 4208  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\\Windows\\system32\\drivers\\irenum.sys

02:09:13.0957 4208  IRENUM - ok

02:09:13.0988 4208  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\\Windows\\system32\\drivers\\isapnp.sys

02:09:13.0988 4208  isapnp - ok

02:09:14.0020 4208  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\\Windows\\system32\\drivers\\msiscsi.sys

02:09:14.0066 4208  iScsiPrt - ok

02:09:14.0113 4208  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\\Windows\\system32\\drivers\\kbdclass.sys

02:09:14.0113 4208  kbdclass - ok

02:09:14.0144 4208  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\\Windows\\system32\\drivers\\kbdhid.sys

02:09:14.0144 4208  kbdhid - ok

02:09:14.0191 4208  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\\Windows\\system32\\lsass.exe

02:09:14.0207 4208  KeyIso - ok

02:09:14.0222 4208  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\\Windows\\system32\\Drivers\\ksecdd.sys

02:09:14.0222 4208  KSecDD - ok

02:09:14.0254 4208  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg         C:\\Windows\\system32\\Drivers\\ksecpkg.sys

02:09:14.0254 4208  KSecPkg - ok

02:09:14.0300 4208  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk         C:\\Windows\\system32\\drivers\\ksthunk.sys

02:09:14.0300 4208  ksthunk - ok

02:09:14.0347 4208  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm           C:\\Windows\\system32\\msdtckrm.dll

02:09:14.0378 4208  KtmRm - ok

02:09:14.0441 4208  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\\Windows\\system32\\srvsvc.dll

02:09:14.0488 4208  LanmanServer - ok

02:09:14.0534 4208  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\\Windows\\System32\\wkssvc.dll

02:09:14.0581 4208  LanmanWorkstation - ok

02:09:14.0628 4208  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\\Windows\\system32\\DRIVERS\\lltdio.sys

02:09:14.0628 4208  lltdio - ok

02:09:14.0659 4208  [ C1185803384AB3FEED115F79F109427F ] lltdsvc         C:\\Windows\\System32\\lltdsvc.dll

02:09:14.0690 4208  lltdsvc - ok

02:09:14.0706 4208  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts         C:\\Windows\\System32\\lmhsvc.dll

02:09:14.0737 4208  lmhosts - ok

02:09:14.0784 4208  [ 0803906D607A9B83184447B75B60ECC2 ] LMS             C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

02:09:14.0784 4208  LMS - ok

02:09:14.0815 4208  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\\Windows\\system32\\DRIVERS\\lsi_fc.sys

02:09:14.0831 4208  LSI_FC - ok

02:09:14.0846 4208  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS         C:\\Windows\\system32\\DRIVERS\\lsi_sas.sys

02:09:14.0862 4208  LSI_SAS - ok

02:09:14.0878 4208  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\\Windows\\system32\\DRIVERS\\lsi_sas2.sys

02:09:14.0878 4208  LSI_SAS2 - ok

02:09:14.0893 4208  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\\Windows\\system32\\DRIVERS\\lsi_scsi.sys

02:09:14.0909 4208  LSI_SCSI - ok

02:09:14.0940 4208  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv           C:\\Windows\\system32\\drivers\\luafv.sys

02:09:14.0940 4208  luafv - ok

02:09:14.0971 4208  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc         C:\\Windows\\system32\\Mcx2Svc.dll

02:09:15.0002 4208  Mcx2Svc - ok

02:09:15.0034 4208  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas         C:\\Windows\\system32\\DRIVERS\\megasas.sys

02:09:15.0034 4208  megasas - ok

02:09:15.0065 4208  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\\Windows\\system32\\DRIVERS\\MegaSR.sys

02:09:15.0080 4208  MegaSR - ok

02:09:15.0127 4208  [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64          C:\\Windows\\system32\\DRIVERS\\HECIx64.sys

02:09:15.0127 4208  MEIx64 - ok

02:09:15.0158 4208  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS           C:\\Windows\\system32\\mmcss.dll

