Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy
3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free
%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)
Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS
Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS
Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS
Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days
PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe
PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe
PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE
PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe
PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe
PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe
PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe
PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe
MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll
SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)
SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)
SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)
SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)
SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)
SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)
SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)
SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)
SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)
SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)
SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)
SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)
SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)
DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)
IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01 [binary data]
IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found
IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37
FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()
FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)
FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins
[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions
[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions
[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}
[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions
[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll
[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml
[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll
CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL
CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll
CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll
CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll
CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\
CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\
CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\
CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\
CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\
CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\
CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\
CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\
CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\
CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\
CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\
CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\
CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\
CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak
CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\
O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)
O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.
O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)
O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found
O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found
O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found
O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()
O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)
O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found
O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe
O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto
O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe
O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe
[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe
[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro
[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis
[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe
[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL
[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL
[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo
[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO
[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo
[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo
[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll
[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013
[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll
[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys
[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys
[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab
[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security
[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security
[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs
[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero
[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero
[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll
[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll
[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll
[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll
[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll
[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll
[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead
[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps
[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps
[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys
[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices
[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer
[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager
[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager
[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro
[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen
[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll
[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll
[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro
[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro
[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF
[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia
[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java
[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe
[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe
[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe
[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll
[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys
[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll
[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll
[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll
[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll
[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll
[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll
[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll
[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll
[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe
[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll
[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll
[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll
[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll
[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll
[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll
[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll
[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll
[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll
[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll
[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe
[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll
[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe
[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll
[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll
[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe
[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll
[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll
[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll
[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll
[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll
[2013/05/06 01:53:19 | 000,
Can you do the following:
You appear to be running 2 antivirus software, both battling against each other possibly even do more harm than good
I see
COMODO Internet Security
and
Kaspersky Anti-Virus 2013
Why don\'t you uninstall one of them, keep the one your happiest with
NOTE: It may be best to disable the Protection of the one your going to keep so it
won\'t interfere with the uninstall process
Reboot the computer afterwards
Back in Windows. Temporarily keep your AV protection disable
Run another scan with OTL.exe and post the log that opens afterwards
OTL logfile created on: 03/Aug/13 11:38:56 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\\Users\\Faraz\\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy
3.91 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 58.89% Memory free
7.82 Gb Paging File | 6.15 Gb Available in Paging File | 78.69% Paging File free
Paging file location(s): ?:\\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)
Drive C: | 48.73 Gb Total Space | 7.81 Gb Free Space | 16.03% Space Free | Partition Type: NTFS
Drive D: | 48.83 Gb Total Space | 2.40 Gb Free Space | 4.92% Space Free | Partition Type: NTFS
Drive E: | 368.10 Gb Total Space | 32.71 Gb Free Space | 8.89% Space Free | Partition Type: NTFS
Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe
PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe
PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE
PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe
PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe
PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe
PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe
PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe
========== Modules (No Company Name) ==========
MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll
========== Services (SafeList) ==========
SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)
SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)
SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)
SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)
SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)
SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)
SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)
SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)
SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)
SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)
SRV - [2010/11/20 17:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)
SRV - [2010/11/20 17:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)
SRV - [2010/11/20 17:18:03 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)
SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)
SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)
SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)
SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)
SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)
DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)
DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)
DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)
DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)
DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)
DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)
DRV:64bit: - [2012/03/01 11:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)
DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/03/11 11:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 11:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)
DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)
DRV:64bit: - [2010/11/20 18:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 16:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 16:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/20 15:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)
DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)
DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)
DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)
DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)
DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)
DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)
DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)
DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)
DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)
DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)
DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank
IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope =
IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm
IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank
IE - HKLM\\..\\SearchScopes,DefaultScope =
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01 [binary data]
IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found
IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found
IE - HKCU\\..\\SearchScopes,DefaultScope =
IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37
FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"
FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"
FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"
FF - user.js - File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()
FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)
FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\
[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins
FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\
[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\
[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]
[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions
[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions
[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}
[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions
[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\
[email protected]
[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll
[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml
[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\
CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\
CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\
CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\
CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak
O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)
O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.
O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)
O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)
O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found
O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found
O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found
O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found
O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found
O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()
O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()
O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found
O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found
