Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - faraz

Pages: [1] 2 3 4
1

and yes pc is mine as you can see from my name & pc user name ..... how ever i managed to get my password recover as i completly forgot 



2
Guestolo i was trying to paste the log but getting errors

so i have attached it with post plz see attachment

3
02:08:26.0181 2420  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42

02:08:26.0337 2420  ============================================================

02:08:26.0337 2420  Current date / time: 2013/08/10 02:08:26.0337

02:08:26.0337 2420  SystemInfo:

02:08:26.0337 2420  

02:08:26.0337 2420  OS Version: 6.1.7601 ServicePack: 1.0

02:08:26.0337 2420  Product type: Workstation

02:08:26.0337 2420  ComputerName: SLAIN

02:08:26.0337 2420  UserName: Faraz

02:08:26.0337 2420  Windows directory: C:\\Windows

02:08:26.0337 2420  System windows directory: C:\\Windows

02:08:26.0337 2420  Running under WOW64

02:08:26.0337 2420  Processor architecture: Intel x64

02:08:26.0337 2420  Number of processors: 4

02:08:26.0337 2420  Page size: 0x1000

02:08:26.0337 2420  Boot type: Normal boot

02:08:26.0337 2420  ============================================================

02:08:30.0698 2420  Drive \\Device\\Harddisk0\\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type \'K0\', Flags 0x00000040

02:08:30.0714 2420  ============================================================

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0:

02:08:30.0714 2420  MBR partitions:

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0\\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0\\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x6176000

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0\\Partition3: MBR, Type 0x7, StartLBA 0x61A8800, BlocksNum 0x61A8000

02:08:30.0714 2420  \\Device\\Harddisk0\\DR0\\Partition4: MBR, Type 0x7, StartLBA 0xC350800, BlocksNum 0x2E035000

02:08:30.0714 2420  ============================================================

02:08:30.0730 2420  C: <-> \\Device\\Harddisk0\\DR0\\Partition2

02:08:30.0776 2420  D: <-> \\Device\\Harddisk0\\DR0\\Partition3

02:08:30.0808 2420  E: <-> \\Device\\Harddisk0\\DR0\\Partition4

02:08:30.0808 2420  ============================================================

02:08:30.0808 2420  Initialize success

02:08:30.0808 2420  ============================================================

02:09:02.0054 4208  ============================================================

02:09:02.0054 4208  Scan started

02:09:02.0054 4208  Mode: Manual; 

02:09:02.0054 4208  ============================================================

02:09:03.0068 4208  ================ Scan system memory ========================

02:09:03.0068 4208  System memory - ok

02:09:03.0068 4208  ================ Scan services =============================

02:09:03.0209 4208  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\\Windows\\system32\\drivers\\1394ohci.sys

02:09:03.0224 4208  1394ohci - ok

02:09:03.0256 4208  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\\Windows\\system32\\drivers\\ACPI.sys

02:09:03.0256 4208  ACPI - ok

02:09:03.0287 4208  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi         C:\\Windows\\system32\\drivers\\acpipmi.sys

02:09:03.0287 4208  AcpiPmi - ok

02:09:03.0396 4208  [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe

02:09:03.0412 4208  AdobeFlashPlayerUpdateSvc - ok

02:09:03.0458 4208  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx         C:\\Windows\\system32\\DRIVERS\\adp94xx.sys

02:09:03.0490 4208  adp94xx - ok

02:09:03.0505 4208  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci         C:\\Windows\\system32\\DRIVERS\\adpahci.sys

02:09:03.0521 4208  adpahci - ok

02:09:03.0536 4208  [ E109549C90F62FB570B9540C4B148E54 ] adpu320         C:\\Windows\\system32\\DRIVERS\\adpu320.sys

02:09:03.0552 4208  adpu320 - ok

02:09:03.0583 4208  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc     C:\\Windows\\System32\\aelupsvc.dll

02:09:03.0599 4208  AeLookupSvc - ok

02:09:03.0630 4208  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD             C:\\Windows\\system32\\drivers\\afd.sys

02:09:03.0677 4208  AFD - ok

02:09:03.0708 4208  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\\Windows\\system32\\drivers\\agp440.sys

02:09:03.0708 4208  agp440 - ok

02:09:03.0739 4208  [ 3290D6946B5E30E70414990574883DDB ] ALG             C:\\Windows\\System32\\alg.exe

02:09:03.0739 4208  ALG - ok

02:09:03.0770 4208  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\\Windows\\system32\\drivers\\aliide.sys

02:09:03.0770 4208  aliide - ok

02:09:03.0770 4208  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\\Windows\\system32\\drivers\\amdide.sys

02:09:03.0786 4208  amdide - ok

02:09:03.0802 4208  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8           C:\\Windows\\system32\\DRIVERS\\amdk8.sys

02:09:03.0802 4208  AmdK8 - ok

02:09:03.0833 4208  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\\Windows\\system32\\DRIVERS\\amdppm.sys

02:09:03.0833 4208  AmdPPM - ok

02:09:03.0864 4208  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata         C:\\Windows\\system32\\drivers\\amdsata.sys

02:09:03.0880 4208  amdsata - ok

02:09:03.0895 4208  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\\Windows\\system32\\DRIVERS\\amdsbs.sys

02:09:03.0911 4208  amdsbs - ok

02:09:03.0926 4208  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata         C:\\Windows\\system32\\drivers\\amdxata.sys

02:09:03.0926 4208  amdxata - ok

02:09:03.0942 4208  apcrybwd - ok

02:09:03.0989 4208  [ 24ED0EB2B2558970176ECEE680F8F806 ] ApfiltrService  C:\\Windows\\system32\\DRIVERS\\Apfiltr.sys

02:09:04.0004 4208  ApfiltrService - ok

02:09:04.0067 4208  [ 59D01FA91962C9C1E9B4022B2D3B46DB ] AppHostSvc      C:\\Windows\\system32\\inetsrv\\apphostsvc.dll

02:09:04.0067 4208  AppHostSvc - ok

02:09:04.0114 4208  [ 89A69C3F2F319B43379399547526D952 ] AppID           C:\\Windows\\system32\\drivers\\appid.sys

02:09:04.0129 4208  AppID - ok

02:09:04.0160 4208  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\\Windows\\System32\\appidsvc.dll

02:09:04.0160 4208  AppIDSvc - ok

02:09:04.0192 4208  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo         C:\\Windows\\System32\\appinfo.dll

02:09:04.0192 4208  Appinfo - ok

02:09:04.0223 4208  [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt         C:\\Windows\\System32\\appmgmts.dll

02:09:04.0238 4208  AppMgmt - ok

02:09:04.0270 4208  [ C484F8CEB1717C540242531DB7845C4E ] arc             C:\\Windows\\system32\\DRIVERS\\arc.sys

02:09:04.0270 4208  arc - ok

02:09:04.0285 4208  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\\Windows\\system32\\DRIVERS\\arcsas.sys

02:09:04.0301 4208  arcsas - ok

02:09:04.0348 4208  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\\Windows\\system32\\DRIVERS\\asyncmac.sys

02:09:04.0348 4208  AsyncMac - ok

02:09:04.0379 4208  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi           C:\\Windows\\system32\\drivers\\atapi.sys

02:09:04.0379 4208  atapi - ok

02:09:04.0410 4208  [ CBE61B4494165F458BD87E37181EE934 ] AthBTPort       C:\\Windows\\system32\\DRIVERS\\btath_flt.sys

02:09:04.0410 4208  AthBTPort - ok

02:09:04.0488 4208  [ 67B8BD46E8626C348688930244761DAB ] Atheros Bt&Wlan Coex Agent C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe

02:09:04.0722 4208  Atheros Bt&Wlan Coex Agent - ok

02:09:04.0784 4208  [ 8430ED17CEF0D7878B25776E02508957 ] AtherosSvc      C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\adminservice.exe

02:09:04.0784 4208  AtherosSvc - ok

02:09:04.0878 4208  [ 782D36BAD8DDBF008D02E055DBE70F82 ] athr            C:\\Windows\\system32\\DRIVERS\\athrx.sys

02:09:04.0956 4208  athr - ok

02:09:05.0034 4208  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\\Windows\\System32\\Audiosrv.dll

02:09:05.0065 4208  AudioEndpointBuilder - ok

02:09:05.0096 4208  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\\Windows\\System32\\Audiosrv.dll

02:09:05.0112 4208  AudioSrv - ok

02:09:05.0143 4208  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\\Windows\\System32\\AxInstSV.dll

02:09:05.0159 4208  AxInstSV - ok

02:09:05.0190 4208  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv         C:\\Windows\\system32\\DRIVERS\\bxvbda.sys

02:09:05.0221 4208  b06bdrv - ok

02:09:05.0252 4208  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\\Windows\\system32\\DRIVERS\\b57nd60a.sys

02:09:05.0252 4208  b57nd60a - ok

02:09:05.0284 4208  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\\Windows\\System32\\bdesvc.dll

02:09:05.0299 4208  BDESVC - ok

02:09:05.0315 4208  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\\Windows\\system32\\drivers\\Beep.sys

02:09:05.0315 4208  Beep - ok

02:09:05.0377 4208  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE             C:\\Windows\\System32\\bfe.dll

02:09:05.0408 4208  BFE - ok

02:09:05.0440 4208  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\\Windows\\System32\\qmgr.dll

02:09:05.0502 4208  BITS - ok

02:09:05.0518 4208  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\\Windows\\system32\\DRIVERS\\blbdrive.sys

02:09:05.0533 4208  blbdrive - ok

02:09:05.0627 4208  [ 093B1B419EF25B15D3A1CA6953F41AFB ] Bluetooth Device Monitor C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe

02:09:05.0674 4208  Bluetooth Device Monitor - ok

02:09:05.0736 4208  [ 03A7341E94ACD92E0831336D4F3ACE92 ] Bluetooth Media Service C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe

02:09:06.0064 4208  Bluetooth Media Service - ok

02:09:06.0110 4208  [ A2EBF384ED105FED7D05C5465500EF2E ] Bluetooth OBEX Service C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe

02:09:06.0422 4208  Bluetooth OBEX Service - ok

02:09:06.0485 4208  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\\Windows\\system32\\DRIVERS\\bowser.sys

02:09:06.0485 4208  bowser - ok

02:09:06.0516 4208  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\\Windows\\system32\\DRIVERS\\BrFiltLo.sys

02:09:06.0516 4208  BrFiltLo - ok

02:09:06.0532 4208  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\\Windows\\system32\\DRIVERS\\BrFiltUp.sys

02:09:06.0532 4208  BrFiltUp - ok

02:09:06.0563 4208  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser         C:\\Windows\\System32\\browser.dll

02:09:06.0594 4208  Browser - ok

02:09:06.0625 4208  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid         C:\\Windows\\System32\\Drivers\\Brserid.sys

02:09:06.0625 4208  Brserid - ok

02:09:06.0641 4208  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\\Windows\\System32\\Drivers\\BrSerWdm.sys

02:09:06.0656 4208  BrSerWdm - ok

02:09:06.0672 4208  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\\Windows\\System32\\Drivers\\BrUsbMdm.sys

02:09:06.0672 4208  BrUsbMdm - ok

02:09:06.0672 4208  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\\Windows\\System32\\Drivers\\BrUsbSer.sys

02:09:06.0688 4208  BrUsbSer - ok

02:09:06.0766 4208  [ 227C8F308DE4AF4808E587465CEAB838 ] BTATH_A2DP      C:\\Windows\\system32\\drivers\\btath_a2dp.sys

02:09:06.0766 4208  BTATH_A2DP - ok

02:09:06.0781 4208  [ A83A91D07D1FE6BBE7A9DB46CA00434B ] BTATH_BUS       C:\\Windows\\system32\\DRIVERS\\btath_bus.sys

02:09:06.0781 4208  BTATH_BUS - ok

02:09:06.0812 4208  [ C864FF85EE16D61C2BDD5EF76824625F ] BTATH_HCRP      C:\\Windows\\system32\\DRIVERS\\btath_hcrp.sys

02:09:06.0828 4208  BTATH_HCRP - ok

02:09:06.0844 4208  [ 0DEA505EFB5D771826D177EF8B8A208F ] BTATH_LWFLT     C:\\Windows\\system32\\DRIVERS\\btath_lwflt.sys

02:09:06.0844 4208  BTATH_LWFLT - ok

02:09:06.0859 4208  [ 724C8088C96EFE7A3E63FEC21D4681C0 ] BTATH_RCP       C:\\Windows\\system32\\DRIVERS\\btath_rcp.sys