02:09:15.0190 4208  MMCSS - ok

02:09:15.0205 4208  [ 800BA92F7010378B09F9ED9270F07137 ] Modem           C:\\Windows\\system32\\drivers\\modem.sys

02:09:15.0205 4208  Modem - ok

02:09:15.0236 4208  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor         C:\\Windows\\system32\\DRIVERS\\monitor.sys

02:09:15.0236 4208  monitor - ok

02:09:15.0268 4208  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\\Windows\\system32\\drivers\\mouclass.sys

02:09:15.0283 4208  mouclass - ok

02:09:15.0299 4208  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\\Windows\\system32\\DRIVERS\\mouhid.sys

02:09:15.0299 4208  mouhid - ok

02:09:15.0346 4208  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\\Windows\\system32\\drivers\\mountmgr.sys

02:09:15.0346 4208  mountmgr - ok

02:09:15.0361 4208  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\\Windows\\system32\\drivers\\mpio.sys

02:09:15.0377 4208  mpio - ok

02:09:15.0392 4208  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\\Windows\\system32\\drivers\\mpsdrv.sys

02:09:15.0408 4208  mpsdrv - ok

02:09:15.0486 4208  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\\Windows\\system32\\mpssvc.dll

02:09:15.0533 4208  MpsSvc - ok

02:09:15.0580 4208  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\\Windows\\system32\\drivers\\mrxdav.sys

02:09:15.0595 4208  MRxDAV - ok

02:09:15.0626 4208  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\\Windows\\system32\\DRIVERS\\mrxsmb.sys

02:09:15.0626 4208  mrxsmb - ok

02:09:15.0658 4208  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\\Windows\\system32\\DRIVERS\\mrxsmb10.sys

02:09:15.0689 4208  mrxsmb10 - ok

02:09:15.0704 4208  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\\Windows\\system32\\DRIVERS\\mrxsmb20.sys

02:09:15.0720 4208  mrxsmb20 - ok

02:09:15.0751 4208  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\\Windows\\system32\\drivers\\msahci.sys

02:09:15.0751 4208  msahci - ok

02:09:15.0782 4208  [ DB801A638D011B9633829EB6F663C900 ] msdsm           C:\\Windows\\system32\\drivers\\msdsm.sys

02:09:15.0798 4208  msdsm - ok

02:09:15.0814 4208  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC           C:\\Windows\\System32\\msdtc.exe

02:09:15.0845 4208  MSDTC - ok

02:09:15.0876 4208  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\\Windows\\system32\\drivers\\Msfs.sys

02:09:15.0892 4208  Msfs - ok

02:09:15.0970 4208  [ F7E0900F9A8E3F71F2C16A932F0E03E0 ] msftesql$PRIMAVERA C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

02:09:16.0188 4208  msftesql$PRIMAVERA - ok

02:09:16.0235 4208  [ F7E0900F9A8E3F71F2C16A932F0E03E0 ] msftesql$SQLEXPRESS C:\\Program Files (x86)\\Microsoft SQL Server\\MSSQL.2\\MSSQL\\Binn\\msftesql.exe

02:09:16.0406 4208  msftesql$SQLEXPRESS - ok

02:09:16.0438 4208  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf       C:\\Windows\\System32\\drivers\\mshidkmdf.sys

02:09:16.0453 4208  mshidkmdf - ok

02:09:16.0484 4208  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\\Windows\\system32\\drivers\\msisadrv.sys

02:09:16.0484 4208  msisadrv - ok

02:09:16.0531 4208  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI         C:\\Windows\\system32\\iscsiexe.dll

02:09:16.0547 4208  MSiSCSI - ok

02:09:16.0562 4208  msiserver - ok

02:09:16.0594 4208  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV         C:\\Windows\\system32\\drivers\\MSKSSRV.sys

02:09:16.0594 4208  MSKSSRV - ok

02:09:16.0609 4208  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\\Windows\\system32\\drivers\\MSPCLOCK.sys

02:09:16.0609 4208  MSPCLOCK - ok

02:09:16.0625 4208  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM           C:\\Windows\\system32\\drivers\\MSPQM.sys