O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found
O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)
O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found
O18 - Protocol\\Filter\\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\\PROGRA~2\\COMMON~1\\MICROS~1\\OFFICE12\\MSOXMLMF.DLL File not found
O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)
O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)
O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe
O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto
O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe
O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*
O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*
O35 - HKLM\\..comfile [open] -- \"%1\" %*
O35 - HKLM\\..exefile [open] -- \"%1\" %*
O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*
O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*
O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*
O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/08/01 23:20:32 | 000,000,000 | ---D | C] -- C:\\Windows\\SysNative\\SPReview
[2013/08/01 23:19:26 | 000,000,000 | ---D | C] -- C:\\Windows\\SysNative\\EventProviders
[2013/08/01 23:19:14 | 000,000,000 | ---D | C] -- C:\\3ca1477372be1ce35eb66ac4b2
[2013/07/29 11:51:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\T
[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT
[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe
[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro
[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis
[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe
[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL
[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL
========== Files - Modified Within 30 Days ==========
[2013/08/03 23:35:53 | 000,019,184 | -H-- | M] () -- C:\\Windows\\SysNative\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/03 23:35:53 | 000,019,184 | -H-- | M] () -- C:\\Windows\\SysNative\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/03 23:30:30 | 000,067,584 | --S- | M] () -- C:\\Windows\\bootstat.dat
[2013/08/03 23:30:23 | 3148,218,368 | -HS- | M] () -- C:\\hiberfil.sys
[2013/08/03 23:22:06 | 000,000,830 | ---- | M] () -- C:\\Windows\\tasks\\Adobe Flash Player Updater.job
[2013/08/03 23:08:28 | 000,986,742 | ---- | M] () -- C:\\Windows\\SysNative\\PerfStringBackup.INI
[2013/08/03 23:08:28 | 000,815,680 | ---- | M] () -- C:\\Windows\\SysNative\\perfh009.dat
[2013/08/03 23:08:28 | 000,169,078 | ---- | M] () -- C:\\Windows\\SysNative\\perfc009.dat
[2013/08/03 23:07:02 | 000,000,908 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000UA.job
[2013/08/03 22:00:15 | 000,000,928 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000UA.job
[2013/08/03 11:55:03 | 000,000,856 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000Core.job
[2013/08/03 01:00:02 | 000,000,906 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000Core.job
[2013/08/02 22:21:22 | 000,002,361 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Google Chrome.lnk
[2013/08/02 21:17:57 | 000,344,816 | ---- | M] () -- C:\\Windows\\SysNative\\FNTCACHE.DAT
[2013/08/01 23:41:46 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\msclmd.dll
[2013/08/01 23:41:45 | 000,175,616 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msclmd.dll
[2013/07/25 04:38:36 | 000,000,105 | ---- | M] () -- C:\\Windows\\DeleteOnReboot.bat
[2013/07/25 04:20:28 | 000,666,633 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\AdwCleaner.exe
[2013/07/25 04:19:54 | 000,560,934 | ---- | M] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe
[2013/07/24 19:03:10 | 000,002,975 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\HiJackThis.lnk
[2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe
[2013/07/21 00:18:49 | 000,000,866 | ---- | M] () -- C:\\Users\\Public\\Desktop\\EVDO BROADBAND PTCL.lnk
[2013/07/20 10:48:19 | 000,000,600 | ---- | M] () -- C:\\Users\\Faraz\\PUTTY.RND
[2013/07/20 10:23:20 | 000,580,227 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\How To Hack Any Email Account.pdf
[2013/07/20 09:03:30 | 000,242,310 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\[Tutorial] Disinfecting and Hacking a Keylogger ~ Software Zone.pdf
[2013/07/19 17:23:55 | 001,474,832 | ---- | M] () -- C:\\Windows\\SysNative\\drivers\\sfi.dat
[2013/07/19 16:51:11 | 000,222,725 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Untitled.jpg
[2013/07/18 00:54:17 | 000,441,269 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Q\'s Blog.pdf
[2013/07/16 16:29:58 | 000,174,956 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\HR Q & A.pdf
[2013/07/12 02:14:50 | 001,501,408 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Understanding The Differ..._ Simple Small Business.pdf
[2013/07/12 01:59:48 | 000,644,296 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Markup vs. Margin. What ...rence_ – Consero Global.pdf
[2013/07/12 01:54:42 | 002,197,905 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Gross margin .pdf
[2013/07/10 23:38:42 | 000,001,922 | ---- | M] () -- C:\\Users\\Public\\Desktop\\Nitro Pro 8.lnk
========== Files Created - No Company Name ==========
[2013/07/25 04:36:43 | 000,000,105 | ---- | C] () -- C:\\Windows\\DeleteOnReboot.bat
[2013/07/25 04:33:26 | 000,666,633 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\AdwCleaner.exe
[2013/07/24 19:03:10 | 000,002,975 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\HiJackThis.lnk
[2013/07/21 00:18:49 | 000,000,866 | ---- | C] () -- C:\\Users\\Public\\Desktop\\EVDO BROADBAND PTCL.lnk
[2013/07/20 10:23:20 | 000,580,227 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\How To Hack Any Email Account.pdf
[2013/07/20 09:03:23 | 000,242,310 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\[Tutorial] Disinfecting and Hacking a Keylogger ~ Software Zone.pdf
[2013/07/18 00:52:53 | 000,441,269 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Q\'s Blog.pdf
[2013/07/16 16:29:21 | 000,174,956 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\HR Q & A.pdf
[2013/07/15 16:16:24 | 002,197,905 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Gross margin .pdf
[2013/07/15 16:16:24 | 001,501,408 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Understanding The Differ..._ Simple Small Business.pdf
[2013/07/15 16:16:24 | 000,644,296 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Markup vs. Margin. What ...rence_ – Consero Global.pdf
[2013/06/27 12:18:04 | 000,033,576 | ---- | C] () -- C:\\Windows\\SysWow64\\BCGPOleAcc.dll
[2013/06/17 14:22:10 | 000,003,441 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\lgr
[2013/06/16 20:21:28 | 000,000,884 | RHS- | C] () -- C:\\Users\\Faraz\\ntuser.pol
[2013/05/31 12:10:39 | 000,007,605 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Local\\Resmon.ResmonCfg
[2013/03/29 14:37:29 | 000,000,004 | ---- | C] () -- C:\\Windows\\vx86036.dat
[2013/03/29 14:36:01 | 000,000,054 | ---- | C] () -- C:\\Windows\\Crypkey.ini
[2013/03/29 14:35:58 | 000,011,776 | ---- | C] () -- C:\\Windows\\Ckrfresh.exe
[2013/03/09 00:05:20 | 000,000,009 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\WinAcc.EML
[2013/03/08 23:59:52 | 000,017,920 | ---- | C] () -- C:\\Windows\\SysWow64\\implode.dll
[2012/08/26 01:49:44 | 000,000,022 | ---- | C] () -- C:\\Windows\\Wininit.ini
[2012/08/05 21:58:10 | 000,002,016 | -HS- | C] () -- C:\\Windows\\SysWow64\\win_fp_sys.dat
[2012/08/05 21:47:33 | 000,000,000 | -HS- | C] () -- C:\\Windows\\SysWow64\\win_fp_app.dat
[2012/08/05 21:47:30 | 000,007,168 | ---- | C] () -- C:\\Windows\\SysWow64\\FPService.exe
[2012/08/05 21:47:29 | 000,116,944 | ---- | C] () -- C:\\Windows\\Secure.dll
[2012/08/05 21:47:29 | 000,110,800 | ---- | C] () -- C:\\Windows\\Secure64.dll
[2012/08/05 21:47:29 | 000,035,840 | ---- | C] () -- C:\\Windows\\SysWow64\\WinFPdrv.sys
[2012/08/05 21:47:29 | 000,008,064 | -HS- | C] () -- C:\\Windows\\SysWow64\\win_fp_config.dat
[2012/08/04 22:11:41 | 000,000,327 | ---- | C] () -- C:\\Windows\\dvdcreator.INI
[2012/08/04 22:07:20 | 000,014,496 | ---- | C] () -- C:\\Windows\\SysWow64\\VDI08X.DAT
[2012/08/04 22:04:00 | 000,135,168 | ---- | C] () -- C:\\Windows\\SysWow64\\VDProductInfoEx.dll
[2012/08/02 01:37:56 | 000,149,504 | ---- | C] () -- C:\\Windows\\SysWow64\\UNWISE.EXE
[2011/10/12 01:02:54 | 000,006,656 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Local\\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/10 23:25:18 | 000,000,000 | ---- | C] () -- C:\\Windows\\SysWow64\\cd.dat
[2011/09/27 00:18:38 | 000,037,647 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\Debut.dmp
[2011/09/01 17:06:21 | 000,000,600 | ---- | C] () -- C:\\Users\\Faraz\\PUTTY.RND
[2011/08/13 23:07:15 | 000,000,990 | -HS- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\systemfl.$dk
========== ZeroAccess Check ==========
[2011/11/17 12:14:10 | 000,002,048 | -HS- | M] () -- C:\\Windows\\Installer\\{7c0eee1f-7b7e-6235-9f22-0f2dea83d0ae}\\@
[2013/07/03 16:10:09 | 000,000,000 | -HSD | M] -- C:\\Windows\\Installer\\{7c0eee1f-7b7e-6235-9f22-0f2dea83d0ae}\\L
[2013/04/19 11:30:38 | 000,000,000 | -HSD | M] -- C:\\Windows\\Installer\\{7c0eee1f-7b7e-6235-9f22-0f2dea83d0ae}\\U
[2009/07/14 09:55:00 | 000,000,227 | RHS- | M] () -- C:\\Windows\\assembly\\Desktop.ini
[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32] /64
[HKEY_CURRENT_USER\\Software\\Classes\\Wow6432node\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]
[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32] /64
[HKEY_CURRENT_USER\\Software\\Classes\\Wow6432node\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32]
[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32] /64
\"\" = C:\\Windows\\SysNative\\shell32.dll -- [2012/06/09 10:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Apartment
[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]
\"\" = %SystemRoot%\\system32\\shell32.dll -- [2012/06/09 09:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Apartment
[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32] /64
\"\" = C:\\Windows\\SysNative\\wbem\\fastprox.dll -- [2009/07/14 06:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Free
[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32]
\"\" = %systemroot%\\system32\\wbem\\fastprox.dll -- [2010/11/20 17:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Free
[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32] /64
\"\" = C:\\Windows\\SysNative\\wbem\\wbemess.dll -- [2009/07/14 06:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Both
[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32]
< End of report >
Again the Extras.txt didn\'t popped up & also it is not on desktop
what should i do ?
Don\'t worry about Extra.txt
It wasn\'t needed or asked to popup... We\'ll set OTL to run it if needed
Right click on OTL.exe and choose to \"Run as Admin....\" allow to run
- Under the Custom Scans/Fixes box at the bottom, copy/paste in the following in the quote box below. don\'t include the word Quote please
:OTL
IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found
IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found
O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found
O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.
O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found
O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found
O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found
O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found
O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found
O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe
O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto
O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe
O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe
:Commands
[EmptyTemp]
[Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
On startup, Allow OTL to run if prompted
A log should open, can you post it please
A copy of this log can also be found in
C:\\_OTL\\Moved Files folder
Let me know how things are running please
All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08d6b0b4-c132-470d-a8e2-aa2e9c3851c9}\\ not found.
Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\\ not found.
Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{c34bfb11-eff0-4123-a7a5-79051ef24cf5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{c34bfb11-eff0-4123-a7a5-79051ef24cf5}\\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{98ED5451-2AA6-96DB-7012-46C7C9673C57}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{98ED5451-2AA6-96DB-7012-46C7C9673C57}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{C08DF07A-3E49-4E25-9AB0-D3882835F153}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C08DF07A-3E49-4E25-9AB0-D3882835F153}\\ deleted successfully.
Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08D6B0B4-C132-470D-A8E2-AA2E9C3851C9}\\ not found.
Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}\\ not found.
Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{C34BFB11-EFF0-4123-A7A5-79051EF24CF5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C34BFB11-EFF0-4123-A7A5-79051EF24CF5}\\ not found.
Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\IDMan deleted successfully.
64bit-Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download all links with IDM\\ deleted successfully.
64bit-Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download with IDM\\ deleted successfully.
64bit-Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\QuickDefine\\ deleted successfully.
C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm moved successfully.
Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download all links with IDM\\ not found.
Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download with IDM\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ not found.
File I:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ not found.
File G:\\Setup.exe /Auto not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ not found.
File H:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ not found.
File G:\\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ not found.
File I:\\AutoRun.exe not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: AppData
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56466 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Faraz
->Temp folder emptied: 13298084 bytes
->Temporary Internet Files folder emptied: 1482353368 bytes
->Java cache emptied: 23858 bytes
->FireFox cache emptied: 66979817 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 14912678 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\\System32 .tmp files removed: 0 bytes
%systemroot%\\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\\System32\\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 63117321 bytes
%systemroot%\\sysnative\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files folder emptied: 100669 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1,565.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 08042013_174319
Files\\Folders moved on Reboot...
C:\\Users\\Faraz\\AppData\\Local\\Temp\\FXSAPIDebugLogFile.txt moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
system seems to be running good now........ but
- i have doubts of some keylogger or hacking backdoor file presence on my system,as my system got hacked recently & he stole all my personal files and after that he hacked all my working email ids
have you found any such traces on my system after these logs.....
- and i am also seeing some hidden desktop.ini files in almost each folder & dektop ....what is this ?
and i am also seeing some hidden desktop.ini files in almost each folder & dektop ....