02:09:06.0859 4208  BTATH_RCP - ok

02:09:06.0906 4208  [ 486720DA2B3BB13D1080C83140C18B56 ] BtFilter        C:\\Windows\\system32\\DRIVERS\\btfilter.sys

02:09:06.0922 4208  BtFilter - ok

02:09:06.0953 4208  [ CF98190A94F62E405C8CB255018B2315 ] BthEnum         C:\\Windows\\system32\\drivers\\BthEnum.sys

02:09:06.0968 4208  BthEnum - ok

02:09:06.0984 4208  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\\Windows\\system32\\DRIVERS\\bthmodem.sys

02:09:07.0000 4208  BTHMODEM - ok

02:09:07.0031 4208  [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan          C:\\Windows\\system32\\DRIVERS\\bthpan.sys

02:09:07.0031 4208  BthPan - ok

02:09:07.0062 4208  [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT         C:\\Windows\\System32\\Drivers\\BTHport.sys

02:09:07.0093 4208  BTHPORT - ok

02:09:07.0124 4208  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv         C:\\Windows\\system32\\bthserv.dll

02:09:07.0124 4208  bthserv - ok

02:09:07.0156 4208  [ F188B7394D81010767B6DF3178519A37 ] BTHUSB          C:\\Windows\\System32\\Drivers\\BTHUSB.sys

02:09:07.0156 4208  BTHUSB - ok

02:09:07.0171 4208  [ 16C1BAC9760C9FA85A30F3FA0FBB1B7A ] btmaux          C:\\Windows\\system32\\DRIVERS\\btmaux.sys

02:09:07.0187 4208  btmaux - ok

02:09:07.0202 4208  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\\Windows\\system32\\DRIVERS\\cdfs.sys

02:09:07.0218 4208  cdfs - ok

02:09:07.0265 4208  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom           C:\\Windows\\system32\\DRIVERS\\cdrom.sys

02:09:07.0265 4208  cdrom - ok

02:09:07.0312 4208  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc     C:\\Windows\\System32\\certprop.dll

02:09:07.0327 4208  CertPropSvc - ok

02:09:07.0358 4208  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\\Windows\\system32\\DRIVERS\\circlass.sys

02:09:07.0358 4208  circlass - ok

02:09:07.0390 4208  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\\Windows\\system32\\CLFS.sys

02:09:07.0405 4208  CLFS - ok

02:09:07.0514 4208  [ 882E3973505C441CE000133C821D0EDD ] CLPSLS          C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe

02:09:07.0546 4208  CLPSLS - ok

02:09:07.0608 4208  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe

02:09:07.0608 4208  clr_optimization_v2.0.50727_32 - ok

02:09:07.0655 4208  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe

02:09:07.0670 4208  clr_optimization_v2.0.50727_64 - ok

02:09:07.0702 4208  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\\Windows\\system32\\DRIVERS\\CmBatt.sys

02:09:07.0717 4208  CmBatt - ok

02:09:07.0795 4208  [ 65FB5097D9EE7E3A99E932CFA0E4B344 ] cmdAgent        C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe

02:09:07.0842 4208  cmdAgent - ok

02:09:07.0858 4208  [ 2D6DC31AA55BFF702519235DEF0DA68E ] cmderd          C:\\Windows\\system32\\DRIVERS\\cmderd.sys

02:09:07.0873 4208  cmderd - ok

02:09:07.0904 4208  [ 919ACCC22ABDC1C3CA68326C0E5DEAF9 ] cmdGuard        C:\\Windows\\system32\\DRIVERS\\cmdguard.sys

02:09:07.0904 4208  cmdGuard - ok

02:09:07.0936 4208  [ F8FECE0F1D44C4A58778083B00EEADAC ] cmdHlp          C:\\Windows\\system32\\DRIVERS\\cmdhlp.sys

02:09:07.0936 4208  cmdHlp - ok

02:09:07.0967 4208  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\\Windows\\system32\\drivers\\cmdide.sys

02:09:07.0967 4208  cmdide - ok

02:09:08.0014 4208  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG             C:\\Windows\\system32\\Drivers\\cng.sys

02:09:08.0045 4208  CNG - ok

02:09:08.0076 4208  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\\Windows\\system32\\DRIVERS\\compbatt.sys

02:09:08.0076 4208  Compbatt - ok

02:09:08.0123 4208  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\\Windows\\system32\\drivers\\CompositeBus.sys

02:09:08.0123 4208  CompositeBus - ok

02:09:08.0138 4208  COMSysApp - ok

02:09:08.0170 4208  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk         C:\\Windows\\system32\\DRIVERS\\crcdisk.sys

02:09:08.0170 4208  crcdisk - ok

02:09:08.0232 4208  [ 2177A0F611584BCA1DFDD7EEB35C0224 ] CrypKey License C:\\Windows\\system32\\crypserv.exe

02:09:08.0482 4208  CrypKey License - ok

02:09:08.0528 4208  [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc        C:\\Windows\\system32\\cryptsvc.dll

02:09:08.0544 4208  CryptSvc - ok

02:09:08.0575 4208  [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC             C:\\Windows\\system32\\drivers\\csc.sys

02:09:08.0606 4208  CSC - ok

02:09:08.0638 4208  [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService      C:\\Windows\\System32\\cscsvc.dll

02:09:08.0669 4208  CscService - ok

02:09:08.0700 4208  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\\Windows\\system32\\rpcss.dll

02:09:08.0747 4208  DcomLaunch - ok

02:09:08.0778 4208  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc       C:\\Windows\\System32\\defragsvc.dll

02:09:08.0809 4208  defragsvc - ok

02:09:08.0840 4208  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\\Windows\\system32\\Drivers\\dfsc.sys

02:09:08.0840 4208  DfsC - ok

02:09:08.0872 4208  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\\Windows\\system32\\dhcpcore.dll

02:09:08.0887 4208  Dhcp - ok

02:09:08.0918 4208  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\\Windows\\system32\\drivers\\discache.sys

02:09:08.0918 4208  discache - ok

02:09:08.0965 4208  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\\Windows\\system32\\DRIVERS\\disk.sys

02:09:08.0965 4208  Disk - ok

02:09:08.0996 4208  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\\Windows\\System32\\dnsrslvr.dll

02:09:09.0012 4208  Dnscache - ok

02:09:09.0059 4208  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc         C:\\Windows\\System32\\dot3svc.dll

02:09:09.0090 4208  dot3svc - ok

02:09:09.0121 4208  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS             C:\\Windows\\system32\\dps.dll

02:09:09.0137 4208  DPS - ok

02:09:09.0168 4208  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud         C:\\Windows\\system32\\drivers\\drmkaud.sys

02:09:09.0184 4208  drmkaud - ok

02:09:09.0215 4208  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl         C:\\Windows\\System32\\drivers\\dxgkrnl.sys

02:09:09.0246 4208  DXGKrnl - ok

02:09:09.0277 4208  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost         C:\\Windows\\System32\\eapsvc.dll

02:09:09.0293 4208  EapHost - ok

02:09:09.0433 4208  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv           C:\\Windows\\system32\\DRIVERS\\evbda.sys

02:09:09.0527 4208  ebdrv - ok

02:09:09.0542 4208  [ C118A82CD78818C29AB228366EBF81C3 ] EFS             C:\\Windows\\System32\\lsass.exe

02:09:09.0574 4208  EFS - ok

02:09:09.0667 4208  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr         C:\\Windows\\ehome\\ehRecvr.exe

02:09:09.0683 4208  ehRecvr - ok

02:09:09.0730 4208  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched         C:\\Windows\\ehome\\ehsched.exe

02:09:09.0730 4208  ehSched - ok

02:09:09.0761 4208  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor         C:\\Windows\\system32\\DRIVERS\\elxstor.sys

02:09:09.0792 4208  elxstor - ok

02:09:09.0823 4208  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\\Windows\\system32\\drivers\\errdev.sys

02:09:09.0823 4208  ErrDev - ok

02:09:09.0886 4208  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem     C:\\Windows\\system32\\es.dll

02:09:09.0901 4208  EventSystem - ok

02:09:09.0979 4208  [ 2B831232C7F57FD675C9AFCA82A5CC24 ] ewusbmbb        C:\\Windows\\system32\\DRIVERS\\ewusbwwan.sys

02:09:10.0010 4208  ewusbmbb - ok

02:09:10.0026 4208  ewusbnet - ok

02:09:10.0057 4208  [ 86F7951BBCEE4A86E79A97306BD14318 ] ew_hwusbdev     C:\\Windows\\system32\\DRIVERS\\ew_hwusbdev.sys

02:09:10.0057 4208  ew_hwusbdev - ok

02:09:10.0088 4208  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat           C:\\Windows\\system32\\drivers\\exfat.sys

02:09:10.0104 4208  exfat - ok

02:09:10.0120 4208  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat         C:\\Windows\\system32\\drivers\\fastfat.sys

02:09:10.0135 4208  fastfat - ok

02:09:10.0182 4208  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax             C:\\Windows\\system32\\fxssvc.exe

02:09:10.0229 4208  Fax - ok

02:09:10.0260 4208  [ 240FF3619817B039198CDCD1E8DAE921 ] fcdabus         C:\\Windows\\system32\\DRIVERS\\fcdabus.sys

02:09:10.0260 4208  fcdabus - ok

02:09:10.0291 4208  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc             C:\\Windows\\system32\\DRIVERS\\fdc.sys

02:09:10.0291 4208  fdc - ok

02:09:10.0322 4208  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost         C:\\Windows\\system32\\fdPHost.dll

02:09:10.0338 4208  fdPHost - ok

02:09:10.0354 4208  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\\Windows\\system32\\fdrespub.dll

02:09:10.0385 4208  FDResPub - ok

02:09:10.0400 4208  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\\Windows\\system32\\drivers\\fileinfo.sys

02:09:10.0400 4208  FileInfo - ok

02:09:10.0416 4208  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace       C:\\Windows\\system32\\drivers\\filetrace.sys

02:09:10.0432 4208  Filetrace - ok

02:09:10.0447 4208  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\\Windows\\system32\\DRIVERS\\flpydisk.sys

02:09:10.0447 4208  flpydisk - ok

02:09:10.0510 4208  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\\Windows\\system32\\drivers\\fltmgr.sys

02:09:10.0541 4208  FltMgr - ok

02:09:10.0619 4208  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache       C:\\Windows\\system32\\FntCache.dll

02:09:10.0666 4208  FontCache - ok

02:09:10.0712 4208  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe

02:09:10.0915 4208  FontCache3.0.0.0 - ok

02:09:10.0946 4208  fqtirfym - ok

02:09:10.0962 4208  [ D43703496149971890703B4B1B723EAC ] FsDepends       C:\\Windows\\system32\\drivers\\FsDepends.sys

02:09:10.0978 4208  FsDepends - ok

02:09:10.0993 4208  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\\Windows\\system32\\drivers\\Fs_Rec.sys

02:09:10.0993 4208  Fs_Rec - ok

02:09:11.0040 4208  [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol          C:\\Windows\\system32\\DRIVERS\\fvevol.sys

02:09:11.0056 4208  fvevol - ok

02:09:11.0087 4208  [ C4AE69B476A40C165B6E99D10E814D0F ] FVXSCSI         C:\\Windows\\system32\\DRIVERS\\fvxscsi.sys

02:09:11.0087 4208  FVXSCSI - ok

02:09:11.0134 4208  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\\Windows\\system32\\DRIVERS\\gagp30kx.sys

02:09:11.0134 4208  gagp30kx - ok

02:09:11.0149 4208  gnfjuabb - ok

02:09:11.0212 4208  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc           C:\\Windows\\System32\\gpsvc.dll

02:09:11.0258 4208  gpsvc - ok

02:09:11.0274 4208  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\\Windows\\system32\\drivers\\hcw85cir.sys

02:09:11.0274 4208  hcw85cir - ok

02:09:11.0336 4208  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\\Windows\\system32\\drivers\\HdAudio.sys

02:09:11.0352 4208  HdAudAddService - ok

02:09:11.0368 4208  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\\Windows\\system32\\drivers\\HDAudBus.sys

02:09:11.0383 4208  HDAudBus - ok

02:09:11.0399 4208  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt         C:\\Windows\\system32\\DRIVERS\\HidBatt.sys

02:09:11.0399 4208  HidBatt - ok

02:09:11.0414 4208  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\\Windows\\system32\\DRIVERS\\hidbth.sys

02:09:11.0430 4208  HidBth - ok

02:09:11.0446 4208  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr           C:\\Windows\\system32\\DRIVERS\\hidir.sys