02:09:16.0640 4208  MSPQM - ok

02:09:16.0703 4208  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC           C:\\Windows\\system32\\drivers\\MsRPC.sys

02:09:16.0718 4208  MsRPC - ok

02:09:16.0734 4208  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\\Windows\\system32\\drivers\\mssmbios.sys

02:09:16.0734 4208  mssmbios - ok

02:09:16.0765 4208  MSSQL$PRIMAVERA - ok

02:09:16.0781 4208  MSSQL$SQLEXPRESS - ok

02:09:16.0828 4208  [ ADAF062116B4E6D96E44D26486A87AF6 ] MSSQLServerADHelper C:\\Program Files (x86)\\Microsoft SQL Server\\90\\Shared\\sqladhlp90.exe

02:09:16.0843 4208  MSSQLServerADHelper - ok

02:09:16.0859 4208  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE           C:\\Windows\\system32\\drivers\\MSTEE.sys

02:09:16.0874 4208  MSTEE - ok

02:09:16.0890 4208  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\\Windows\\system32\\DRIVERS\\MTConfig.sys

02:09:16.0890 4208  MTConfig - ok

02:09:16.0921 4208  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup             C:\\Windows\\system32\\Drivers\\mup.sys

02:09:16.0921 4208  Mup - ok

02:09:16.0968 4208  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\\Windows\\system32\\qagentRT.dll

02:09:17.0015 4208  napagent - ok

02:09:17.0077 4208  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP     C:\\Windows\\system32\\DRIVERS\\nwifi.sys

02:09:17.0093 4208  NativeWifiP - ok

02:09:17.0140 4208  [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS            C:\\Windows\\system32\\drivers\\ndis.sys

02:09:17.0155 4208  NDIS - ok

02:09:17.0186 4208  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap         C:\\Windows\\system32\\DRIVERS\\ndiscap.sys

02:09:17.0202 4208  NdisCap - ok

02:09:17.0218 4208  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\\Windows\\system32\\DRIVERS\\ndistapi.sys

02:09:17.0233 4208  NdisTapi - ok

02:09:17.0264 4208  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio         C:\\Windows\\system32\\DRIVERS\\ndisuio.sys

02:09:17.0280 4208  Ndisuio - ok

02:09:17.0311 4208  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan         C:\\Windows\\system32\\DRIVERS\\ndiswan.sys

02:09:17.0327 4208  NdisWan - ok

02:09:17.0358 4208  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy         C:\\Windows\\system32\\drivers\\NDProxy.sys

02:09:17.0358 4208  NDProxy - ok

02:09:17.0389 4208  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS         C:\\Windows\\system32\\DRIVERS\\netbios.sys

02:09:17.0405 4208  NetBIOS - ok

02:09:17.0436 4208  [ 09594D1089C523423B32A4229263F068 ] NetBT           C:\\Windows\\system32\\DRIVERS\\netbt.sys

02:09:17.0467 4208  NetBT - ok

02:09:17.0483 4208  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\\Windows\\system32\\lsass.exe

02:09:17.0498 4208  Netlogon - ok

02:09:17.0561 4208  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\\Windows\\System32\\netman.dll

02:09:17.0608 4208  Netman - ok

02:09:17.0623 4208  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\\Windows\\System32\\netprofm.dll

02:09:17.0670 4208  netprofm - ok

02:09:17.0732 4208  [ C9E9017AC2291E96ED3376B72BC7CF8D ] netr28ux        C:\\Windows\\system32\\DRIVERS\\netr28ux.sys

02:09:17.0779 4208  netr28ux - ok

02:09:17.0810 4208  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\SMSvcHost.exe

02:09:18.0029 4208  NetTcpPortSharing - ok

02:09:18.0060 4208  [ A97D9B1C2EEB2E169D2593E7073BCD27 ] NetworkX        C:\\Windows\\System32\\ckldrv.sys

02:09:18.0076 4208  NetworkX - ok

02:09:18.0107 4208  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960         C:\\Windows\\system32\\DRIVERS\\nfrd960.sys