You probably have windows set to show hidden files/folders
Not a big worry, we\'ll deal with that in a bit
You can open Adwcleaner and click the Uninstall button
Can you temporarily disable your Spyware/Virus protections
Let\'s run a couple more tools
Download TDSSKiller:
http://support.kaspersky.com/downloads/utils/tdsskiller.exe
Save it to your desktop then double click on it to run it
Click the START SCAN, when done
If TDSSKiller alerts you that the system needs to reboot, please consent.
When done, a log file should be created on your C: drive named \"TDSSKiller.txt\" please copy and paste the contents in your next reply.
In addition:
Download ComboFix from the following location
Link 1
Save it ONLY to your Desktop
Double click on ComboFix to run it, follow the prompts
Click on Yes, to continue scanning for malware if prompted
When finished, it shall produce a log for you. Please include the C:\\ComboFix.txt in your next reply
NOTE: Do not mouseclick inside ComboFix window as it\'s running, it may cause it to stall
ComboFix will/may run again on startup, it will prompt that it\'s creating a log
This process could take up to 10 minutes, let it run uninterrupted please
sorry Guestolo m late on response
but i had changed my laptop password & forget it unfortunately
can you please first guide me how to remove the password i have checked & done some tutorials form internet but failed to do so ...
please its off the topic but guide me to remove the pasword so i could perform your asked steps from last post
Thanks
Do you have another Admin account on the computer you can login to and remove the password on your account?
We may have to enable the hidden Admin account and use it to remove the password
This is your computer right?
02:08:26.0181 2420 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
02:08:26.0337 2420 ============================================================
02:08:26.0337 2420 Current date / time: 2013/08/10 02:08:26.0337
02:08:26.0337 2420 SystemInfo:
02:08:26.0337 2420
02:08:26.0337 2420 OS Version: 6.1.7601 ServicePack: 1.0
02:08:26.0337 2420 Product type: Workstation
02:08:26.0337 2420 ComputerName: SLAIN
02:08:26.0337 2420 UserName: Faraz
02:08:26.0337 2420 Windows directory: C:\\Windows
02:08:26.0337 2420 System windows directory: C:\\Windows
02:08:26.0337 2420 Running under WOW64
02:08:26.0337 2420 Processor architecture: Intel x64
02:08:26.0337 2420 Number of processors: 4
02:08:26.0337 2420 Page size: 0x1000
02:08:26.0337 2420 Boot type: Normal boot
02:08:26.0337 2420 ============================================================
02:08:30.0698 2420 Drive \\Device\\Harddisk0\\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type \'K0\', Flags 0x00000040
02:08:30.0714 2420 ============================================================
02:08:30.0714 2420 \\Device\\Harddisk0\\DR0:
02:08:30.0714 2420 MBR partitions:
02:08:30.0714 2420 \\Device\\Harddisk0\\DR0\\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
02:08:30.0714 2420 \\Device\\Harddisk0\\DR0\\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x6176000
02:08:30.0714 2420 \\Device\\Harddisk0\\DR0\\Partition3: MBR, Type 0x7, StartLBA 0x61A8800, BlocksNum 0x61A8000
02:08:30.0714 2420 \\Device\\Harddisk0\\DR0\\Partition4: MBR, Type 0x7, StartLBA 0xC350800, BlocksNum 0x2E035000
02:08:30.0714 2420 ============================================================
02:08:30.0730 2420 C: <-> \\Device\\Harddisk0\\DR0\\Partition2
02:08:30.0776 2420 D: <-> \\Device\\Harddisk0\\DR0\\Partition3
02:08:30.0808 2420 E: <-> \\Device\\Harddisk0\\DR0\\Partition4
02:08:30.0808 2420 ============================================================
02:08:30.0808 2420 Initialize success
02:08:30.0808 2420 ============================================================
02:09:02.0054 4208 ============================================================
02:09:02.0054 4208 Scan started
02:09:02.0054 4208 Mode: Manual;
02:09:02.0054 4208 ============================================================
02:09:03.0068 4208 ================ Scan system memory ========================
02:09:03.0068 4208 System memory - ok
02:09:03.0068 4208 ================ Scan services =============================
02:09:03.0209 4208 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\\Windows\\system32\\drivers\\1394ohci.sys
02:09:03.0224 4208 1394ohci - ok
02:09:03.0256 4208 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\\Windows\\system32\\drivers\\ACPI.sys
02:09:03.0256 4208 ACPI - ok
02:09:03.0287 4208 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\\Windows\\system32\\drivers\\acpipmi.sys
02:09:03.0287 4208 AcpiPmi - ok
02:09:03.0396 4208 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe
02:09:03.0412 4208 AdobeFlashPlayerUpdateSvc - ok
02:09:03.0458 4208 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\\Windows\\system32\\DRIVERS\\adp94xx.sys
02:09:03.0490 4208 adp94xx - ok
02:09:03.0505 4208 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\\Windows\\system32\\DRIVERS\\adpahci.sys
02:09:03.0521 4208 adpahci - ok
02:09:03.0536 4208 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\\Windows\\system32\\DRIVERS\\adpu320.sys
02:09:03.0552 4208 adpu320 - ok
02:09:03.0583 4208 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\\Windows\\System32\\aelupsvc.dll
02:09:03.0599 4208 AeLookupSvc - ok
02:09:03.0630 4208 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\\Windows\\system32\\drivers\\afd.sys
02:09:03.0677 4208 AFD - ok
02:09:03.0708 4208 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\\Windows\\system32\\drivers\\agp440.sys
02:09:03.0708 4208 agp440 - ok
02:09:03.0739 4208 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\\Windows\\System32\\alg.exe
02:09:03.0739 4208 ALG - ok
02:09:03.0770 4208 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\\Windows\\system32\\drivers\\aliide.sys
02:09:03.0770 4208 aliide - ok
02:09:03.0770 4208 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\\Windows\\system32\\drivers\\amdide.sys
02:09:03.0786 4208 amdide - ok
02:09:03.0802 4208 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\\Windows\\system32\\DRIVERS\\amdk8.sys
02:09:03.0802 4208 AmdK8 - ok
02:09:03.0833 4208 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\\Windows\\system32\\DRIVERS\\amdppm.sys
02:09:03.0833 4208 AmdPPM - ok
02:09:03.0864 4208 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\\Windows\\system32\\drivers\\amdsata.sys
02:09:03.0880 4208 amdsata - ok
02:09:03.0895 4208 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\\Windows\\system32\\DRIVERS\\amdsbs.sys
02:09:03.0911 4208 amdsbs - ok
02:09:03.0926 4208 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\\Windows\\system32\\drivers\\amdxata.sys
02:09:03.0926 4208 amdxata - ok
02:09:03.0942 4208 apcrybwd - ok
02:09:03.0989 4208 [ 24ED0EB2B2558970176ECEE680F8F806 ] ApfiltrService C:\\Windows\\system32\\DRIVERS\\Apfiltr.sys
02:09:04.0004 4208 ApfiltrService - ok
02:09:04.0067 4208 [ 59D01FA91962C9C1E9B4022B2D3B46DB ] AppHostSvc C:\\Windows\\system32\\inetsrv\\apphostsvc.dll
02:09:04.0067 4208 AppHostSvc - ok
02:09:04.0114 4208 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\\Windows\\system32\\drivers\\appid.sys
02:09:04.0129 4208 AppID - ok
02:09:04.0160 4208 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\\Windows\\System32\\appidsvc.dll
02:09:04.0160 4208 AppIDSvc - ok
02:09:04.0192 4208 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\\Windows\\System32\\appinfo.dll
02:09:04.0192 4208 Appinfo - ok
02:09:04.0223 4208 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\\Windows\\System32\\appmgmts.dll
02:09:04.0238 4208 AppMgmt - ok
02:09:04.0270 4208 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\\Windows\\system32\\DRIVERS\\arc.sys
02:09:04.0270 4208 arc - ok
02:09:04.0285 4208 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\\Windows\\system32\\DRIVERS\\arcsas.sys
02:09:04.0301 4208 arcsas - ok
02:09:04.0348 4208 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\\Windows\\system32\\DRIVERS\\asyncmac.sys
02:09:04.0348 4208 AsyncMac - ok
02:09:04.0379 4208 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\\Windows\\system32\\drivers\\atapi.sys