02:09:11.0446 4208  HidIr - ok

02:09:11.0477 4208  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv         C:\\Windows\\system32\\hidserv.dll

02:09:11.0492 4208  hidserv - ok

02:09:11.0508 4208  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\\Windows\\system32\\drivers\\hidusb.sys

02:09:11.0508 4208  HidUsb - ok

02:09:11.0555 4208  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\\Windows\\system32\\kmsvc.dll

02:09:11.0570 4208  hkmsvc - ok

02:09:11.0617 4208  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\\Windows\\system32\\ListSvc.dll

02:09:11.0664 4208  HomeGroupListener - ok

02:09:11.0695 4208  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\\Windows\\system32\\provsvc.dll

02:09:11.0726 4208  HomeGroupProvider - ok

02:09:11.0758 4208  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\\Windows\\system32\\drivers\\HpSAMD.sys

02:09:11.0773 4208  HpSAMD - ok

02:09:11.0804 4208  [ 26B05FFD8FB5E70EB501A610E3425341 ] HssDRV6         C:\\Windows\\system32\\DRIVERS\\hssdrv6.sys

02:09:11.0820 4208  HssDRV6 - ok

02:09:11.0914 4208  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\\Windows\\system32\\drivers\\HTTP.sys

02:09:11.0960 4208  HTTP - ok

02:09:11.0992 4208  [ 91971BCD780D6063DF90DE4F1DF10C2F ] huawei_cdcacm   C:\\Windows\\system32\\DRIVERS\\ew_jucdcacm.sys

02:09:12.0007 4208  huawei_cdcacm - ok

02:09:12.0038 4208  [ 53D3E56CB36C9DDE9B7CDB5447DA0E80 ] huawei_cdcecm   C:\\Windows\\system32\\DRIVERS\\ew_jucdcecm.sys

02:09:12.0038 4208  huawei_cdcecm - ok

02:09:12.0070 4208  [ CCE3DB0BA3C615CAA321EB1301532688 ] huawei_enumerator C:\\Windows\\system32\\DRIVERS\\ew_jubusenum.sys

02:09:12.0085 4208  huawei_enumerator - ok

02:09:12.0101 4208  [ C4BC37B9E5E54A50B2AA458F1FCA428C ] huawei_ext_ctrl C:\\Windows\\system32\\DRIVERS\\ew_juextctrl.sys

02:09:12.0101 4208  huawei_ext_ctrl - ok

02:09:12.0148 4208  [ CE93B8AF848FE2AA44455A4769C1BC8A ] hwdatacard      C:\\Windows\\system32\\DRIVERS\\ewusbmdm.sys

02:09:12.0163 4208  hwdatacard - ok

02:09:12.0241 4208  [ E90DA42B87D684DEBFB73B38A718A006 ] HWDeviceService64.exe C:\\ProgramData\\DatacardService\\HWDeviceService64.exe

02:09:12.0257 4208  HWDeviceService64.exe - ok

02:09:12.0288 4208  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\\Windows\\system32\\drivers\\hwpolicy.sys

02:09:12.0304 4208  hwpolicy - ok

02:09:12.0319 4208  hwusbdev - ok

02:09:12.0366 4208  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\\Windows\\system32\\drivers\\i8042prt.sys

02:09:12.0366 4208  i8042prt - ok

02:09:12.0413 4208  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV         C:\\Windows\\system32\\drivers\\iaStorV.sys

02:09:12.0444 4208  iaStorV - ok

02:09:12.0491 4208  [ 2A63036283B36B3B68CDC6F85A7D53ED ] IDMWFP          C:\\Windows\\system32\\DRIVERS\\idmwfp.sys

02:09:12.0491 4208  IDMWFP - ok

02:09:12.0538 4208  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc           C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe

02:09:12.0569 4208  idsvc - ok

02:09:13.0052 4208  [ 795C99DC4F574C97C03D0BB39CF099EE ] igfx            C:\\Windows\\system32\\DRIVERS\\igdkmd64.sys

02:09:13.0364 4208  igfx - ok

02:09:13.0411 4208  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp           C:\\Windows\\system32\\DRIVERS\\iirsp.sys

02:09:13.0411 4208  iirsp - ok

02:09:13.0474 4208  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\\Windows\\System32\\ikeext.dll

02:09:13.0505 4208  IKEEXT - ok

02:09:13.0552 4208  [ C4E67D3037DC79E39D7136581A947F50 ] inspect         C:\\Windows\\system32\\DRIVERS\\inspect.sys

02:09:13.0552 4208  inspect - ok

02:09:13.0583 4208  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\\Windows\\system32\\drivers\\intelide.sys

02:09:13.0598 4208  intelide - ok

02:09:13.0630 4208  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\\Windows\\system32\\DRIVERS\\intelppm.sys

02:09:13.0630 4208  intelppm - ok

02:09:13.0661 4208  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum       C:\\Windows\\system32\\ipbusenum.dll

02:09:13.0676 4208  IPBusEnum - ok

02:09:13.0708 4208  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\\Windows\\system32\\DRIVERS\\ipfltdrv.sys

02:09:13.0723 4208  IpFilterDriver - ok

02:09:13.0770 4208  [ A34A587FFFD45FA649FBA6D03784D257 ] IpHlpSvc        C:\\Windows\\System32\\iphlpsvc.dll

02:09:13.0848 4208  IpHlpSvc - ok

02:09:13.0879 4208  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV         C:\\Windows\\system32\\drivers\\IPMIDrv.sys

02:09:13.0895 4208  IPMIDRV - ok

02:09:13.0926 4208  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT           C:\\Windows\\system32\\drivers\\ipnat.sys

02:09:13.0926 4208  IPNAT - ok

02:09:13.0957 4208  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\\Windows\\system32\\drivers\\irenum.sys

02:09:13.0957 4208  IRENUM - ok

02:09:13.0988 4208  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\\Windows\\system32\\drivers\\isapnp.sys

02:09:13.0988 4208  isapnp - ok

02:09:14.0020 4208  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\\Windows\\system32\\drivers\\msiscsi.sys

02:09:14.0066 4208  iScsiPrt - ok

02:09:14.0113 4208  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\\Windows\\system32\\drivers\\kbdclass.sys

02:09:14.0113 4208  kbdclass - ok

02:09:14.0144 4208  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\\Windows\\system32\\drivers\\kbdhid.sys

02:09:14.0144 4208  kbdhid - ok

02:09:14.0191 4208  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\\Windows\\system32\\lsass.exe

02:09:14.0207 4208  KeyIso - ok

02:09:14.0222 4208  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\\Windows\\system32\\Drivers\\ksecdd.sys

02:09:14.0222 4208  KSecDD - ok

02:09:14.0254 4208  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg         C:\\Windows\\system32\\Drivers\\ksecpkg.sys

02:09:14.0254 4208  KSecPkg - ok

02:09:14.0300 4208  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk         C:\\Windows\\system32\\drivers\\ksthunk.sys

02:09:14.0300 4208  ksthunk - ok

02:09:14.0347 4208  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm           C:\\Windows\\system32\\msdtckrm.dll

02:09:14.0378 4208  KtmRm - ok

02:09:14.0441 4208  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\\Windows\\system32\\srvsvc.dll

02:09:14.0488 4208  LanmanServer - ok

02:09:14.0534 4208  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\\Windows\\System32\\wkssvc.dll

02:09:14.0581 4208  LanmanWorkstation - ok

02:09:14.0628 4208  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\\Windows\\system32\\DRIVERS\\lltdio.sys

02:09:14.0628 4208  lltdio - ok

02:09:14.0659 4208  [ C1185803384AB3FEED115F79F109427F ] lltdsvc         C:\\Windows\\System32\\lltdsvc.dll

02:09:14.0690 4208  lltdsvc - ok

02:09:14.0706 4208  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts         C:\\Windows\\System32\\lmhsvc.dll

02:09:14.0737 4208  lmhosts - ok

02:09:14.0784 4208  [ 0803906D607A9B83184447B75B60ECC2 ] LMS             C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

02:09:14.0784 4208  LMS - ok

02:09:14.0815 4208  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\\Windows\\system32\\DRIVERS\\lsi_fc.sys

02:09:14.0831 4208  LSI_FC - ok

02:09:14.0846 4208  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS         C:\\Windows\\system32\\DRIVERS\\lsi_sas.sys

02:09:14.0862 4208  LSI_SAS - ok

02:09:14.0878 4208  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\\Windows\\system32\\DRIVERS\\lsi_sas2.sys

02:09:14.0878 4208  LSI_SAS2 - ok

02:09:14.0893 4208  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\\Windows\\system32\\DRIVERS\\lsi_scsi.sys

02:09:14.0909 4208  LSI_SCSI - ok

02:09:14.0940 4208  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv           C:\\Windows\\system32\\drivers\\luafv.sys

02:09:14.0940 4208  luafv - ok

02:09:14.0971 4208  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc         C:\\Windows\\system32\\Mcx2Svc.dll

02:09:15.0002 4208  Mcx2Svc - ok

02:09:15.0034 4208  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas         C:\\Windows\\system32\\DRIVERS\\megasas.sys

02:09:15.0034 4208  megasas - ok

02:09:15.0065 4208  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\\Windows\\system32\\DRIVERS\\MegaSR.sys

02:09:15.0080 4208  MegaSR - ok

02:09:15.0127 4208  [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64          C:\\Windows\\system32\\DRIVERS\\HECIx64.sys

02:09:15.0127 4208  MEIx64 - ok

02:09:15.0158 4208  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS           C:\\Windows\\system32\\mmcss.dll

02:09:15.0190 4208  MMCSS - ok

02:09:15.0205 4208  [ 800BA92F7010378B09F9ED9270F07137 ] Modem           C:\\Windows\\system32\\drivers\\modem.sys

02:09:15.0205 4208  Modem - ok

02:09:15.0236 4208  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor         C:\\Windows\\system32\\DRIVERS\\monitor.sys

02:09:15.0236 4208  monitor - ok

02:09:15.0268 4208  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\\Windows\\system32\\drivers\\mouclass.sys

02:09:15.0283 4208  mouclass - ok

02:09:15.0299 4208  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\\Windows\\system32\\DRIVERS\\mouhid.sys

02:09:15.0299 4208  mouhid - ok

02:09:15.0346 4208  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\\Windows\\system32\\drivers\\mountmgr.sys

02:09:15.0346 4208  mountmgr - ok

02:09:15.0361 4208  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\\Windows\\system32\\drivers\\mpio.sys

02:09:15.0377 4208  mpio - ok

02:09:15.0392 4208  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\\Windows\\system32\\drivers\\mpsdrv.sys

02:09:15.0408 4208  mpsdrv - ok

02:09:15.0486 4208  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\\Windows\\system32\\mpssvc.dll

02:09:15.0533 4208  MpsSvc - ok

02:09:15.0580 4208  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\\Windows\\system32\\drivers\\mrxdav.sys

02:09:15.0595 4208  MRxDAV - ok

02:09:15.0626 4208  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\\Windows\\system32\\DRIVERS\\mrxsmb.sys

02:09:15.0626 4208  mrxsmb - ok

02:09:15.0658 4208  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\\Windows\\system32\\DRIVERS\\mrxsmb10.sys

02:09:15.0689 4208  mrxsmb10 - ok

02:09:15.0704 4208  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\\Windows\\system32\\DRIVERS\\mrxsmb20.sys

02:09:15.0720 4208  mrxsmb20 - ok

02:09:15.0751 4208  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\\Windows\\system32\\drivers\\msahci.sys

02:09:15.0751 4208  msahci - ok

02:09:15.0782 4208  [ DB801A638D011B9633829EB6F663C900 ] msdsm           C:\\Windows\\system32\\drivers\\msdsm.sys

02:09:15.0798 4208  msdsm - ok

02:09:15.0814 4208  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC           C:\\Windows\\System32\\msdtc.exe

02:09:15.0845 4208  MSDTC - ok

02:09:15.0876 4208  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\\Windows\\system32\\drivers\\Msfs.sys

02:09:15.0892 4208  Msfs - ok

02:09:15.0970 4208  [ F7E0900F9A8E3F71F2C16A932F0E03E0 ] msftesql$PRIMAVERA C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

02:09:16.0188 4208  msftesql$PRIMAVERA - ok

02:09:16.0235 4208  [ F7E0900F9A8E3F71F2C16A932F0E03E0 ] msftesql$SQLEXPRESS C:\\Program Files (x86)\\Microsoft SQL Server\\MSSQL.2\\MSSQL\\Binn\\msftesql.exe

02:09:16.0406 4208  msftesql$SQLEXPRESS - ok

02:09:16.0438 4208  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf       C:\\Windows\\System32\\drivers\\mshidkmdf.sys