02:09:18.0122 4208  nfrd960 - ok

02:09:18.0200 4208  [ 07937CE37AD35FBECBF9D8BE584DCF2A ] NitroDriverReadSpool8 C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe

02:09:18.0216 4208  NitroDriverReadSpool8 - ok

02:09:18.0263 4208  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\\Windows\\System32\\nlasvc.dll

02:09:18.0294 4208  NlaSvc - ok

02:09:18.0450 4208  [ 06FE5405DA932CD4DEF1517B532F543A ] nlsX86cc        C:\\Windows\\SysWOW64\\NLSSRV32.EXE

02:09:18.0684 4208  nlsX86cc - ok

02:09:18.0715 4208  [ 02C1198276C0D4F39E54EB5148AF1E2A ] nmwcdcx64       C:\\Windows\\system32\\drivers\\ccdcmbox64.sys

02:09:18.0731 4208  nmwcdcx64 - ok

02:09:18.0746 4208  [ D8F00FCC82451BDAA3DB93BB62AE6AC3 ] nmwcdx64        C:\\Windows\\system32\\drivers\\ccdcmbx64.sys

02:09:18.0762 4208  nmwcdx64 - ok

02:09:18.0778 4208  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\\Windows\\system32\\drivers\\Npfs.sys

02:09:18.0778 4208  Npfs - ok

02:09:18.0809 4208  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi             C:\\Windows\\system32\\nsisvc.dll

02:09:18.0840 4208  nsi - ok

02:09:18.0856 4208  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\\Windows\\system32\\drivers\\nsiproxy.sys

02:09:18.0871 4208  nsiproxy - ok

02:09:18.0949 4208  [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs            C:\\Windows\\system32\\drivers\\Ntfs.sys

02:09:19.0027 4208  Ntfs - ok

02:09:19.0043 4208  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\\Windows\\system32\\drivers\\Null.sys

02:09:19.0058 4208  Null - ok

02:09:19.0090 4208  [ 158AD24745BD85BA9BE3C51C38F48C32 ] nusb3hub        C:\\Windows\\system32\\DRIVERS\\nusb3hub.sys

02:09:19.0090 4208  nusb3hub - ok

02:09:19.0105 4208  [ D40A13B2C0891E218F9523B376955DB6 ] nusb3xhc        C:\\Windows\\system32\\DRIVERS\\nusb3xhc.sys

02:09:19.0121 4208  nusb3xhc - ok

02:09:19.0168 4208  [ F2662FDC20518EE8A8EED4F61BA42349 ] NVHDA           C:\\Windows\\system32\\drivers\\nvhda64v.sys

02:09:19.0183 4208  NVHDA - ok

02:09:19.0526 4208  [ 573B0941A37AEBEE96085D56A103F57B ] nvlddmkm        C:\\Windows\\system32\\DRIVERS\\nvlddmkm.sys

02:09:19.0729 4208  nvlddmkm - ok

02:09:19.0760 4208  [ 43AF7EBEAC2AB623468E32CADDCB61A4 ] nvpciflt        C:\\Windows\\system32\\DRIVERS\\nvpciflt.sys

02:09:19.0760 4208  nvpciflt - ok

02:09:19.0807 4208  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\\Windows\\system32\\drivers\\nvraid.sys

02:09:19.0823 4208  nvraid - ok

02:09:19.0854 4208  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\\Windows\\system32\\drivers\\nvstor.sys

02:09:19.0854 4208  nvstor - ok

02:09:19.0901 4208  [ C500760572C6059918FB0C960967695B ] NVSvc           C:\\Windows\\system32\\nvvsvc.exe

02:09:19.0948 4208  NVSvc - ok

02:09:20.0041 4208  [ F28169A7ADF7B41809CF92D369E744F0 ] nvUpdatusService C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe

02:09:20.0462 4208  nvUpdatusService - ok

02:09:20.0494 4208  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\\Windows\\system32\\drivers\\nv_agp.sys

02:09:20.0509 4208  nv_agp - ok

02:09:20.0540 4208  odserv - ok

02:09:20.0572 4208  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\\Windows\\system32\\drivers\\ohci1394.sys