02:09:04.0379 4208 atapi - ok
02:09:04.0410 4208 [ CBE61B4494165F458BD87E37181EE934 ] AthBTPort C:\\Windows\\system32\\DRIVERS\\btath_flt.sys
02:09:04.0410 4208 AthBTPort - ok
02:09:04.0488 4208 [ 67B8BD46E8626C348688930244761DAB ] Atheros Bt&Wlan Coex Agent C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe
02:09:04.0722 4208 Atheros Bt&Wlan Coex Agent - ok
02:09:04.0784 4208 [ 8430ED17CEF0D7878B25776E02508957 ] AtherosSvc C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\adminservice.exe
02:09:04.0784 4208 AtherosSvc - ok
02:09:04.0878 4208 [ 782D36BAD8DDBF008D02E055DBE70F82 ] athr C:\\Windows\\system32\\DRIVERS\\athrx.sys
02:09:04.0956 4208 athr - ok
02:09:05.0034 4208 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\\Windows\\System32\\Audiosrv.dll
02:09:05.0065 4208 AudioEndpointBuilder - ok
02:09:05.0096 4208 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\\Windows\\System32\\Audiosrv.dll
02:09:05.0112 4208 AudioSrv - ok
02:09:05.0143 4208 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\\Windows\\System32\\AxInstSV.dll
02:09:05.0159 4208 AxInstSV - ok
02:09:05.0190 4208 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\\Windows\\system32\\DRIVERS\\bxvbda.sys
02:09:05.0221 4208 b06bdrv - ok
02:09:05.0252 4208 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\\Windows\\system32\\DRIVERS\\b57nd60a.sys
02:09:05.0252 4208 b57nd60a - ok
02:09:05.0284 4208 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\\Windows\\System32\\bdesvc.dll
02:09:05.0299 4208 BDESVC - ok
02:09:05.0315 4208 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\\Windows\\system32\\drivers\\Beep.sys
02:09:05.0315 4208 Beep - ok
02:09:05.0377 4208 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\\Windows\\System32\\bfe.dll
02:09:05.0408 4208 BFE - ok
02:09:05.0440 4208 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\\Windows\\System32\\qmgr.dll
02:09:05.0502 4208 BITS - ok
02:09:05.0518 4208 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\\Windows\\system32\\DRIVERS\\blbdrive.sys
02:09:05.0533 4208 blbdrive - ok
02:09:05.0627 4208 [ 093B1B419EF25B15D3A1CA6953F41AFB ] Bluetooth Device Monitor C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe
02:09:05.0674 4208 Bluetooth Device Monitor - ok
02:09:05.0736 4208 [ 03A7341E94ACD92E0831336D4F3ACE92 ] Bluetooth Media Service C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe
02:09:06.0064 4208 Bluetooth Media Service - ok
02:09:06.0110 4208 [ A2EBF384ED105FED7D05C5465500EF2E ] Bluetooth OBEX Service C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe
02:09:06.0422 4208 Bluetooth OBEX Service - ok
02:09:06.0485 4208 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\\Windows\\system32\\DRIVERS\\bowser.sys
02:09:06.0485 4208 bowser - ok
02:09:06.0516 4208 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\\Windows\\system32\\DRIVERS\\BrFiltLo.sys
02:09:06.0516 4208 BrFiltLo - ok
02:09:06.0532 4208 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\\Windows\\system32\\DRIVERS\\BrFiltUp.sys
02:09:06.0532 4208 BrFiltUp - ok
02:09:06.0563 4208 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\\Windows\\System32\\browser.dll
02:09:06.0594 4208 Browser - ok
02:09:06.0625 4208 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\\Windows\\System32\\Drivers\\Brserid.sys
02:09:06.0625 4208 Brserid - ok
02:09:06.0641 4208 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\\Windows\\System32\\Drivers\\BrSerWdm.sys
02:09:06.0656 4208 BrSerWdm - ok
02:09:06.0672 4208 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\\Windows\\System32\\Drivers\\BrUsbMdm.sys
02:09:06.0672 4208 BrUsbMdm - ok
02:09:06.0672 4208 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\\Windows\\System32\\Drivers\\BrUsbSer.sys
02:09:06.0688 4208 BrUsbSer - ok
02:09:06.0766 4208 [ 227C8F308DE4AF4808E587465CEAB838 ] BTATH_A2DP C:\\Windows\\system32\\drivers\\btath_a2dp.sys
02:09:06.0766 4208 BTATH_A2DP - ok
02:09:06.0781 4208 [ A83A91D07D1FE6BBE7A9DB46CA00434B ] BTATH_BUS C:\\Windows\\system32\\DRIVERS\\btath_bus.sys
02:09:06.0781 4208 BTATH_BUS - ok
02:09:06.0812 4208 [ C864FF85EE16D61C2BDD5EF76824625F ] BTATH_HCRP C:\\Windows\\system32\\DRIVERS\\btath_hcrp.sys
02:09:06.0828 4208 BTATH_HCRP - ok
02:09:06.0844 4208 [ 0DEA505EFB5D771826D177EF8B8A208F ] BTATH_LWFLT C:\\Windows\\system32\\DRIVERS\\btath_lwflt.sys
02:09:06.0844 4208 BTATH_LWFLT - ok
02:09:06.0859 4208 [ 724C8088C96EFE7A3E63FEC21D4681C0 ] BTATH_RCP C:\\Windows\\system32\\DRIVERS\\btath_rcp.sys
02:09:06.0859 4208 BTATH_RCP - ok
02:09:06.0906 4208 [ 486720DA2B3BB13D1080C83140C18B56 ] BtFilter C:\\Windows\\system32\\DRIVERS\\btfilter.sys
02:09:06.0922 4208 BtFilter - ok
02:09:06.0953 4208 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\\Windows\\system32\\drivers\\BthEnum.sys
02:09:06.0968 4208 BthEnum - ok
02:09:06.0984 4208 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\\Windows\\system32\\DRIVERS\\bthmodem.sys
02:09:07.0000 4208 BTHMODEM - ok
02:09:07.0031 4208 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\\Windows\\system32\\DRIVERS\\bthpan.sys
02:09:07.0031 4208 BthPan - ok
02:09:07.0062 4208 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\\Windows\\System32\\Drivers\\BTHport.sys
02:09:07.0093 4208 BTHPORT - ok
02:09:07.0124 4208 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\\Windows\\system32\\bthserv.dll
02:09:07.0124 4208 bthserv - ok
02:09:07.0156 4208 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\\Windows\\System32\\Drivers\\BTHUSB.sys
02:09:07.0156 4208 BTHUSB - ok
02:09:07.0171 4208 [ 16C1BAC9760C9FA85A30F3FA0FBB1B7A ] btmaux C:\\Windows\\system32\\DRIVERS\\btmaux.sys
02:09:07.0187 4208 btmaux - ok
02:09:07.0202 4208 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\\Windows\\system32\\DRIVERS\\cdfs.sys
02:09:07.0218 4208 cdfs - ok
02:09:07.0265 4208 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\\Windows\\system32\\DRIVERS\\cdrom.sys
02:09:07.0265 4208 cdrom - ok
02:09:07.0312 4208 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\\Windows\\System32\\certprop.dll
02:09:07.0327 4208 CertPropSvc - ok
02:09:07.0358 4208 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\\Windows\\system32\\DRIVERS\\circlass.sys
02:09:07.0358 4208 circlass - ok
02:09:07.0390 4208 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\\Windows\\system32\\CLFS.sys
02:09:07.0405 4208 CLFS - ok
02:09:07.0514 4208 [ 882E3973505C441CE000133C821D0EDD ] CLPSLS C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe
02:09:07.0546 4208 CLPSLS - ok
02:09:07.0608 4208 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe
02:09:07.0608 4208 clr_optimization_v2.0.50727_32 - ok
02:09:07.0655 4208 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe
02:09:07.0670 4208 clr_optimization_v2.0.50727_64 - ok
02:09:07.0702 4208 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\\Windows\\system32\\DRIVERS\\CmBatt.sys
02:09:07.0717 4208 CmBatt - ok
02:09:07.0795 4208 [ 65FB5097D9EE7E3A99E932CFA0E4B344 ] cmdAgent C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe
02:09:07.0842 4208 cmdAgent - ok
02:09:07.0858 4208 [ 2D6DC31AA55BFF702519235DEF0DA68E ] cmderd C:\\Windows\\system32\\DRIVERS\\cmderd.sys
02:09:07.0873 4208 cmderd - ok
02:09:07.0904 4208 [ 919ACCC22ABDC1C3CA68326C0E5DEAF9 ] cmdGuard C:\\Windows\\system32\\DRIVERS\\cmdguard.sys
02:09:07.0904 4208 cmdGuard - ok
02:09:07.0936 4208 [ F8FECE0F1D44C4A58778083B00EEADAC ] cmdHlp C:\\Windows\\system32\\DRIVERS\\cmdhlp.sys
02:09:07.0936 4208 cmdHlp - ok
02:09:07.0967 4208 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\\Windows\\system32\\drivers\\cmdide.sys
02:09:07.0967 4208 cmdide - ok
02:09:08.0014 4208 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\\Windows\\system32\\Drivers\\cng.sys
02:09:08.0045 4208 CNG - ok
02:09:08.0076 4208 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\\Windows\\system32\\DRIVERS\\compbatt.sys
02:09:08.0076 4208 Compbatt - ok
02:09:08.0123 4208 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\\Windows\\system32\\drivers\\CompositeBus.sys
02:09:08.0123 4208 CompositeBus - ok