02:09:16.0453 4208  mshidkmdf - ok

02:09:16.0484 4208  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\\Windows\\system32\\drivers\\msisadrv.sys

02:09:16.0484 4208  msisadrv - ok

02:09:16.0531 4208  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI         C:\\Windows\\system32\\iscsiexe.dll

02:09:16.0547 4208  MSiSCSI - ok

02:09:16.0562 4208  msiserver - ok

02:09:16.0594 4208  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV         C:\\Windows\\system32\\drivers\\MSKSSRV.sys

02:09:16.0594 4208  MSKSSRV - ok

02:09:16.0609 4208  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\\Windows\\system32\\drivers\\MSPCLOCK.sys

02:09:16.0609 4208  MSPCLOCK - ok

02:09:16.0625 4208  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM           C:\\Windows\\system32\\drivers\\MSPQM.sys

02:09:16.0640 4208  MSPQM - ok

02:09:16.0703 4208  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC           C:\\Windows\\system32\\drivers\\MsRPC.sys

02:09:16.0718 4208  MsRPC - ok

02:09:16.0734 4208  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\\Windows\\system32\\drivers\\mssmbios.sys

02:09:16.0734 4208  mssmbios - ok

02:09:16.0765 4208  MSSQL$PRIMAVERA - ok

02:09:16.0781 4208  MSSQL$SQLEXPRESS - ok

02:09:16.0828 4208  [ ADAF062116B4E6D96E44D26486A87AF6 ] MSSQLServerADHelper C:\\Program Files (x86)\\Microsoft SQL Server\\90\\Shared\\sqladhlp90.exe

02:09:16.0843 4208  MSSQLServerADHelper - ok

02:09:16.0859 4208  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE           C:\\Windows\\system32\\drivers\\MSTEE.sys

02:09:16.0874 4208  MSTEE - ok

02:09:16.0890 4208  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\\Windows\\system32\\DRIVERS\\MTConfig.sys

02:09:16.0890 4208  MTConfig - ok

02:09:16.0921 4208  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup             C:\\Windows\\system32\\Drivers\\mup.sys

02:09:16.0921 4208  Mup - ok

02:09:16.0968 4208  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\\Windows\\system32\\qagentRT.dll

02:09:17.0015 4208  napagent - ok

02:09:17.0077 4208  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP     C:\\Windows\\system32\\DRIVERS\\nwifi.sys

02:09:17.0093 4208  NativeWifiP - ok

02:09:17.0140 4208  [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS            C:\\Windows\\system32\\drivers\\ndis.sys

02:09:17.0155 4208  NDIS - ok

02:09:17.0186 4208  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap         C:\\Windows\\system32\\DRIVERS\\ndiscap.sys

02:09:17.0202 4208  NdisCap - ok

02:09:17.0218 4208  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\\Windows\\system32\\DRIVERS\\ndistapi.sys

02:09:17.0233 4208  NdisTapi - ok

02:09:17.0264 4208  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio         C:\\Windows\\system32\\DRIVERS\\ndisuio.sys

02:09:17.0280 4208  Ndisuio - ok

02:09:17.0311 4208  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan         C:\\Windows\\system32\\DRIVERS\\ndiswan.sys

02:09:17.0327 4208  NdisWan - ok

02:09:17.0358 4208  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy         C:\\Windows\\system32\\drivers\\NDProxy.sys

02:09:17.0358 4208  NDProxy - ok

02:09:17.0389 4208  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS         C:\\Windows\\system32\\DRIVERS\\netbios.sys

02:09:17.0405 4208  NetBIOS - ok

02:09:17.0436 4208  [ 09594D1089C523423B32A4229263F068 ] NetBT           C:\\Windows\\system32\\DRIVERS\\netbt.sys

02:09:17.0467 4208  NetBT - ok

02:09:17.0483 4208  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\\Windows\\system32\\lsass.exe

02:09:17.0498 4208  Netlogon - ok

02:09:17.0561 4208  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\\Windows\\System32\\netman.dll

02:09:17.0608 4208  Netman - ok

02:09:17.0623 4208  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\\Windows\\System32\\netprofm.dll

02:09:17.0670 4208  netprofm - ok

02:09:17.0732 4208  [ C9E9017AC2291E96ED3376B72BC7CF8D ] netr28ux        C:\\Windows\\system32\\DRIVERS\\netr28ux.sys

02:09:17.0779 4208  netr28ux - ok

02:09:17.0810 4208  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\SMSvcHost.exe

02:09:18.0029 4208  NetTcpPortSharing - ok

02:09:18.0060 4208  [ A97D9B1C2EEB2E169D2593E7073BCD27 ] NetworkX        C:\\Windows\\System32\\ckldrv.sys

02:09:18.0076 4208  NetworkX - ok

02:09:18.0107 4208  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960         C:\\Windows\\system32\\DRIVERS\\nfrd960.sys

02:09:18.0122 4208  nfrd960 - ok

02:09:18.0200 4208  [ 07937CE37AD35FBECBF9D8BE584DCF2A ] NitroDriverReadSpool8 C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe

02:09:18.0216 4208  NitroDriverReadSpool8 - ok

02:09:18.0263 4208  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\\Windows\\System32\\nlasvc.dll

02:09:18.0294 4208  NlaSvc - ok

02:09:18.0450 4208  [ 06FE5405DA932CD4DEF1517B532F543A ] nlsX86cc        C:\\Windows\\SysWOW64\\NLSSRV32.EXE

02:09:18.0684 4208  nlsX86cc - ok

02:09:18.0715 4208  [ 02C1198276C0D4F39E54EB5148AF1E2A ] nmwcdcx64       C:\\Windows\\system32\\drivers\\ccdcmbox64.sys

02:09:18.0731 4208  nmwcdcx64 - ok

02:09:18.0746 4208  [ D8F00FCC82451BDAA3DB93BB62AE6AC3 ] nmwcdx64        C:\\Windows\\system32\\drivers\\ccdcmbx64.sys

02:09:18.0762 4208  nmwcdx64 - ok

02:09:18.0778 4208  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\\Windows\\system32\\drivers\\Npfs.sys

02:09:18.0778 4208  Npfs - ok

02:09:18.0809 4208  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi             C:\\Windows\\system32\\nsisvc.dll

02:09:18.0840 4208  nsi - ok

02:09:18.0856 4208  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\\Windows\\system32\\drivers\\nsiproxy.sys

02:09:18.0871 4208  nsiproxy - ok

02:09:18.0949 4208  [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs            C:\\Windows\\system32\\drivers\\Ntfs.sys

02:09:19.0027 4208  Ntfs - ok

02:09:19.0043 4208  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\\Windows\\system32\\drivers\\Null.sys

02:09:19.0058 4208  Null - ok

02:09:19.0090 4208  [ 158AD24745BD85BA9BE3C51C38F48C32 ] nusb3hub        C:\\Windows\\system32\\DRIVERS\\nusb3hub.sys

02:09:19.0090 4208  nusb3hub - ok

02:09:19.0105 4208  [ D40A13B2C0891E218F9523B376955DB6 ] nusb3xhc        C:\\Windows\\system32\\DRIVERS\\nusb3xhc.sys

02:09:19.0121 4208  nusb3xhc - ok

02:09:19.0168 4208  [ F2662FDC20518EE8A8EED4F61BA42349 ] NVHDA           C:\\Windows\\system32\\drivers\\nvhda64v.sys

02:09:19.0183 4208  NVHDA - ok

02:09:19.0526 4208  [ 573B0941A37AEBEE96085D56A103F57B ] nvlddmkm        C:\\Windows\\system32\\DRIVERS\\nvlddmkm.sys

02:09:19.0729 4208  nvlddmkm - ok

02:09:19.0760 4208  [ 43AF7EBEAC2AB623468E32CADDCB61A4 ] nvpciflt        C:\\Windows\\system32\\DRIVERS\\nvpciflt.sys

02:09:19.0760 4208  nvpciflt - ok

02:09:19.0807 4208  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\\Windows\\system32\\drivers\\nvraid.sys

02:09:19.0823 4208  nvraid - ok

02:09:19.0854 4208  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\\Windows\\system32\\drivers\\nvstor.sys

02:09:19.0854 4208  nvstor - ok

02:09:19.0901 4208  [ C500760572C6059918FB0C960967695B ] NVSvc           C:\\Windows\\system32\\nvvsvc.exe

02:09:19.0948 4208  NVSvc - ok

02:09:20.0041 4208  [ F28169A7ADF7B41809CF92D369E744F0 ] nvUpdatusService C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe

02:09:20.0462 4208  nvUpdatusService - ok

02:09:20.0494 4208  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\\Windows\\system32\\drivers\\nv_agp.sys

02:09:20.0509 4208  nv_agp - ok

02:09:20.0540 4208  odserv - ok

02:09:20.0572 4208  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\\Windows\\system32\\drivers\\ohci1394.sys

02:09:20.0587 4208  ohci1394 - ok

02:09:20.0650 4208  [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose             C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE

02:09:20.0868 4208  ose - ok

02:09:21.0040 4208  [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc         C:\\Program Files\\Common Files\\Microsoft Shared\\OfficeSoftwareProtectionPlatform\\OSPPSVC.EXE

02:09:21.0258 4208  osppsvc - ok

02:09:21.0305 4208  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\\Windows\\system32\\pnrpsvc.dll

02:09:21.0352 4208  p2pimsvc - ok

02:09:21.0367 4208  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\\Windows\\system32\\p2psvc.dll

02:09:21.0414 4208  p2psvc - ok

02:09:21.0445 4208  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport         C:\\Windows\\system32\\DRIVERS\\parport.sys

02:09:21.0461 4208  Parport - ok

02:09:21.0492 4208  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr         C:\\Windows\\system32\\drivers\\partmgr.sys

02:09:21.0492 4208  partmgr - ok

02:09:21.0523 4208  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\\Windows\\System32\\pcasvc.dll

02:09:21.0554 4208  PcaSvc - ok

02:09:21.0601 4208  [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd        C:\\Windows\\system32\\DRIVERS\\pccsmcfdx64.sys

02:09:21.0601 4208  pccsmcfd - ok

02:09:21.0632 4208  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci             C:\\Windows\\system32\\drivers\\pci.sys

02:09:21.0664 4208  pci - ok

02:09:21.0695 4208  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\\Windows\\system32\\drivers\\pciide.sys

02:09:21.0695 4208  pciide - ok

02:09:21.0726 4208  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\\Windows\\system32\\DRIVERS\\pcmcia.sys

02:09:21.0742 4208  pcmcia - ok

02:09:21.0757 4208  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw             C:\\Windows\\system32\\drivers\\pcw.sys

02:09:21.0773 4208  pcw - ok

02:09:21.0804 4208  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\\Windows\\system32\\drivers\\peauth.sys

02:09:21.0835 4208  PEAUTH - ok

02:09:21.0898 4208  [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc     C:\\Windows\\system32\\peerdistsvc.dll

02:09:21.0976 4208  PeerDistSvc - ok

02:09:22.0022 4208  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\\Windows\\SysWow64\\perfhost.exe

02:09:22.0272 4208  PerfHost - ok

02:09:22.0350 4208  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla             C:\\Windows\\system32\\pla.dll

02:09:22.0428 4208  pla - ok

02:09:22.0490 4208  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\\Windows\\system32\\umpnpmgr.dll

02:09:22.0553 4208  PlugPlay - ok

02:09:22.0584 4208  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg     C:\\Windows\\system32\\pnrpauto.dll

02:09:22.0631 4208  PNRPAutoReg - ok

02:09:22.0646 4208  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc         C:\\Windows\\system32\\pnrpsvc.dll

02:09:22.0678 4208  PNRPsvc - ok

02:09:22.0709 4208  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent     C:\\Windows\\System32\\ipsecsvc.dll

02:09:22.0756 4208  PolicyAgent - ok

02:09:22.0802 4208  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power           C:\\Windows\\system32\\umpo.dll

02:09:22.0849 4208  Power - ok

02:09:22.0880 4208  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\\Windows\\system32\\DRIVERS\\raspptp.sys

02:09:22.0896 4208  PptpMiniport - ok

02:09:23.0005 4208  [ 4747B514561B1F6E8937202C0BCE0411 ] PrmBackAgent    C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe

02:09:23.0426 4208  PrmBackAgent - ok

02:09:23.0458 4208  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor       C:\\Windows\\system32\\DRIVERS\\processr.sys

02:09:23.0458 4208  Processor - ok

02:09:23.0504 4208  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc         C:\\Windows\\system32\\profsvc.dll