02:09:20.0587 4208  ohci1394 - ok

02:09:20.0650 4208  [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose             C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE

02:09:20.0868 4208  ose - ok

02:09:21.0040 4208  [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc         C:\\Program Files\\Common Files\\Microsoft Shared\\OfficeSoftwareProtectionPlatform\\OSPPSVC.EXE

02:09:21.0258 4208  osppsvc - ok

02:09:21.0305 4208  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\\Windows\\system32\\pnrpsvc.dll

02:09:21.0352 4208  p2pimsvc - ok

02:09:21.0367 4208  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\\Windows\\system32\\p2psvc.dll

02:09:21.0414 4208  p2psvc - ok

02:09:21.0445 4208  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport         C:\\Windows\\system32\\DRIVERS\\parport.sys

02:09:21.0461 4208  Parport - ok

02:09:21.0492 4208  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr         C:\\Windows\\system32\\drivers\\partmgr.sys

02:09:21.0492 4208  partmgr - ok

02:09:21.0523 4208  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\\Windows\\System32\\pcasvc.dll

02:09:21.0554 4208  PcaSvc - ok

02:09:21.0601 4208  [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd        C:\\Windows\\system32\\DRIVERS\\pccsmcfdx64.sys

02:09:21.0601 4208  pccsmcfd - ok

02:09:21.0632 4208  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci             C:\\Windows\\system32\\drivers\\pci.sys

02:09:21.0664 4208  pci - ok

02:09:21.0695 4208  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\\Windows\\system32\\drivers\\pciide.sys

02:09:21.0695 4208  pciide - ok

02:09:21.0726 4208  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\\Windows\\system32\\DRIVERS\\pcmcia.sys

02:09:21.0742 4208  pcmcia - ok

02:09:21.0757 4208  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw             C:\\Windows\\system32\\drivers\\pcw.sys

02:09:21.0773 4208  pcw - ok

02:09:21.0804 4208  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\\Windows\\system32\\drivers\\peauth.sys

02:09:21.0835 4208  PEAUTH - ok

02:09:21.0898 4208  [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc     C:\\Windows\\system32\\peerdistsvc.dll

02:09:21.0976 4208  PeerDistSvc - ok

02:09:22.0022 4208  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\\Windows\\SysWow64\\perfhost.exe

02:09:22.0272 4208  PerfHost - ok

02:09:22.0350 4208  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla             C:\\Windows\\system32\\pla.dll

02:09:22.0428 4208  pla - ok

02:09:22.0490 4208  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\\Windows\\system32\\umpnpmgr.dll

02:09:22.0553 4208  PlugPlay - ok

02:09:22.0584 4208  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg     C:\\Windows\\system32\\pnrpauto.dll

02:09:22.0631 4208  PNRPAutoReg - ok

02:09:22.0646 4208  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc         C:\\Windows\\system32\\pnrpsvc.dll

02:09:22.0678 4208  PNRPsvc - ok

02:09:22.0709 4208  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent     C:\\Windows\\System32\\ipsecsvc.dll

02:09:22.0756 4208  PolicyAgent - ok

02:09:22.0802 4208  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power           C:\\Windows\\system32\\umpo.dll

02:09:22.0849 4208  Power - ok

02:09:22.0880 4208  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\\Windows\\system32\\DRIVERS\\raspptp.sys

02:09:22.0896 4208  PptpMiniport - ok

02:09:23.0005 4208  [ 4747B514561B1F6E8937202C0BCE0411 ] PrmBackAgent    C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe

02:09:23.0426 4208  PrmBackAgent - ok

02:09:23.0458 4208  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor       C:\\Windows\\system32\\DRIVERS\\processr.sys

02:09:23.0458 4208  Processor - ok

02:09:23.0504 4208  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc         C:\\Windows\\system32\\profsvc.dll

02:09:23.0536 4208  ProfSvc - ok

02:09:23.0551 4208  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\\Windows\\system32\\lsass.exe

02:09:23.0582 4208  ProtectedStorage - ok

02:09:23.0629 4208  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\\Windows\\system32\\DRIVERS\\pacer.sys