02:09:08.0138 4208 COMSysApp - ok
02:09:08.0170 4208 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\\Windows\\system32\\DRIVERS\\crcdisk.sys
02:09:08.0170 4208 crcdisk - ok
02:09:08.0232 4208 [ 2177A0F611584BCA1DFDD7EEB35C0224 ] CrypKey License C:\\Windows\\system32\\crypserv.exe
02:09:08.0482 4208 CrypKey License - ok
02:09:08.0528 4208 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\\Windows\\system32\\cryptsvc.dll
02:09:08.0544 4208 CryptSvc - ok
02:09:08.0575 4208 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\\Windows\\system32\\drivers\\csc.sys
02:09:08.0606 4208 CSC - ok
02:09:08.0638 4208 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\\Windows\\System32\\cscsvc.dll
02:09:08.0669 4208 CscService - ok
02:09:08.0700 4208 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\\Windows\\system32\\rpcss.dll
02:09:08.0747 4208 DcomLaunch - ok
02:09:08.0778 4208 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\\Windows\\System32\\defragsvc.dll
02:09:08.0809 4208 defragsvc - ok
02:09:08.0840 4208 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\\Windows\\system32\\Drivers\\dfsc.sys
02:09:08.0840 4208 DfsC - ok
02:09:08.0872 4208 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\\Windows\\system32\\dhcpcore.dll
02:09:08.0887 4208 Dhcp - ok
02:09:08.0918 4208 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\\Windows\\system32\\drivers\\discache.sys
02:09:08.0918 4208 discache - ok
02:09:08.0965 4208 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\\Windows\\system32\\DRIVERS\\disk.sys
02:09:08.0965 4208 Disk - ok
02:09:08.0996 4208 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\\Windows\\System32\\dnsrslvr.dll
02:09:09.0012 4208 Dnscache - ok
02:09:09.0059 4208 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\\Windows\\System32\\dot3svc.dll
02:09:09.0090 4208 dot3svc - ok
02:09:09.0121 4208 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\\Windows\\system32\\dps.dll
02:09:09.0137 4208 DPS - ok
02:09:09.0168 4208 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\\Windows\\system32\\drivers\\drmkaud.sys
02:09:09.0184 4208 drmkaud - ok
02:09:09.0215 4208 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\\Windows\\System32\\drivers\\dxgkrnl.sys
02:09:09.0246 4208 DXGKrnl - ok
02:09:09.0277 4208 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\\Windows\\System32\\eapsvc.dll
02:09:09.0293 4208 EapHost - ok
02:09:09.0433 4208 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\\Windows\\system32\\DRIVERS\\evbda.sys
02:09:09.0527 4208 ebdrv - ok
02:09:09.0542 4208 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\\Windows\\System32\\lsass.exe
02:09:09.0574 4208 EFS - ok
02:09:09.0667 4208 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\\Windows\\ehome\\ehRecvr.exe
02:09:09.0683 4208 ehRecvr - ok
02:09:09.0730 4208 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\\Windows\\ehome\\ehsched.exe
02:09:09.0730 4208 ehSched - ok
02:09:09.0761 4208 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\\Windows\\system32\\DRIVERS\\elxstor.sys
02:09:09.0792 4208 elxstor - ok
02:09:09.0823 4208 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\\Windows\\system32\\drivers\\errdev.sys
02:09:09.0823 4208 ErrDev - ok
02:09:09.0886 4208 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\\Windows\\system32\\es.dll
02:09:09.0901 4208 EventSystem - ok
02:09:09.0979 4208 [ 2B831232C7F57FD675C9AFCA82A5CC24 ] ewusbmbb C:\\Windows\\system32\\DRIVERS\\ewusbwwan.sys
02:09:10.0010 4208 ewusbmbb - ok
02:09:10.0026 4208 ewusbnet - ok
02:09:10.0057 4208 [ 86F7951BBCEE4A86E79A97306BD14318 ] ew_hwusbdev C:\\Windows\\system32\\DRIVERS\\ew_hwusbdev.sys
02:09:10.0057 4208 ew_hwusbdev - ok
02:09:10.0088 4208 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\\Windows\\system32\\drivers\\exfat.sys
02:09:10.0104 4208 exfat - ok
02:09:10.0120 4208 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\\Windows\\system32\\drivers\\fastfat.sys
02:09:10.0135 4208 fastfat - ok
02:09:10.0182 4208 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\\Windows\\system32\\fxssvc.exe
02:09:10.0229 4208 Fax - ok
02:09:10.0260 4208 [ 240FF3619817B039198CDCD1E8DAE921 ] fcdabus C:\\Windows\\system32\\DRIVERS\\fcdabus.sys
02:09:10.0260 4208 fcdabus - ok
02:09:10.0291 4208 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\\Windows\\system32\\DRIVERS\\fdc.sys
02:09:10.0291 4208 fdc - ok
02:09:10.0322 4208 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\\Windows\\system32\\fdPHost.dll
02:09:10.0338 4208 fdPHost - ok
02:09:10.0354 4208 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\\Windows\\system32\\fdrespub.dll
02:09:10.0385 4208 FDResPub - ok
02:09:10.0400 4208 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\\Windows\\system32\\drivers\\fileinfo.sys
02:09:10.0400 4208 FileInfo - ok
02:09:10.0416 4208 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\\Windows\\system32\\drivers\\filetrace.sys
02:09:10.0432 4208 Filetrace - ok
02:09:10.0447 4208 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\\Windows\\system32\\DRIVERS\\flpydisk.sys
02:09:10.0447 4208 flpydisk - ok
02:09:10.0510 4208 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\\Windows\\system32\\drivers\\fltmgr.sys
02:09:10.0541 4208 FltMgr - ok
02:09:10.0619 4208 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\\Windows\\system32\\FntCache.dll
02:09:10.0666 4208 FontCache - ok
02:09:10.0712 4208 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe
02:09:10.0915 4208 FontCache3.0.0.0 - ok
02:09:10.0946 4208 fqtirfym - ok
02:09:10.0962 4208 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\\Windows\\system32\\drivers\\FsDepends.sys
02:09:10.0978 4208 FsDepends - ok
02:09:10.0993 4208 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\\Windows\\system32\\drivers\\Fs_Rec.sys
02:09:10.0993 4208 Fs_Rec - ok
02:09:11.0040 4208 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\\Windows\\system32\\DRIVERS\\fvevol.sys
02:09:11.0056 4208 fvevol - ok
02:09:11.0087 4208 [ C4AE69B476A40C165B6E99D10E814D0F ] FVXSCSI C:\\Windows\\system32\\DRIVERS\\fvxscsi.sys
02:09:11.0087 4208 FVXSCSI - ok
02:09:11.0134 4208 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\\Windows\\system32\\DRIVERS\\gagp30kx.sys
02:09:11.0134 4208 gagp30kx - ok
02:09:11.0149 4208 gnfjuabb - ok
02:09:11.0212 4208 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\\Windows\\System32\\gpsvc.dll
02:09:11.0258 4208 gpsvc - ok
02:09:11.0274 4208 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\\Windows\\system32\\drivers\\hcw85cir.sys
02:09:11.0274 4208 hcw85cir - ok
02:09:11.0336 4208 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\\Windows\\system32\\drivers\\HdAudio.sys
02:09:11.0352 4208 HdAudAddService - ok
02:09:11.0368 4208 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\\Windows\\system32\\drivers\\HDAudBus.sys
02:09:11.0383 4208 HDAudBus - ok
02:09:11.0399 4208 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\\Windows\\system32\\DRIVERS\\HidBatt.sys
02:09:11.0399 4208 HidBatt - ok
02:09:11.0414 4208 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\\Windows\\system32\\DRIVERS\\hidbth.sys
02:09:11.0430 4208 HidBth - ok
02:09:11.0446 4208 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\\Windows\\system32\\DRIVERS\\hidir.sys
02:09:11.0446 4208 HidIr - ok
02:09:11.0477 4208 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\\Windows\\system32\\hidserv.dll
02:09:11.0492 4208 hidserv - ok
02:09:11.0508 4208 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\\Windows\\system32\\drivers\\hidusb.sys
02:09:11.0508 4208 HidUsb - ok
02:09:11.0555 4208 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\\Windows\\system32\\kmsvc.dll
02:09:11.0570 4208 hkmsvc - ok
02:09:11.0617 4208 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\\Windows\\system32\\ListSvc.dll
02:09:11.0664 4208 HomeGroupListener - ok
02:09:11.0695 4208 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\\Windows\\system32\\provsvc.dll
02:09:11.0726 4208 HomeGroupProvider - ok
02:09:11.0758 4208 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\\Windows\\system32\\drivers\\HpSAMD.sys