02:09:23.0536 4208  ProfSvc - ok

02:09:23.0551 4208  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\\Windows\\system32\\lsass.exe

02:09:23.0582 4208  ProtectedStorage - ok

02:09:23.0629 4208  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\\Windows\\system32\\DRIVERS\\pacer.sys

02:09:23.0645 4208  Psched - ok

02:09:23.0692 4208  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\\Windows\\system32\\DRIVERS\\ql2300.sys

02:09:23.0754 4208  ql2300 - ok

02:09:23.0770 4208  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\\Windows\\system32\\DRIVERS\\ql40xx.sys

02:09:23.0785 4208  ql40xx - ok

02:09:23.0816 4208  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE           C:\\Windows\\system32\\qwave.dll

02:09:23.0863 4208  QWAVE - ok

02:09:23.0879 4208  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\\Windows\\system32\\drivers\\qwavedrv.sys

02:09:23.0894 4208  QWAVEdrv - ok

02:09:23.0910 4208  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\\Windows\\system32\\DRIVERS\\rasacd.sys

02:09:23.0910 4208  RasAcd - ok

02:09:23.0957 4208  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn     C:\\Windows\\system32\\DRIVERS\\AgileVpn.sys

02:09:23.0957 4208  RasAgileVpn - ok

02:09:23.0988 4208  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto         C:\\Windows\\System32\\rasauto.dll

02:09:24.0019 4208  RasAuto - ok

02:09:24.0050 4208  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp         C:\\Windows\\system32\\DRIVERS\\rasl2tp.sys

02:09:24.0066 4208  Rasl2tp - ok

02:09:24.0097 4208  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\\Windows\\System32\\rasmans.dll

02:09:24.0144 4208  RasMan - ok

02:09:24.0175 4208  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\\Windows\\system32\\DRIVERS\\raspppoe.sys

02:09:24.0175 4208  RasPppoe - ok

02:09:24.0206 4208  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp         C:\\Windows\\system32\\DRIVERS\\rassstp.sys

02:09:24.0222 4208  RasSstp - ok

02:09:24.0253 4208  [ 77F665941019A1594D887A74F301FA2F ] rdbss           C:\\Windows\\system32\\DRIVERS\\rdbss.sys

02:09:24.0284 4208  rdbss - ok

02:09:24.0300 4208  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\\Windows\\system32\\DRIVERS\\rdpbus.sys

02:09:24.0316 4208  rdpbus - ok

02:09:24.0331 4208  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\\Windows\\system32\\DRIVERS\\RDPCDD.sys

02:09:24.0331 4208  RDPCDD - ok

02:09:24.0378 4208  [ 1B6163C503398B23FF8B939C67747683 ] RDPDR           C:\\Windows\\system32\\drivers\\rdpdr.sys

02:09:24.0409 4208  RDPDR - ok

02:09:24.0440 4208  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\\Windows\\system32\\drivers\\rdpencdd.sys

02:09:24.0440 4208  RDPENCDD - ok

02:09:24.0472 4208  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\\Windows\\system32\\drivers\\rdprefmp.sys

02:09:24.0472 4208  RDPREFMP - ok

02:09:24.0518 4208  [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\\Windows\\system32\\drivers\\rdpvideominiport.sys

02:09:24.0518 4208  RdpVideoMiniport - ok

02:09:24.0550 4208  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD           C:\\Windows\\system32\\drivers\\RDPWD.sys

02:09:24.0581 4208  RDPWD - ok

02:09:24.0612 4208  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost    

4

sorry Guestolo m late on response 


 


but i had changed my laptop password & forget it unfortunately


 


can you please first guide me how to remove the password  i have checked & done some tutorials form internet but failed to do so ...


 


 


please its off the topic but guide me to remove the pasword so i could perform your asked steps from last post


 


Thanks



5

system seems to be running good now........ but 


 


  1. i have doubts of some keylogger or hacking backdoor file presence on my system,as my system got hacked recently & he stole all my personal files and after that he hacked all my working email ids 



       

    have you found any such traces on my system after these logs.....  


       

     


       

       

  2.    
  3. and i am also seeing some hidden desktop.ini files in almost each folder & dektop ....what is this ? 


6
All processes killed

========== OTL ==========

Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08d6b0b4-c132-470d-a8e2-aa2e9c3851c9}\\ not found.

Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\\ not found.

Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{c34bfb11-eff0-4123-a7a5-79051ef24cf5} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{c34bfb11-eff0-4123-a7a5-79051ef24cf5}\\ not found.

64bit-Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.

64bit-Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0055C089-8582-441B-A0BF-17B458C2A3A8}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{98ED5451-2AA6-96DB-7012-46C7C9673C57}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{98ED5451-2AA6-96DB-7012-46C7C9673C57}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{C08DF07A-3E49-4E25-9AB0-D3882835F153}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C08DF07A-3E49-4E25-9AB0-D3882835F153}\\ deleted successfully.

Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08D6B0B4-C132-470D-A8E2-AA2E9C3851C9}\\ not found.

Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}\\ not found.

Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{C34BFB11-EFF0-4123-A7A5-79051EF24CF5} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C34BFB11-EFF0-4123-A7A5-79051EF24CF5}\\ not found.

Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\IDMan deleted successfully.

64bit-Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download all links with IDM\\ deleted successfully.

64bit-Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download with IDM\\ deleted successfully.

64bit-Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\QuickDefine\\ deleted successfully.

C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm moved successfully.

Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download all links with IDM\\ not found.

Registry key HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\Download with IDM\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f29098-acba-11e1-b04f-bb72616340ba}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\ not found.

File I:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\ not found.

File G:\\Setup.exe /Auto not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568119-c4b4-11e0-b905-001e101f24f1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{86568127-c4b4-11e0-b905-001e101f24f1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e385c-0a03-11e1-916b-95476b19059a}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3869-0a03-11e1-916b-95476b19059a}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{b78e3877-0a03-11e1-916b-95476b19059a}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

File H:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\ not found.

File G:\\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ not found.

Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ not found.

Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\ not found.

File I:\\AutoRun.exe not found.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: All Users

 

User: AppData

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 56466 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

 

User: Faraz

->Temp folder emptied: 13298084 bytes

->Temporary Internet Files folder emptied: 1482353368 bytes

->Java cache emptied: 23858 bytes

->FireFox cache emptied: 66979817 bytes

->Google Chrome cache emptied: 0 bytes

->Opera cache emptied: 0 bytes

->Flash cache emptied: 14912678 bytes

 

User: Public

 

User: UpdatusUser

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\\System32 .tmp files removed: 0 bytes

%systemroot%\\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\\System32\\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 63117321 bytes

%systemroot%\\sysnative\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files folder emptied: 100669 bytes

RecycleBin emptied: 0 bytes

 

Total Files Cleaned = 1,565.00 mb

 

 

OTL by OldTimer - Version 3.2.69.0 log created on 08042013_174319

 

Files\\Folders moved on Reboot...

C:\\Users\\Faraz\\AppData\\Local\\Temp\\FXSAPIDebugLogFile.txt moved successfully.

 

PendingFileRenameOperations files...

 

Registry entries deleted on Reboot...

7

Again the Extras.txt didn\'t popped up & also it is not on desktop 


 


what should i do ?



8
OTL logfile created on: 03/Aug/13 11:38:56 PM - Run 4

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 58.89% Memory free

7.82 Gb Paging File | 6.15 Gb Available in Paging File | 78.69% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 7.81 Gb Free Space | 16.03% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.40 Gb Free Space | 4.92% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 32.71 Gb Free Space | 8.89% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/20 17:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2010/11/20 17:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2010/11/20 17:18:03 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/20 18:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2010/11/20 16:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\TsUsbFlt.sys -- (TsUsbFlt)

DRV:64bit: - [2010/11/20 16:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\rdpvideominiport.sys -- (RdpVideoMiniport)

DRV:64bit: - [2010/11/20 15:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK\'>http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p=\'>http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\'>http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"


FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)






O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O18 - Protocol\\Filter\\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\\PROGRA~2\\COMMON~1\\MICROS~1\\OFFICE12\\MSOXMLMF.DLL File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2013/08/01 23:20:32 | 000,000,000 | ---D | C] -- C:\\Windows\\SysNative\\SPReview

[2013/08/01 23:19:26 | 000,000,000 | ---D | C] -- C:\\Windows\\SysNative\\EventProviders

[2013/08/01 23:19:14 | 000,000,000 | ---D | C] -- C:\\3ca1477372be1ce35eb66ac4b2

[2013/07/29 11:51:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\T

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

 

========== Files - Modified Within 30 Days ==========

 

[2013/08/03 23:35:53 | 000,019,184 | -H-- | M] () -- C:\\Windows\\SysNative\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2013/08/03 23:35:53 | 000,019,184 | -H-- | M] () -- C:\\Windows\\SysNative\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2013/08/03 23:30:30 | 000,067,584 | --S- | M] () -- C:\\Windows\\bootstat.dat

[2013/08/03 23:30:23 | 3148,218,368 | -HS- | M] () -- C:\\hiberfil.sys

[2013/08/03 23:22:06 | 000,000,830 | ---- | M] () -- C:\\Windows\\tasks\\Adobe Flash Player Updater.job

[2013/08/03 23:08:28 | 000,986,742 | ---- | M] () -- C:\\Windows\\SysNative\\PerfStringBackup.INI

[2013/08/03 23:08:28 | 000,815,680 | ---- | M] () -- C:\\Windows\\SysNative\\perfh009.dat

[2013/08/03 23:08:28 | 000,169,078 | ---- | M] () -- C:\\Windows\\SysNative\\perfc009.dat

[2013/08/03 23:07:02 | 000,000,908 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000UA.job

[2013/08/03 22:00:15 | 000,000,928 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000UA.job

[2013/08/03 11:55:03 | 000,000,856 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000Core.job

[2013/08/03 01:00:02 | 000,000,906 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-182233152-2924250215-3996894080-1000Core.job

[2013/08/02 22:21:22 | 000,002,361 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Google Chrome.lnk

[2013/08/02 21:17:57 | 000,344,816 | ---- | M] () -- C:\\Windows\\SysNative\\FNTCACHE.DAT

[2013/08/01 23:41:46 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\msclmd.dll

[2013/08/01 23:41:45 | 000,175,616 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msclmd.dll

[2013/07/25 04:38:36 | 000,000,105 | ---- | M] () -- C:\\Windows\\DeleteOnReboot.bat

[2013/07/25 04:20:28 | 000,666,633 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\AdwCleaner.exe

[2013/07/25 04:19:54 | 000,560,934 | ---- | M] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,002,975 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\HiJackThis.lnk

[2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,866 | ---- | M] () -- C:\\Users\\Public\\Desktop\\EVDO BROADBAND PTCL.lnk

[2013/07/20 10:48:19 | 000,000,600 | ---- | M] () -- C:\\Users\\Faraz\\PUTTY.RND

[2013/07/20 10:23:20 | 000,580,227 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\How To Hack Any Email Account.pdf

[2013/07/20 09:03:30 | 000,242,310 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\[Tutorial] Disinfecting and Hacking a Keylogger ~ Software Zone.pdf

[2013/07/19 17:23:55 | 001,474,832 | ---- | M] () -- C:\\Windows\\SysNative\\drivers\\sfi.dat

[2013/07/19 16:51:11 | 000,222,725 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Untitled.jpg

[2013/07/18 00:54:17 | 000,441,269 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Q\'s Blog.pdf

[2013/07/16 16:29:58 | 000,174,956 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\HR Q & A.pdf

[2013/07/12 02:14:50 | 001,501,408 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Understanding The Differ..._ Simple Small Business.pdf

[2013/07/12 01:59:48 | 000,644,296 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Markup vs. Margin. What ...rence_ – Consero Global.pdf

[2013/07/12 01:54:42 | 002,197,905 | ---- | M] () -- C:\\Users\\Faraz\\Desktop\\Gross margin .pdf

[2013/07/10 23:38:42 | 000,001,922 | ---- | M] () -- C:\\Users\\Public\\Desktop\\Nitro Pro 8.lnk

 

========== Files Created - No Company Name ==========

 

[2013/07/25 04:36:43 | 000,000,105 | ---- | C] () -- C:\\Windows\\DeleteOnReboot.bat

[2013/07/25 04:33:26 | 000,666,633 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\AdwCleaner.exe

[2013/07/24 19:03:10 | 000,002,975 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\HiJackThis.lnk

[2013/07/21 00:18:49 | 000,000,866 | ---- | C] () -- C:\\Users\\Public\\Desktop\\EVDO BROADBAND PTCL.lnk

[2013/07/20 10:23:20 | 000,580,227 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\How To Hack Any Email Account.pdf