02:09:23.0645 4208  Psched - ok

02:09:23.0692 4208  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\\Windows\\system32\\DRIVERS\\ql2300.sys

02:09:23.0754 4208  ql2300 - ok

02:09:23.0770 4208  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\\Windows\\system32\\DRIVERS\\ql40xx.sys

02:09:23.0785 4208  ql40xx - ok

02:09:23.0816 4208  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE           C:\\Windows\\system32\\qwave.dll

02:09:23.0863 4208  QWAVE - ok

02:09:23.0879 4208  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\\Windows\\system32\\drivers\\qwavedrv.sys

02:09:23.0894 4208  QWAVEdrv - ok

02:09:23.0910 4208  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\\Windows\\system32\\DRIVERS\\rasacd.sys

02:09:23.0910 4208  RasAcd - ok

02:09:23.0957 4208  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn     C:\\Windows\\system32\\DRIVERS\\AgileVpn.sys

02:09:23.0957 4208  RasAgileVpn - ok

02:09:23.0988 4208  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto         C:\\Windows\\System32\\rasauto.dll

02:09:24.0019 4208  RasAuto - ok

02:09:24.0050 4208  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp         C:\\Windows\\system32\\DRIVERS\\rasl2tp.sys

02:09:24.0066 4208  Rasl2tp - ok

02:09:24.0097 4208  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\\Windows\\System32\\rasmans.dll

02:09:24.0144 4208  RasMan - ok

02:09:24.0175 4208  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\\Windows\\system32\\DRIVERS\\raspppoe.sys

02:09:24.0175 4208  RasPppoe - ok

02:09:24.0206 4208  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp         C:\\Windows\\system32\\DRIVERS\\rassstp.sys

02:09:24.0222 4208  RasSstp - ok

02:09:24.0253 4208  [ 77F665941019A1594D887A74F301FA2F ] rdbss           C:\\Windows\\system32\\DRIVERS\\rdbss.sys

02:09:24.0284 4208  rdbss - ok

02:09:24.0300 4208  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\\Windows\\system32\\DRIVERS\\rdpbus.sys

02:09:24.0316 4208  rdpbus - ok

02:09:24.0331 4208  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\\Windows\\system32\\DRIVERS\\RDPCDD.sys

02:09:24.0331 4208  RDPCDD - ok

02:09:24.0378 4208  [ 1B6163C503398B23FF8B939C67747683 ] RDPDR           C:\\Windows\\system32\\drivers\\rdpdr.sys

02:09:24.0409 4208  RDPDR - ok

02:09:24.0440 4208  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\\Windows\\system32\\drivers\\rdpencdd.sys

02:09:24.0440 4208  RDPENCDD - ok

02:09:24.0472 4208  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\\Windows\\system32\\drivers\\rdprefmp.sys

02:09:24.0472 4208  RDPREFMP - ok

02:09:24.0518 4208  [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\\Windows\\system32\\drivers\\rdpvideominiport.sys

02:09:24.0518 4208  RdpVideoMiniport - ok

02:09:24.0550 4208  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD           C:\\Windows\\system32\\drivers\\RDPWD.sys

02:09:24.0581 4208  RDPWD - ok

02:09:24.0612 4208  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost    
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: guestolo on August 09, 2013, 06:23:16 PM

Just waiting on the ComboFix log now


Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on August 11, 2013, 12:05:21 AM
Guestolo i was trying to paste the log but getting errors

so i have attached it with post plz see attachment
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: faraz on August 11, 2013, 12:07:00 AM

and yes pc is mine as you can see from my name & pc user name ..... how ever i managed to get my password recover as i completly forgot 


Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: guestolo on August 30, 2013, 11:08:45 AM
I was out of town without internet... Are you still around?
How are things now running?
Title: System is popping up continously infected with Trojan Gamethief.Win32.
Post by: guestolo on September 09, 2013, 01:10:43 PM

I\'ll lock this topic as the original starter  has not returned, If you do return


please PM me and I\'ll reopen the topic