02:09:11.0773 4208 HpSAMD - ok
02:09:11.0804 4208 [ 26B05FFD8FB5E70EB501A610E3425341 ] HssDRV6 C:\\Windows\\system32\\DRIVERS\\hssdrv6.sys
02:09:11.0820 4208 HssDRV6 - ok
02:09:11.0914 4208 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\\Windows\\system32\\drivers\\HTTP.sys
02:09:11.0960 4208 HTTP - ok
02:09:11.0992 4208 [ 91971BCD780D6063DF90DE4F1DF10C2F ] huawei_cdcacm C:\\Windows\\system32\\DRIVERS\\ew_jucdcacm.sys
02:09:12.0007 4208 huawei_cdcacm - ok
02:09:12.0038 4208 [ 53D3E56CB36C9DDE9B7CDB5447DA0E80 ] huawei_cdcecm C:\\Windows\\system32\\DRIVERS\\ew_jucdcecm.sys
02:09:12.0038 4208 huawei_cdcecm - ok
02:09:12.0070 4208 [ CCE3DB0BA3C615CAA321EB1301532688 ] huawei_enumerator C:\\Windows\\system32\\DRIVERS\\ew_jubusenum.sys
02:09:12.0085 4208 huawei_enumerator - ok
02:09:12.0101 4208 [ C4BC37B9E5E54A50B2AA458F1FCA428C ] huawei_ext_ctrl C:\\Windows\\system32\\DRIVERS\\ew_juextctrl.sys
02:09:12.0101 4208 huawei_ext_ctrl - ok
02:09:12.0148 4208 [ CE93B8AF848FE2AA44455A4769C1BC8A ] hwdatacard C:\\Windows\\system32\\DRIVERS\\ewusbmdm.sys
02:09:12.0163 4208 hwdatacard - ok
02:09:12.0241 4208 [ E90DA42B87D684DEBFB73B38A718A006 ] HWDeviceService64.exe C:\\ProgramData\\DatacardService\\HWDeviceService64.exe
02:09:12.0257 4208 HWDeviceService64.exe - ok
02:09:12.0288 4208 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\\Windows\\system32\\drivers\\hwpolicy.sys
02:09:12.0304 4208 hwpolicy - ok
02:09:12.0319 4208 hwusbdev - ok
02:09:12.0366 4208 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\\Windows\\system32\\drivers\\i8042prt.sys
02:09:12.0366 4208 i8042prt - ok
02:09:12.0413 4208 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\\Windows\\system32\\drivers\\iaStorV.sys
02:09:12.0444 4208 iaStorV - ok
02:09:12.0491 4208 [ 2A63036283B36B3B68CDC6F85A7D53ED ] IDMWFP C:\\Windows\\system32\\DRIVERS\\idmwfp.sys
02:09:12.0491 4208 IDMWFP - ok
02:09:12.0538 4208 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe
02:09:12.0569 4208 idsvc - ok
02:09:13.0052 4208 [ 795C99DC4F574C97C03D0BB39CF099EE ] igfx C:\\Windows\\system32\\DRIVERS\\igdkmd64.sys
02:09:13.0364 4208 igfx - ok
02:09:13.0411 4208 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\\Windows\\system32\\DRIVERS\\iirsp.sys
02:09:13.0411 4208 iirsp - ok
02:09:13.0474 4208 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\\Windows\\System32\\ikeext.dll
02:09:13.0505 4208 IKEEXT - ok
02:09:13.0552 4208 [ C4E67D3037DC79E39D7136581A947F50 ] inspect C:\\Windows\\system32\\DRIVERS\\inspect.sys
02:09:13.0552 4208 inspect - ok
02:09:13.0583 4208 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\\Windows\\system32\\drivers\\intelide.sys
02:09:13.0598 4208 intelide - ok
02:09:13.0630 4208 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\\Windows\\system32\\DRIVERS\\intelppm.sys
02:09:13.0630 4208 intelppm - ok
02:09:13.0661 4208 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\\Windows\\system32\\ipbusenum.dll
02:09:13.0676 4208 IPBusEnum - ok
02:09:13.0708 4208 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\\Windows\\system32\\DRIVERS\\ipfltdrv.sys
02:09:13.0723 4208 IpFilterDriver - ok
02:09:13.0770 4208 [ A34A587FFFD45FA649FBA6D03784D257 ] IpHlpSvc C:\\Windows\\System32\\iphlpsvc.dll
02:09:13.0848 4208 IpHlpSvc - ok
02:09:13.0879 4208 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\\Windows\\system32\\drivers\\IPMIDrv.sys
02:09:13.0895 4208 IPMIDRV - ok
02:09:13.0926 4208 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\\Windows\\system32\\drivers\\ipnat.sys
02:09:13.0926 4208 IPNAT - ok
02:09:13.0957 4208 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\\Windows\\system32\\drivers\\irenum.sys
02:09:13.0957 4208 IRENUM - ok
02:09:13.0988 4208 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\\Windows\\system32\\drivers\\isapnp.sys
02:09:13.0988 4208 isapnp - ok
02:09:14.0020 4208 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\\Windows\\system32\\drivers\\msiscsi.sys
02:09:14.0066 4208 iScsiPrt - ok
02:09:14.0113 4208 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\\Windows\\system32\\drivers\\kbdclass.sys
02:09:14.0113 4208 kbdclass - ok
02:09:14.0144 4208 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\\Windows\\system32\\drivers\\kbdhid.sys
02:09:14.0144 4208 kbdhid - ok
02:09:14.0191 4208 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\\Windows\\system32\\lsass.exe
02:09:14.0207 4208 KeyIso - ok
02:09:14.0222 4208 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\\Windows\\system32\\Drivers\\ksecdd.sys
02:09:14.0222 4208 KSecDD - ok
02:09:14.0254 4208 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\\Windows\\system32\\Drivers\\ksecpkg.sys
02:09:14.0254 4208 KSecPkg - ok
02:09:14.0300 4208 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\\Windows\\system32\\drivers\\ksthunk.sys
02:09:14.0300 4208 ksthunk - ok
02:09:14.0347 4208 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\\Windows\\system32\\msdtckrm.dll
02:09:14.0378 4208 KtmRm - ok
02:09:14.0441 4208 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\\Windows\\system32\\srvsvc.dll
02:09:14.0488 4208 LanmanServer - ok
02:09:14.0534 4208 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\\Windows\\System32\\wkssvc.dll
02:09:14.0581 4208 LanmanWorkstation - ok
02:09:14.0628 4208 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\\Windows\\system32\\DRIVERS\\lltdio.sys
02:09:14.0628 4208 lltdio - ok
02:09:14.0659 4208 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\\Windows\\System32\\lltdsvc.dll
02:09:14.0690 4208 lltdsvc - ok
02:09:14.0706 4208 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\\Windows\\System32\\lmhsvc.dll
02:09:14.0737 4208 lmhosts - ok
02:09:14.0784 4208 [ 0803906D607A9B83184447B75B60ECC2 ] LMS C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe
02:09:14.0784 4208 LMS - ok
02:09:14.0815 4208 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\\Windows\\system32\\DRIVERS\\lsi_fc.sys
02:09:14.0831 4208 LSI_FC - ok
02:09:14.0846 4208 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\\Windows\\system32\\DRIVERS\\lsi_sas.sys
02:09:14.0862 4208 LSI_SAS - ok
02:09:14.0878 4208 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\\Windows\\system32\\DRIVERS\\lsi_sas2.sys
02:09:14.0878 4208 LSI_SAS2 - ok
02:09:14.0893 4208 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\\Windows\\system32\\DRIVERS\\lsi_scsi.sys
02:09:14.0909 4208 LSI_SCSI - ok
02:09:14.0940 4208 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\\Windows\\system32\\drivers\\luafv.sys
02:09:14.0940 4208 luafv - ok
02:09:14.0971 4208 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\\Windows\\system32\\Mcx2Svc.dll
02:09:15.0002 4208 Mcx2Svc - ok
02:09:15.0034 4208 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\\Windows\\system32\\DRIVERS\\megasas.sys
02:09:15.0034 4208 megasas - ok
02:09:15.0065 4208 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\\Windows\\system32\\DRIVERS\\MegaSR.sys
02:09:15.0080 4208 MegaSR - ok
02:09:15.0127 4208 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\\Windows\\system32\\DRIVERS\\HECIx64.sys
02:09:15.0127 4208 MEIx64 - ok
02:09:15.0158 4208 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\\Windows\\system32\\mmcss.dll
02:09:15.0190 4208 MMCSS - ok
02:09:15.0205 4208 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\\Windows\\system32\\drivers\\modem.sys
02:09:15.0205 4208 Modem - ok
02:09:15.0236 4208 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\\Windows\\system32\\DRIVERS\\monitor.sys
02:09:15.0236 4208 monitor - ok
02:09:15.0268 4208 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\\Windows\\system32\\drivers\\mouclass.sys
02:09:15.0283 4208 mouclass - ok
02:09:15.0299 4208 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\\Windows\\system32\\DRIVERS\\mouhid.sys
02:09:15.0299 4208 mouhid - ok
02:09:15.0346 4208 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\\Windows\\system32\\drivers\\mountmgr.sys
02:09:15.0346 4208 mountmgr - ok
02:09:15.0361 4208 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\\Windows\\system32\\drivers\\mpio.sys
02:09:15.0377 4208 mpio - ok