[2013/07/20 09:03:23 | 000,242,310 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\[Tutorial] Disinfecting and Hacking a Keylogger ~ Software Zone.pdf

[2013/07/18 00:52:53 | 000,441,269 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Q\'s Blog.pdf

[2013/07/16 16:29:21 | 000,174,956 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\HR Q & A.pdf

[2013/07/15 16:16:24 | 002,197,905 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Gross margin .pdf

[2013/07/15 16:16:24 | 001,501,408 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Understanding The Differ..._ Simple Small Business.pdf

[2013/07/15 16:16:24 | 000,644,296 | ---- | C] () -- C:\\Users\\Faraz\\Desktop\\Markup vs. Margin. What ...rence_ – Consero Global.pdf

[2013/06/27 12:18:04 | 000,033,576 | ---- | C] () -- C:\\Windows\\SysWow64\\BCGPOleAcc.dll

[2013/06/17 14:22:10 | 000,003,441 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\lgr

[2013/06/16 20:21:28 | 000,000,884 | RHS- | C] () -- C:\\Users\\Faraz\\ntuser.pol

[2013/05/31 12:10:39 | 000,007,605 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Local\\Resmon.ResmonCfg

[2013/03/29 14:37:29 | 000,000,004 | ---- | C] () -- C:\\Windows\\vx86036.dat

[2013/03/29 14:36:01 | 000,000,054 | ---- | C] () -- C:\\Windows\\Crypkey.ini

[2013/03/29 14:35:58 | 000,011,776 | ---- | C] () -- C:\\Windows\\Ckrfresh.exe

[2013/03/09 00:05:20 | 000,000,009 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\WinAcc.EML

[2013/03/08 23:59:52 | 000,017,920 | ---- | C] () -- C:\\Windows\\SysWow64\\implode.dll

[2012/08/26 01:49:44 | 000,000,022 | ---- | C] () -- C:\\Windows\\Wininit.ini

[2012/08/05 21:58:10 | 000,002,016 | -HS- | C] () -- C:\\Windows\\SysWow64\\win_fp_sys.dat

[2012/08/05 21:47:33 | 000,000,000 | -HS- | C] () -- C:\\Windows\\SysWow64\\win_fp_app.dat

[2012/08/05 21:47:30 | 000,007,168 | ---- | C] () -- C:\\Windows\\SysWow64\\FPService.exe

[2012/08/05 21:47:29 | 000,116,944 | ---- | C] () -- C:\\Windows\\Secure.dll

[2012/08/05 21:47:29 | 000,110,800 | ---- | C] () -- C:\\Windows\\Secure64.dll

[2012/08/05 21:47:29 | 000,035,840 | ---- | C] () -- C:\\Windows\\SysWow64\\WinFPdrv.sys

[2012/08/05 21:47:29 | 000,008,064 | -HS- | C] () -- C:\\Windows\\SysWow64\\win_fp_config.dat

[2012/08/04 22:11:41 | 000,000,327 | ---- | C] () -- C:\\Windows\\dvdcreator.INI

[2012/08/04 22:07:20 | 000,014,496 | ---- | C] () -- C:\\Windows\\SysWow64\\VDI08X.DAT

[2012/08/04 22:04:00 | 000,135,168 | ---- | C] () -- C:\\Windows\\SysWow64\\VDProductInfoEx.dll

[2012/08/02 01:37:56 | 000,149,504 | ---- | C] () -- C:\\Windows\\SysWow64\\UNWISE.EXE

[2011/10/12 01:02:54 | 000,006,656 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Local\\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011/10/10 23:25:18 | 000,000,000 | ---- | C] () -- C:\\Windows\\SysWow64\\cd.dat

[2011/09/27 00:18:38 | 000,037,647 | ---- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\Debut.dmp

[2011/09/01 17:06:21 | 000,000,600 | ---- | C] () -- C:\\Users\\Faraz\\PUTTY.RND

[2011/08/13 23:07:15 | 000,000,990 | -HS- | C] () -- C:\\Users\\Faraz\\AppData\\Roaming\\systemfl.$dk

 

========== ZeroAccess Check ==========

 

[2011/11/17 12:14:10 | 000,002,048 | -HS- | M] () -- C:\\Windows\\Installer\\{7c0eee1f-7b7e-6235-9f22-0f2dea83d0ae}\\@

[2013/07/03 16:10:09 | 000,000,000 | -HSD | M] -- C:\\Windows\\Installer\\{7c0eee1f-7b7e-6235-9f22-0f2dea83d0ae}\\L

[2013/04/19 11:30:38 | 000,000,000 | -HSD | M] -- C:\\Windows\\Installer\\{7c0eee1f-7b7e-6235-9f22-0f2dea83d0ae}\\U

[2009/07/14 09:55:00 | 000,000,227 | RHS- | M] () -- C:\\Windows\\assembly\\Desktop.ini

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32] /64

 

[HKEY_CURRENT_USER\\Software\\Classes\\Wow6432node\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32] /64

 

[HKEY_CURRENT_USER\\Software\\Classes\\Wow6432node\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32]

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32] /64

\"\" = C:\\Windows\\SysNative\\shell32.dll -- [2012/06/09 10:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Apartment

 

[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

\"\" = %SystemRoot%\\system32\\shell32.dll -- [2012/06/09 09:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Apartment

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32] /64

\"\" = C:\\Windows\\SysNative\\wbem\\fastprox.dll -- [2009/07/14 06:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Free

 

[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32]

\"\" = %systemroot%\\system32\\wbem\\fastprox.dll -- [2010/11/20 17:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Free

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32] /64

\"\" = C:\\Windows\\SysNative\\wbem\\wbemess.dll -- [2009/07/14 06:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Both

 

[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32]

 

< End of report >

 


9
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK\'>http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p=\'>http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\'>http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"


FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo\'>http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)






O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,

10
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK\'>http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p=\'>http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\'>http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"


FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo\'>http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)






O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,

11
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK\'>http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p=\'>http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\'>http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"


FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo\'>http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)






O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,

12
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK\'>http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p=\'>http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\'>http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"


FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo\'>http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)






O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,

13
OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free

7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = 

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK\'>http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p=\'>http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\'>http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"


FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

FF - user.js - File not found

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\[email protected]

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo\'>http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)






O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL

[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL

[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo

[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA

[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO

[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot

[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo

[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO

[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo

[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo

[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll

[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll

[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP

[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys

[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys

[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab

[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security

[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security

[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs

[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero

[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero

[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll

[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll

[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll

[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll

[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll

[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll

[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead

[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero

[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps

[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps

[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys

[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices

[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager

[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen

[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen

[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll

[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll

[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro

[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro

[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro

[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF

[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia

[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java

[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys

[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll

[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll

[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll

[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll

[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll

[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll

[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll

[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll

[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe

[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll

[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll

[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll

[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll

[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll

[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll

[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll

[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll

[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll

[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll

[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe

[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll

[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll

[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe

[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll

[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll

[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll

[2013/05/06 01:53:19 | 000,

14
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 5.2.2 (07.22.2013:2)

OS: Windows 7 Ultimate x64

Ran by Faraz on 25/Jul/13 at  4:49:55.16

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

~~~ Services

 

Successfully stopped: [Service] hshld 

Successfully deleted: [Service] hshld 

Successfully stopped: [Service] hsstrayservice 

Successfully deleted: [Service] hsstrayservice 

Successfully stopped: [Service] hsswd 

Successfully deleted: [Service] hsswd 

 

 

 

~~~ Registry Values

 

 

 

~~~ Registry Keys

 

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\anchorfree

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\hotspotshield

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\hotspotshield

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\tracing\\apnstub_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\tracing\\apnstub_rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\tracing\\askpartnercobrandingtool_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\tracing\\askpartnercobrandingtool_rasmancs

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{7902DE1C-DFB2-426C-A5A1-F87FD90FBEEB}

 

 

 

~~~ Files

 

 

 

~~~ Folders

 

Successfully deleted: [Folder] \"C:\\ProgramData\\codecc\"

Successfully deleted: [Folder] \"C:\\Users\\Faraz\\appdata\\locallow\\codecc\"

 

 

 

~~~ Event Viewer Logs were cleared

 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on 25/Jul/13 at  5:42:55.18

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

15

# AdwCleaner v2.306 - Logfile created 07/25/2013 at 04:36:30


# Updated 19/07/2013 by Xplode

# Operating system : Windows 7 Ultimate  (64 bits)

# User : Faraz - SLAIN

# Boot Mode : Normal

# Running from : C:\\Users\\Faraz\\Desktop\\AdwCleaner.exe

# Option [Delete]

 

 

***** [Services] *****

 

 

***** [Files / Folders] *****

 

Deleted on reboot : C:\\Program Files (x86)\\Hotspot Shield

File Deleted : C:\\Program Files (x86)\\Mozilla Firefox\\searchplugins\\avg-secure-search.xml

File Deleted : C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\chrome-extension_jbpcjmidkkgldeplajgnbpjkfpmpeepb_0.localstorage

File Deleted : C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\chrome-extension_jbpcjmidkkgldeplajgnbpjkfpmpeepb_0.localstorage-journal

File Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\searchplugins\\Babylon.xml

File Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\searchplugins\\delta.xml

File Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\searchplugins\\WebSearch.xml

File Deleted : C:\\Windows\\SysWOW64\\conduitEngine.tmp

Folder Deleted : C:\\Program Files (x86)\\Hotspot_Shield

Folder Deleted : C:\\Program Files (x86)\\Mozilla Firefox\\Extensions\\[email protected]

Folder Deleted : C:\\ProgramData\\Hotspot Shield

Folder Deleted : C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Hotspot Shield

Folder Deleted : C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jbpcjmidkkgldeplajgnbpjkfpmpeepb

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\Conduit

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\ConduitEngine

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\delta

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\Hotspot_Shield

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\PriceGong

Folder Deleted : C:\\Users\\Faraz\\AppData\\LocalLow\\Toolbar4

Folder Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Babylon

Folder Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\staged

Folder Deleted : C:\\Users\\Faraz\\AppData\\Roaming\\OpenCandy

Folder Deleted : C:\\Windows\\SysWOW64\\Hotspot Shield

 

***** [Registry] *****

 

Key Deleted : HKCU\\Software\\1ClickDownload

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\conduitEngine

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\ConduitSearchScopes

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\Crossrider

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\Hotspot_Shield

Key Deleted : HKCU\\Software\\AppDataLow\\Software\\PriceGong

Key Deleted : HKCU\\Software\\AppDataLow\\SProtector

Key Deleted : HKCU\\Software\\AppDataLow\\Toolbar

Key Deleted : HKCU\\Software\\BI

Key Deleted : HKCU\\Software\\Conduit

Key Deleted : HKCU\\Software\\Headlight

Key Deleted : HKCU\\Software\\IGearSettings

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{A42F6A7C-B5FA-4565-AC08-ECB439C4342D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{07FCE05F-98B6-4017-8DCE-DCC5823B7678}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{C522512A-9C2C-4DE5-9F63-976B560FEF14}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{79A765E1-C399-405B-85AF-466F52E918B0}

Key Deleted : HKCU\\Software\\Optimizer Pro

Key Deleted : HKCU\\Software\\Softonic

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{C99FDC39-A1AE-4B24-8D71-E5274F8D7C54}

Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{D3F22A84-2A84-49EB-91E6-5DADAAF0165D}

Key Deleted : HKLM\\Software\\Babylon

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\{4CE516A7-F7AC-4628-B411-8F886DC5733E}

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\{628F3201-34D0-49C0-BB9A-82A26AEFB291}

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\DefaultTabBHO.DLL

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\TbCommonUtils.DLL

Key Deleted : HKLM\\SOFTWARE\\Classes\\AppID\\TbHelper.EXE

Key Deleted : HKLM\\SOFTWARE\\Classes\\bhoclass.bho.bhoclass.bho

Key Deleted : HKLM\\SOFTWARE\\Classes\\bhoclass.bho.bhoclass.bho.1.0

Key Deleted : HKLM\\SOFTWARE\\Classes\\ComObject.DeskbarEnabler

Key Deleted : HKLM\\SOFTWARE\\Classes\\ComObject.DeskbarEnabler.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Conduit.Engine

Key Deleted : HKLM\\SOFTWARE\\Classes\\DefaultTabBHO.DefaultTabBrowser

Key Deleted : HKLM\\SOFTWARE\\Classes\\DefaultTabBHO.DefaultTabBrowser.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\DefaultTabBHO.DefaultTabBrowserActiveX