02:09:15.0392 4208 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\\Windows\\system32\\drivers\\mpsdrv.sys
02:09:15.0408 4208 mpsdrv - ok
02:09:15.0486 4208 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\\Windows\\system32\\mpssvc.dll
02:09:15.0533 4208 MpsSvc - ok
02:09:15.0580 4208 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\\Windows\\system32\\drivers\\mrxdav.sys
02:09:15.0595 4208 MRxDAV - ok
02:09:15.0626 4208 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\\Windows\\system32\\DRIVERS\\mrxsmb.sys
02:09:15.0626 4208 mrxsmb - ok
02:09:15.0658 4208 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\\Windows\\system32\\DRIVERS\\mrxsmb10.sys
02:09:15.0689 4208 mrxsmb10 - ok
02:09:15.0704 4208 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\\Windows\\system32\\DRIVERS\\mrxsmb20.sys
02:09:15.0720 4208 mrxsmb20 - ok
02:09:15.0751 4208 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\\Windows\\system32\\drivers\\msahci.sys
02:09:15.0751 4208 msahci - ok
02:09:15.0782 4208 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\\Windows\\system32\\drivers\\msdsm.sys
02:09:15.0798 4208 msdsm - ok
02:09:15.0814 4208 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\\Windows\\System32\\msdtc.exe
02:09:15.0845 4208 MSDTC - ok
02:09:15.0876 4208 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\\Windows\\system32\\drivers\\Msfs.sys
02:09:15.0892 4208 Msfs - ok
02:09:15.0970 4208 [ F7E0900F9A8E3F71F2C16A932F0E03E0 ] msftesql$PRIMAVERA C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe
02:09:16.0188 4208 msftesql$PRIMAVERA - ok
02:09:16.0235 4208 [ F7E0900F9A8E3F71F2C16A932F0E03E0 ] msftesql$SQLEXPRESS C:\\Program Files (x86)\\Microsoft SQL Server\\MSSQL.2\\MSSQL\\Binn\\msftesql.exe
02:09:16.0406 4208 msftesql$SQLEXPRESS - ok
02:09:16.0438 4208 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\\Windows\\System32\\drivers\\mshidkmdf.sys
02:09:16.0453 4208 mshidkmdf - ok
02:09:16.0484 4208 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\\Windows\\system32\\drivers\\msisadrv.sys
02:09:16.0484 4208 msisadrv - ok
02:09:16.0531 4208 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\\Windows\\system32\\iscsiexe.dll
02:09:16.0547 4208 MSiSCSI - ok
02:09:16.0562 4208 msiserver - ok
02:09:16.0594 4208 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\\Windows\\system32\\drivers\\MSKSSRV.sys
02:09:16.0594 4208 MSKSSRV - ok
02:09:16.0609 4208 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\\Windows\\system32\\drivers\\MSPCLOCK.sys
02:09:16.0609 4208 MSPCLOCK - ok
02:09:16.0625 4208 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\\Windows\\system32\\drivers\\MSPQM.sys
02:09:16.0640 4208 MSPQM - ok
02:09:16.0703 4208 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\\Windows\\system32\\drivers\\MsRPC.sys
02:09:16.0718 4208 MsRPC - ok
02:09:16.0734 4208 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\\Windows\\system32\\drivers\\mssmbios.sys
02:09:16.0734 4208 mssmbios - ok
02:09:16.0765 4208 MSSQL$PRIMAVERA - ok
02:09:16.0781 4208 MSSQL$SQLEXPRESS - ok
02:09:16.0828 4208 [ ADAF062116B4E6D96E44D26486A87AF6 ] MSSQLServerADHelper C:\\Program Files (x86)\\Microsoft SQL Server\\90\\Shared\\sqladhlp90.exe
02:09:16.0843 4208 MSSQLServerADHelper - ok
02:09:16.0859 4208 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\\Windows\\system32\\drivers\\MSTEE.sys
02:09:16.0874 4208 MSTEE - ok
02:09:16.0890 4208 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\\Windows\\system32\\DRIVERS\\MTConfig.sys
02:09:16.0890 4208 MTConfig - ok
02:09:16.0921 4208 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\\Windows\\system32\\Drivers\\mup.sys
02:09:16.0921 4208 Mup - ok
02:09:16.0968 4208 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\\Windows\\system32\\qagentRT.dll
02:09:17.0015 4208 napagent - ok
02:09:17.0077 4208 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\\Windows\\system32\\DRIVERS\\nwifi.sys
02:09:17.0093 4208 NativeWifiP - ok
02:09:17.0140 4208 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\\Windows\\system32\\drivers\\ndis.sys
02:09:17.0155 4208 NDIS - ok
02:09:17.0186 4208 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\\Windows\\system32\\DRIVERS\\ndiscap.sys
02:09:17.0202 4208 NdisCap - ok
02:09:17.0218 4208 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\\Windows\\system32\\DRIVERS\\ndistapi.sys
02:09:17.0233 4208 NdisTapi - ok
02:09:17.0264 4208 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\\Windows\\system32\\DRIVERS\\ndisuio.sys
02:09:17.0280 4208 Ndisuio - ok
02:09:17.0311 4208 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\\Windows\\system32\\DRIVERS\\ndiswan.sys
02:09:17.0327 4208 NdisWan - ok
02:09:17.0358 4208 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\\Windows\\system32\\drivers\\NDProxy.sys
02:09:17.0358 4208 NDProxy - ok
02:09:17.0389 4208 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\\Windows\\system32\\DRIVERS\\netbios.sys
02:09:17.0405 4208 NetBIOS - ok
02:09:17.0436 4208 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\\Windows\\system32\\DRIVERS\\netbt.sys
02:09:17.0467 4208 NetBT - ok
02:09:17.0483 4208 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\\Windows\\system32\\lsass.exe
02:09:17.0498 4208 Netlogon - ok
02:09:17.0561 4208 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\\Windows\\System32\\netman.dll
02:09:17.0608 4208 Netman - ok
02:09:17.0623 4208 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\\Windows\\System32\\netprofm.dll
02:09:17.0670 4208 netprofm - ok
02:09:17.0732 4208 [ C9E9017AC2291E96ED3376B72BC7CF8D ] netr28ux C:\\Windows\\system32\\DRIVERS\\netr28ux.sys
02:09:17.0779 4208 netr28ux - ok
02:09:17.0810 4208 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\SMSvcHost.exe
02:09:18.0029 4208 NetTcpPortSharing - ok
02:09:18.0060 4208 [ A97D9B1C2EEB2E169D2593E7073BCD27 ] NetworkX C:\\Windows\\System32\\ckldrv.sys
02:09:18.0076 4208 NetworkX - ok
02:09:18.0107 4208 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\\Windows\\system32\\DRIVERS\\nfrd960.sys
02:09:18.0122 4208 nfrd960 - ok
02:09:18.0200 4208 [ 07937CE37AD35FBECBF9D8BE584DCF2A ] NitroDriverReadSpool8 C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe
02:09:18.0216 4208 NitroDriverReadSpool8 - ok
02:09:18.0263 4208 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\\Windows\\System32\\nlasvc.dll
02:09:18.0294 4208 NlaSvc - ok
02:09:18.0450 4208 [ 06FE5405DA932CD4DEF1517B532F543A ] nlsX86cc C:\\Windows\\SysWOW64\\NLSSRV32.EXE
02:09:18.0684 4208 nlsX86cc - ok
02:09:18.0715 4208 [ 02C1198276C0D4F39E54EB5148AF1E2A ] nmwcdcx64 C:\\Windows\\system32\\drivers\\ccdcmbox64.sys
02:09:18.0731 4208 nmwcdcx64 - ok
02:09:18.0746 4208 [ D8F00FCC82451BDAA3DB93BB62AE6AC3 ] nmwcdx64 C:\\Windows\\system32\\drivers\\ccdcmbx64.sys
02:09:18.0762 4208 nmwcdx64 - ok
02:09:18.0778 4208 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\\Windows\\system32\\drivers\\Npfs.sys
02:09:18.0778 4208 Npfs - ok
02:09:18.0809 4208 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\\Windows\\system32\\nsisvc.dll
02:09:18.0840 4208 nsi - ok
02:09:18.0856 4208 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\\Windows\\system32\\drivers\\nsiproxy.sys
02:09:18.0871 4208 nsiproxy - ok
02:09:18.0949 4208 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\\Windows\\system32\\drivers\\Ntfs.sys
02:09:19.0027 4208 Ntfs - ok
02:09:19.0043 4208 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\\Windows\\system32\\drivers\\Null.sys
02:09:19.0058 4208 Null - ok
02:09:19.0090 4208 [ 158AD24745BD85BA9BE3C51C38F48C32 ] nusb3hub C:\\Windows\\system32\\DRIVERS\\nusb3hub.sys
02:09:19.0090 4208 nusb3hub - ok
02:09:19.0105 4208 [ D40A13B2C0891E218F9523B376955DB6 ] nusb3xhc C:\\Windows\\system32\\DRIVERS\\nusb3xhc.sys
02:09:19.0121 4208 nusb3xhc - ok
02:09:19.0168 4208 [ F2662FDC20518EE8A8EED4F61BA42349 ] NVHDA C:\\Windows\\system32\\drivers\\nvhda64v.sys
02:09:19.0183 4208 NVHDA - ok
02:09:19.0526 4208 [ 573B0941A37AEBEE96085D56A103F57B ] nvlddmkm C:\\Windows\\system32\\DRIVERS\\nvlddmkm.sys
02:09:19.0729 4208 nvlddmkm - ok
02:09:19.0760 4208 [ 43AF7EBEAC2AB623468E32CADDCB61A4 ] nvpciflt C:\\Windows\\system32\\DRIVERS\\nvpciflt.sys
02:09:19.0760 4208 nvpciflt - ok
02:09:19.0807 4208 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\\Windows\\system32\\drivers\\nvraid.sys
02:09:19.0823 4208 nvraid - ok
02:09:19.0854 4208 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\\Windows\\system32\\drivers\\nvstor.sys
02:09:19.0854 4208 nvstor - ok
02:09:19.0901 4208 [ C500760572C6059918FB0C960967695B ] NVSvc C:\\Windows\\system32\\nvvsvc.exe
02:09:19.0948 4208 NVSvc - ok
02:09:20.0041 4208 [ F28169A7ADF7B41809CF92D369E744F0 ] nvUpdatusService C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe
02:09:20.0462 4208 nvUpdatusService - ok
02:09:20.0494 4208 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\\Windows\\system32\\drivers\\nv_agp.sys
02:09:20.0509 4208 nv_agp - ok
02:09:20.0540 4208 odserv - ok
02:09:20.0572 4208 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\\Windows\\system32\\drivers\\ohci1394.sys
02:09:20.0587 4208 ohci1394 - ok
02:09:20.0650 4208 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE
02:09:20.0868 4208 ose - ok
02:09:21.0040 4208 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\\Program Files\\Common Files\\Microsoft Shared\\OfficeSoftwareProtectionPlatform\\OSPPSVC.EXE
02:09:21.0258 4208 osppsvc - ok
02:09:21.0305 4208 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\\Windows\\system32\\pnrpsvc.dll
02:09:21.0352 4208 p2pimsvc - ok
02:09:21.0367 4208 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\\Windows\\system32\\p2psvc.dll
02:09:21.0414 4208 p2psvc - ok
02:09:21.0445 4208 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\\Windows\\system32\\DRIVERS\\parport.sys
02:09:21.0461 4208 Parport - ok
02:09:21.0492 4208 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\\Windows\\system32\\drivers\\partmgr.sys
02:09:21.0492 4208 partmgr - ok
02:09:21.0523 4208 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\\Windows\\System32\\pcasvc.dll
02:09:21.0554 4208 PcaSvc - ok
02:09:21.0601 4208 [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd C:\\Windows\\system32\\DRIVERS\\pccsmcfdx64.sys
02:09:21.0601 4208 pccsmcfd - ok
02:09:21.0632 4208 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\\Windows\\system32\\drivers\\pci.sys
02:09:21.0664 4208 pci - ok
02:09:21.0695 4208 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\\Windows\\system32\\drivers\\pciide.sys
02:09:21.0695 4208 pciide - ok
02:09:21.0726 4208 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\\Windows\\system32\\DRIVERS\\pcmcia.sys
02:09:21.0742 4208 pcmcia - ok
02:09:21.0757 4208 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\\Windows\\system32\\drivers\\pcw.sys
02:09:21.0773 4208 pcw - ok
02:09:21.0804 4208 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\\Windows\\system32\\drivers\\peauth.sys
02:09:21.0835 4208 PEAUTH - ok
02:09:21.0898 4208 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\\Windows\\system32\\peerdistsvc.dll
02:09:21.0976 4208 PeerDistSvc - ok
02:09:22.0022 4208 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\\Windows\\SysWow64\\perfhost.exe
02:09:22.0272 4208 PerfHost - ok
02:09:22.0350 4208 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\\Windows\\system32\\pla.dll
02:09:22.0428 4208 pla - ok
02:09:22.0490 4208 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\\Windows\\system32\\umpnpmgr.dll
02:09:22.0553 4208 PlugPlay - ok
02:09:22.0584 4208 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\\Windows\\system32\\pnrpauto.dll
02:09:22.0631 4208 PNRPAutoReg - ok
02:09:22.0646 4208 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\\Windows\\system32\\pnrpsvc.dll
02:09:22.0678 4208 PNRPsvc - ok
02:09:22.0709 4208 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\\Windows\\System32\\ipsecsvc.dll
02:09:22.0756 4208 PolicyAgent - ok
02:09:22.0802 4208 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\\Windows\\system32\\umpo.dll
02:09:22.0849 4208 Power - ok
02:09:22.0880 4208 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\\Windows\\system32\\DRIVERS\\raspptp.sys
02:09:22.0896 4208 PptpMiniport - ok
02:09:23.0005 4208 [ 4747B514561B1F6E8937202C0BCE0411 ] PrmBackAgent C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe
02:09:23.0426 4208 PrmBackAgent - ok
02:09:23.0458 4208 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\\Windows\\system32\\DRIVERS\\processr.sys
02:09:23.0458 4208 Processor - ok
02:09:23.0504 4208 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\\Windows\\system32\\profsvc.dll
02:09:23.0536 4208 ProfSvc - ok
02:09:23.0551 4208 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\\Windows\\system32\\lsass.exe
02:09:23.0582 4208 ProtectedStorage - ok
02:09:23.0629 4208 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\\Windows\\system32\\DRIVERS\\pacer.sys
02:09:23.0645 4208 Psched - ok
02:09:23.0692 4208 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\\Windows\\system32\\DRIVERS\\ql2300.sys
02:09:23.0754 4208 ql2300 - ok
02:09:23.0770 4208 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\\Windows\\system32\\DRIVERS\\ql40xx.sys
02:09:23.0785 4208 ql40xx - ok
02:09:23.0816 4208 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\\Windows\\system32\\qwave.dll
02:09:23.0863 4208 QWAVE - ok
02:09:23.0879 4208 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\\Windows\\system32\\drivers\\qwavedrv.sys
02:09:23.0894 4208 QWAVEdrv - ok
02:09:23.0910 4208 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\\Windows\\system32\\DRIVERS\\rasacd.sys
02:09:23.0910 4208 RasAcd - ok
02:09:23.0957 4208 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\\Windows\\system32\\DRIVERS\\AgileVpn.sys
02:09:23.0957 4208 RasAgileVpn - ok
02:09:23.0988 4208 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\\Windows\\System32\\rasauto.dll
02:09:24.0019 4208 RasAuto - ok
02:09:24.0050 4208 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\\Windows\\system32\\DRIVERS\\rasl2tp.sys
02:09:24.0066 4208 Rasl2tp - ok
02:09:24.0097 4208 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\\Windows\\System32\\rasmans.dll
02:09:24.0144 4208 RasMan - ok
02:09:24.0175 4208 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\\Windows\\system32\\DRIVERS\\raspppoe.sys
02:09:24.0175 4208 RasPppoe - ok
02:09:24.0206 4208 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\\Windows\\system32\\DRIVERS\\rassstp.sys
02:09:24.0222 4208 RasSstp - ok
02:09:24.0253 4208 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\\Windows\\system32\\DRIVERS\\rdbss.sys
02:09:24.0284 4208 rdbss - ok
02:09:24.0300 4208 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\\Windows\\system32\\DRIVERS\\rdpbus.sys
02:09:24.0316 4208 rdpbus - ok
02:09:24.0331 4208 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\\Windows\\system32\\DRIVERS\\RDPCDD.sys
02:09:24.0331 4208 RDPCDD - ok
02:09:24.0378 4208 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\\Windows\\system32\\drivers\\rdpdr.sys
02:09:24.0409 4208 RDPDR - ok
02:09:24.0440 4208 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\\Windows\\system32\\drivers\\rdpencdd.sys
02:09:24.0440 4208 RDPENCDD - ok
02:09:24.0472 4208 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\\Windows\\system32\\drivers\\rdprefmp.sys
02:09:24.0472 4208 RDPREFMP - ok
02:09:24.0518 4208 [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\\Windows\\system32\\drivers\\rdpvideominiport.sys
02:09:24.0518 4208 RdpVideoMiniport - ok
02:09:24.0550 4208 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\\Windows\\system32\\drivers\\RDPWD.sys
02:09:24.0581 4208 RDPWD - ok
02:09:24.0612 4208 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost
Just waiting on the ComboFix log now
Guestolo i was trying to paste the log but getting errors
so i have attached it with post plz see attachment
and yes pc is mine as you can see from my name & pc user name ..... how ever i managed to get my password recover as i completly forgot
I was out of town without internet... Are you still around?
How are things now running?
I\'ll lock this topic as the original starter has not returned, If you do return
please PM me and I\'ll reopen the topic