Key Deleted : HKLM\\SOFTWARE\\Classes\\DefaultTabBHO.DefaultTabBrowserActiveX.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Prod.cap

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbCommonUtils.CommonUtils

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbCommonUtils.CommonUtils.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbDownloadManager

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbDownloadManager.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbPropertyManager

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbPropertyManager.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbRequest

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbRequest.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbTask

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.TbTask.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.ToolbarHelper

Key Deleted : HKLM\\SOFTWARE\\Classes\\TbHelper.ToolbarHelper.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TBSB00001.IEToolbar

Key Deleted : HKLM\\SOFTWARE\\Classes\\TBSB00001.IEToolbar.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TBSB00001.TBSB00001

Key Deleted : HKLM\\SOFTWARE\\Classes\\TBSB00001.TBSB00001.3

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar.CT1561552

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar.CT2786678

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar.CT3031607

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar.CT3080215

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.ContextMenuNotifier

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.ContextMenuNotifier.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.CustomInternetSecurityImpl

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.CustomInternetSecurityImpl.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.SearchProviderManager

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.SearchProviderManager.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.XBTBPos00

Key Deleted : HKLM\\SOFTWARE\\Classes\\Toolbar3.XBTBPos00.1

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{4509D3CC-B642-4745-B030-645B79522C6D}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{B87F8B63-7274-43FD-87FA-09D3B7496148}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{E2343056-CC08-46AC-B898-BFC7ACF4E755}

Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}

Key Deleted : HKLM\\SOFTWARE\\Classes\\URLSearchHook.ToolbarURLSearchHook

Key Deleted : HKLM\\SOFTWARE\\Classes\\URLSearchHook.ToolbarURLSearchHook.1

Key Deleted : HKLM\\Software\\Conduit

Key Deleted : HKLM\\Software\\conduitEngine

Key Deleted : HKLM\\Software\\Hotspot_Shield

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Tracing\\MyBabylontb_RASAPI32

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Tracing\\MyBabylontb_RASMANCS

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\PreApproved\\{07FCE05F-98B6-4017-8DCE-DCC5823B7678}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\PreApproved\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKLM\\Software\\SP Global

Key Deleted : HKLM\\Software\\SProtector

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{07FCE05F-98B6-4017-8DCE-DCC5823B7678}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{57CADC46-58FF-4105-B733-5A9F3FC9783C}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{A42F6A7C-B5FA-4565-AC08-ECB439C4342D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{C339D489-FABC-41DD-B39D-276101667C70}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{CA3EB689-8F09-4026-AA10-B9534C691CE0}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{D89031C2-10DA-4C90-9A62-FCED012BC46B}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{01221FCC-4BFB-461C-B08C-F6D2DF309921}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{03E2A1F3-4402-4121-8B35-733216D61217}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{0FA32667-9A8A-4E9C-902F-CA3323180003}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{2A42D13C-D427-4787-821B-CF6973855778}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{452AE416-9A97-44CA-93DA-D0F15C36254F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{45CDA4F7-594C-49A0-AAD1-8224517FE979}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{4897BBA6-48D9-468C-8EFA-846275D7701B}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{6B458F62-592F-4B25-8967-E6A350A59328}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{81E852CC-1FD5-4004-8761-79A48B975E29}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{B9F43021-60D4-42A6-A065-9BA37F38AC47}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{D2F39980-399F-492E-8D88-5FF7CCB3B47F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Classes\\Interface\\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{1ADA9BAD-CD7C-46EE-8DED-2DC3A6D8949D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{219168C6-531A-4FD7-87DD-ABB6C223EE27}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{45188CF8-B603-48DF-A71A-F55D3C918753}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{628F3201-34D0-49C0-BB9A-82A26AEFB291}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SearchScopes\\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SearchScopes\\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SearchScopes\\{D3F22A84-2A84-49EB-91E6-5DADAAF0165D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7F6AFBF1-E065-4627-A2FD-810366367D01}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{2EF17083-57D4-4D64-AE4F-55F32A2C4571}

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Conduit Engine 

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Hotspot_Shield Toolbar

Key Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Optimizer Pro_is1

Key Deleted : HKLM\\SOFTWARE\\Classes\\CLSID\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{01221FCC-4BFB-461C-B08C-F6D2DF309921}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{03E2A1F3-4402-4121-8B35-733216D61217}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{0FA32667-9A8A-4E9C-902F-CA3323180003}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{2263BE11-ACB7-49D9-8313-6B1D5CC42FAA}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{23119123-0854-469D-807A-171568457991}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{2A42D13C-D427-4787-821B-CF6973855778}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{452AE416-9A97-44CA-93DA-D0F15C36254F}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{45CDA4F7-594C-49A0-AAD1-8224517FE979}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{4897BBA6-48D9-468C-8EFA-846275D7701B}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{6B458F62-592F-4B25-8967-E6A350A59328}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{81E852CC-1FD5-4004-8761-79A48B975E29}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{97FC5555-8BDC-40EA-8DE2-B1E46B9EA629}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{B9F43021-60D4-42A6-A065-9BA37F38AC47}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{BBA74401-6D6F-4BBD-9F65-E8623814F3BB}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{D2F39980-399F-492E-8D88-5FF7CCB3B47F}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}

Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Shared Tools\\MSConfig\\startupreg\\ApnUpdater

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Optimizer Pro_is1

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser [{1BB22D38-A411-4B13-A746-C2A4F4EC7344}]

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\URLSearchHooks [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]

Value Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\URLSearchHooks [{CA3EB689-8F09-4026-AA10-B9534C691CE0}]

Value Deleted : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]

Value Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Toolbar [{1BB22D38-A411-4B13-A746-C2A4F4EC7344}]

Value Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]

Value Deleted : HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Toolbar [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]

 

***** [Internet Browsers] *****

 

-\\\\ Internet Explorer v9.0.8112.16421

 

[OK] Registry is clean.

 

-\\\\ Mozilla Firefox v11.0 (en-US)

 

File : C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\prefs.js

 

C:\\Users\\Faraz\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\user.js ... Deleted !

 

Deleted : user_pref(\"extensions.delta.admin\", false);

Deleted : user_pref(\"extensions.delta.aflt\", \"babsst\");

Deleted : user_pref(\"extensions.delta.appId\", \"{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}\");

Deleted : user_pref(\"extensions.delta.autoRvrt\", \"false\");

Deleted : user_pref(\"extensions.delta.dfltLng\", \"en\");

Deleted : user_pref(\"extensions.delta.excTlbr\", false);

Deleted : user_pref(\"extensions.delta.ffxUnstlRst\", true);

Deleted : user_pref(\"extensions.delta.id\", \"64a3dba0000000000000000000000000\");

Deleted : user_pref(\"extensions.delta.instlDay\", \"15836\");

Deleted : user_pref(\"extensions.delta.instlRef\", \"sst\");

Deleted : user_pref(\"extensions.delta.newTab\", false);

Deleted : user_pref(\"extensions.delta.prdct\", \"delta\");

Deleted : user_pref(\"extensions.delta.prtnrId\", \"delta\");

Deleted : user_pref(\"extensions.delta.rvrt\", \"false\");

Deleted : user_pref(\"extensions.delta.smplGrp\", \"none\");

Deleted : user_pref(\"extensions.delta.tlbrId\", \"base\");

Deleted : user_pref(\"extensions.delta.tlbrSrchUrl\", \"\");

Deleted : user_pref(\"extensions.delta.vrsn\", \"1.8.16.16\");

Deleted : user_pref(\"extensions.delta.vrsnTs\", \"1.8.16.163:02:05\");

Deleted : user_pref(\"extensions.delta.vrsni\", \"1.8.16.16\");

Deleted : user_pref(\"browser.search.order.1\", \"WebSearch\");


Deleted : user_pref(\"browser.search.order.1,S\", \"WebSearch\");

Deleted : user_pref(\"browser.search.defaultenginename,S\", \"WebSearch\");

Deleted : user_pref(\"browser.search.selectedEngine,S\", \"WebSearch\");

 

-\\\\ Google Chrome v28.0.1500.72

 

File : C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Preferences

 


 

-\\\\ Opera v11.50.1074.0

 

File : C:\\Users\\Faraz\\AppData\\Roaming\\Opera\\Opera\\operaprefs.ini

 

[OK] File is clean.

 

*************************

 

AdwCleaner[S1].txt - [22687 octets] - [25/07/2013 04:36:30]

 

########## EOF - C:\\AdwCleaner[S1].txt - [22748 octets] ##########

16

couldn\'t locate the extras.log of otl scan & it also didn\'t popped up



17
OTL logfile created on: 24/Jul/13 7:40:59 PM - Run 2

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Faraz\\Desktop

64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy

 

3.91 Gb Total Physical Memory | 1.72 Gb Available Physical Memory | 43.98% Memory free

7.82 Gb Paging File | 5.44 Gb Available in Paging File | 69.65% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 48.73 Gb Total Space | 5.88 Gb Free Space | 12.06% Space Free | Partition Type: NTFS

Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS

Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS

 

Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

PRC - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe

PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE

PRC - [2012/09/18 14:28:30 | 000,081,928 | ---- | M] (Nitro PDF) -- C:\\Program Files (x86)\\Nitro\\Pro 8\\NitroPDFThumbnailHelper.exe

PRC - [2012/08/17 21:38:34 | 000,128,440 | ---- | M] (Kaspersky Lab ZAO) -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\klwtblfs.exe

PRC - [2011/10/28 17:19:26 | 001,700,600 | ---- | M] (Comodo) -- C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe

PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2013/06/12 21:24:12 | 016,033,160 | ---- | M] () -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll

MOD - [2012/08/17 21:38:56 | 000,479,160 | ---- | M] () -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\dblite.dll

MOD - [2011/10/28 17:19:26 | 001,097,480 | ---- | M] () -- C:\\Program Files (x86)\\Comodo\\Dragon\\avcodec-53.dll

MOD - [2011/10/28 17:19:26 | 000,189,192 | ---- | M] () -- C:\\Program Files (x86)\\Comodo\\Dragon\\avformat-53.dll

MOD - [2011/10/28 17:19:26 | 000,121,608 | ---- | M] () -- C:\\Program Files (x86)\\Comodo\\Dragon\\avutil-51.dll

MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)

SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)

SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)

SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)

SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)

SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)

SRV - [2013/06/21 06:11:32 | 000,078,512 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Hotspot Shield\\bin\\HssTrayService.exe -- (HssTrayService)

SRV - [2013/06/21 05:51:32 | 000,548,136 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Hotspot Shield\\bin\\hsswd.exe -- (HssWd)

SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)

SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)

SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)

SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)

SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)

SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)

SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)

SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)

SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)

SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)

SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)

SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)

DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)

DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)

DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)

DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)

DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)

DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)

DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)

DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)

DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)

DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)

DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)

DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)

DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)

DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)

DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)

DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)

DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)

DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)

DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)

DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)

DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)

DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)

DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)

DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)

DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)

DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)

DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)

DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)

DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)

DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)

DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)

DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)

DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)

DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)

DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)

DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)

DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)

DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE:64bit: - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKLM\\..\\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

IE - HKLM\\..\\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\..\\SearchScopes\\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3080215

IE - HKLM\\..\\SearchScopes\\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: \"URL\" = http://websearch.searchdwebs.info/?l=1&q=\'>http://websearch.searchdwebs.info/?l=1&q={searchTerms}&pid=914&r=2013/07/01&hid=3788853739&lg=EN&cc=PK&unqvl=22


 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache = http://pk.msn.com/?C=PK\'>http://pk.msn.com/?C=PK

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01  [binary data]

IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found

IE - HKCU\\..\\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

IE - HKCU\\..\\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - SOFTWARE\\Classes\\CLSID\\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\\InprocServer32 File not found

IE - HKCU\\..\\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\\..\\SearchScopes\\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: \"URL\" = http://www2.delta-search.com/?q=\'>http://www2.delta-search.com/?q={searchTerms}&affID=121240&tt=gc_&babsrc=SP_ss&mntrId=64A300FFB4E1DD84

IE - HKCU\\..\\SearchScopes\\{7902DE1C-DFB2-426C-A5A1-F87FD90FBEEB}: \"URL\" = http://www.mysearchresults.com/search?c=3513&t=07&q=\'>http://www.mysearchresults.com/search?c=3513&t=07&q={searchTerms}

IE - HKCU\\..\\SearchScopes\\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: \"URL\" = http://us.search.yahoo.com/search?p=\'>http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo

IE - HKCU\\..\\SearchScopes\\{95B7759C-8C7F-4BF1-B163-73684A933233}: \"URL\" = http://isearch.avg.com/search?cid=\'>http://isearch.avg.com/search?cid={A63E2781-B870-42D9-82C8-A06075A35400}&mid=c81a7d7c81e747d0925b369700e81b25-db1903c4b38bb4be805b7f9e83a77cc34f33ade3&lang=en&ds=gm011&pr=sa&d=2012-04-26 23:17:58&v=11.0.0.9&sap=dsp&q={searchTerms}

IE - HKCU\\..\\SearchScopes\\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3080215

IE - HKCU\\..\\SearchScopes\\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: \"URL\" = http://websearch.searchdwebs.info/?l=1&q=\'>http://websearch.searchdwebs.info/?l=1&q={searchTerms}&pid=914&r=2013/07/01&hid=3788853739&lg=EN&cc=PK&unqvl=22

IE - HKCU\\..\\SearchScopes\\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: \"URL\" = http://search.hotspotshield.com/g/results.php?c=s&q=\'>http://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}


IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0

FF - prefs.js..browser.search.order.1: \"WebSearch\"


FF - prefs.js..browser.search.order.1,S: S\", \"WebSearch\"

FF - prefs.js..browser.search.defaultenginename,S: S\", \"WebSearch\"

FF - prefs.js..browser.search.selectedEngine,S: S\", \"WebSearch\"

FF - prefs.js..browser.startup.homepage: \"http://us.yahoo.com?fr=fp-comodo\'>http://us.yahoo.com?fr=fp-comodo\"

FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"


FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"

FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"

 

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]

 

[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions

[2013/07/03 16:10:18 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions

[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}

[2013/07/01 22:41:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\staged

[2013/05/12 03:01:32 | 000,006,505 | ---- | M] () -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\firefox\\profiles\\3ajw8v5r.default\\searchplugins\\babylon.xml

[2013/05/12 03:02:06 | 000,001,294 | ---- | M] () -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\firefox\\profiles\\3ajw8v5r.default\\searchplugins\\delta.xml

[2013/07/01 21:18:32 | 000,000,637 | ---- | M] () -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\firefox\\profiles\\3ajw8v5r.default\\searchplugins\\WebSearch.xml

[2013/07/16 14:24:26 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

[2012/04/26 23:00:15 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\[email protected]

File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

[2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll

[2012/07/10 00:45:35 | 000,003,769 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\avg-secure-search.xml

[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml

[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://us.yahoo.com?fr=fpc-comodo\'>http://us.yahoo.com?fr=fpc-comodo

CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL

CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll

CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll

CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll

CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll

CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\

CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\

CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\

CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\

CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\

CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\

CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\

CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\

CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\

CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\

CHR - Extension: ChatZum.com -  Easy Pictures zoom = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jbpcjmidkkgldeplajgnbpjkfpmpeepb\\1.0.9_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\

CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak

CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found

O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\\Program Files (x86)\\Hotspot Shield\\HssIE\\HssIE_64.dll (AnchorFree Inc.)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found

O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll File not found

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found

O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\\Users\\Faraz\\AppData\\Roaming\\DefaultTab\\DefaultTab\\DefaultTabBHO.dll File not found

O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found

O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found

O2 - BHO: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\\Program Files (x86)\\Hotspot Shield\\HssIE\\HssIE.dll (AnchorFree Inc.)

O2 - BHO: (XBTBPos00 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O3 - HKLM\\..\\Toolbar: (ChatSend Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O3 - HKLM\\..\\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll File not found

O3 - HKLM\\..\\Toolbar: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.

O3 - HKCU\\..\\Toolbar\\WebBrowser: (ChatSend Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O3 - HKCU\\..\\Toolbar\\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll ⠀砀㠀㘀⤀ File not found

O3 - HKCU\\..\\Toolbar\\WebBrowser: (Hotspot Shield Toolbar) - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll (Conduit Ltd.)

O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)

O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)

O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found

O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found

O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()

O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found

O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra Button: ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O9 - Extra \'Tools\' menuitem : ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll File not found

O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)

O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O9 - Extra \'Tools\' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)






O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{D6CF1441-3187-48F4-915E-017B35738A78}: NameServer = 10.0.1.1 192.168.7.2

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)

O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)

O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)

O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 0

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 90 Days ==========

 

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe

[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\Pr

18

My system got infected with viruses 


 


& hijack no producing the log got the error see the attachment 


 


and i have doubts some one had put his script in my system  as he his hacking my system & email ids


 


******************************************************************************************************************************************************************


 


Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 7:33:56 PM, on 24/Jul/13

Platform: Windows 7  (WinNT 6.00.3504)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

 

Running processes:

C:\\Program Files (x86)\\uTorrent\\uTorrent.exe

C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe

C:\\Program Files (x86)\\Nitro\\Pro 8\\NitroPdfThumbnailHelper.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\klwtblfs.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe

C:\\Program Files (x86)\\Trend Micro\\HiJackThis\\HiJackThis.exe

 

R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896\'>http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157\'>http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896\'>http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896\'>http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant = 

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch = 

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

R1 - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings,ProxyOverride = local

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName = 

R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)

R3 - URLSearchHook: (no name) - {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - (no file)

R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll

R3 - URLSearchHook: (no name) - {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - (no file)

R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbhelper.dll (file missing)

F2 - REG:system.ini: UserInit=userinit.exe,

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll (file missing)

O2 - BHO: Conduit Engine  - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll (file missing)

O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll

O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll

O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll

O2 - BHO: HelloWorldBHO - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll (file missing)

O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\\Users\\Faraz\\AppData\\Roaming\\DefaultTab\\DefaultTab\\DefaultTabBHO.dll (file missing)

O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll

O2 - BHO: ssafEE- saVae - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll (file missing)

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll (file missing)

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\\PROGRA~2\\MICROS~3\\Office14\\URLREDIR.DLL

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll (file missing)

O2 - BHO: Hotspot Shield - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll

O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll

O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\\Program Files (x86)\\Hotspot Shield\\HssIE\\HssIE.dll

O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll (file missing)

O3 - Toolbar: Conduit Engine  - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\\Program Files (x86)\\ConduitEngine\\prxConduitEngin.dll (file missing)

O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\\Program Files (x86)\\Hotspot_Shield\\prxtbHot2.dll

O3 - Toolbar: ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll (file missing)

O4 - HKLM\\..\\Run: [AVP] \"C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe\"

O4 - HKCU\\..\\Run: [uTorrent] \"C:\\Program Files (x86)\\uTorrent\\uTorrent.exe\"  /MINIMIZED

O4 - HKCU\\..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot

O4 - HKCU\\..\\Run: [Sidebar] C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun

O4 - HKUS\\S-1-5-19\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /autoRun (User \'LOCAL SERVICE\')

O4 - HKUS\\S-1-5-19\\..\\RunOnce: [mctadmin] C:\\Windows\\System32\\mctadmin.exe (User \'LOCAL SERVICE\')

O4 - HKUS\\S-1-5-20\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /autoRun (User \'NETWORK SERVICE\')

O4 - HKUS\\S-1-5-20\\..\\RunOnce: [mctadmin] C:\\Windows\\System32\\mctadmin.exe (User \'NETWORK SERVICE\')

O4 - HKUS\\S-1-5-18\\..\\Run: [Mobile Partner] C:\\Program Files (x86)\\VIVA WiFi\\VIVA WiFi (User \'SYSTEM\')

O4 - HKUS\\.DEFAULT\\..\\Run: [Mobile Partner] C:\\Program Files (x86)\\VIVA WiFi\\VIVA WiFi (User \'Default user\')

O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm

O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm


O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\Reference Titles\\eddefine.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll

O9 - Extra \'Tools\' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll

O9 - Extra button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll

O9 - Extra button: ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll (file missing)

O9 - Extra \'Tools\' menuitem: ChatSend Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\\Program Files (x86)\\ChatSend Toolbar\\tbunsgE75D.tmp\\tbcore3.dll (file missing)

O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll

O9 - Extra \'Tools\' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll (file missing)

O9 - Extra \'Tools\' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~2\\MICROS~3\\Office12\\REFIEBAR.DLL

O9 - Extra button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics


O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll (file missing)

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\PROGRA~2\\COMMON~1\\Skype\\SKYPE4~1.DLL

O20 - AppInit_DLLs: c:\\windows\\syswow64\\nvinit.dll   C:\\Windows\\SysWOW64\\guard32.dll

O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe

O23 - Service: @%systemroot%\\system32\\CISVC.EXE,-1 (CISVC) - Unknown owner - C:\\Windows\\system32\\CISVC.EXE (file missing)

O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe

O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe

O23 - Service: @%SystemRoot%\\system32\\efssvc.dll,-100 (EFS) - Unknown owner - C:\\Windows\\System32\\lsass.exe (file missing)

O23 - Service: @%systemroot%\\system32\\fxsresm.dll,-118 (Fax) - Unknown owner - C:\\Windows\\system32\\fxssvc.exe (file missing)

O23 - Service: Hotspot Shield Service (hshld) - Unknown owner - C:\\Program Files (x86)\\Hotspot Shield\\bin\\cmw_srv.exe (file missing)

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\\Windows\\System32\\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\\System32\\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe

O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\\Windows\\SysWOW64\\NLSSRV32.EXE

O23 - Service: @%systemroot%\\system32\\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: @%systemroot%\\system32\\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\\Windows\\system32\\locator.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\samsrv.dll,-1 (SamSs) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\\Windows\\System32\\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\\system32\\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\\Windows\\System32\\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\\Windows\\system32\\sppsvc.exe (file missing)

O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

O23 - Service: UDisk Monitor - Unknown owner - C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe

O23 - Service: @%SystemRoot%\\system32\\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\\Windows\\system32\\UI0Detect.exe (file missing)

O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

O23 - Service: @%SystemRoot%\\system32\\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\vds.exe,-100 (vds) - Unknown owner - C:\\Windows\\System32\\vds.exe (file missing)

O23 - Service: VIVA Broadband. OUC (VIVA Broadband. RunOuc) - Unknown owner - C:\\Program Files (x86)\\VIVA Broadband\\UpdateDog\\ouc.exe (file missing)

O23 - Service: @%systemroot%\\system32\\vssvc.exe,-102 (VSS) - Unknown owner - C:\\Windows\\system32\\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\Wat\\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\\Windows\\system32\\Wat\\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\\system32\\wbengine.exe,-104 (wbengine) - Unknown owner - C:\\Windows\\system32\\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\\system32\\wbem\\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\\Windows\\system32\\wbem\\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\\Windows Media Player\\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\\Program Files (x86)\\Windows Media Player\\wmpnetwk.exe (file missing)

 

--

End of file - 13996 bytes

 


19
Tech Clinic / System is running too slow ... viruses are not detected
« on: July 02, 2013, 05:41:41 AM »

OTL Extras logfile created on: 7/2/2013 2:07:24 PM - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Documents and Settings\\Administrator\\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.2180)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

1015.35 Mb Total Physical Memory | 535.04 Mb Available Physical Memory | 52.70% Memory free

2.38 Gb Paging File | 1.97 Gb Available in Paging File | 82.79% Paging File free

Paging file location(s): C:\\pagefile.sys 1524 3048 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\WINDOWS | %ProgramFiles% = C:\\Program Files

Drive C: | 24.99 Gb Total Space | 14.65 Gb Free Space | 58.61% Space Free | Partition Type: FAT32

Drive D: | 25.00 Gb Total Space | 3.98 Gb Free Space | 15.93% Space Free | Partition Type: NTFS

Drive E: | 49.70 Gb Total Space | 2.90 Gb Free Space | 5.84% Space Free | Partition Type: NTFS

Drive F: | 49.34 Gb Total Space | 3.59 Gb Free Space | 7.27% Space Free | Partition Type: NTFS

 

Computer Name: HP-AC60887941E4 | User Name: Administrator | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL \"%1\",%*

.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\<key>\\shell\\[command]\\command]

batfile [open] -- \"%1\" %*

cmdfile [open] -- \"%1\" %*

comfile [open] -- \"%1\" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL \"%1\",%*

exefile [open] -- \"%1\" %*

InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l

piffile [open] -- \"%1\" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- \"%1\"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- \"%1\" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\\system32\\rundll32.exe %SystemRoot%\\system32\\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- \"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe\" --started-from-file --playlist-enqueue \"%1\" ()

Directory [Bridge] -- C:\\Program Files\\Adobe\\Adobe Bridge CS5\\Bridge.exe \"%L\" (Adobe Systems, Inc.)

Directory [find] -- %SystemRoot%\\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- \"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe\" --started-from-file --no-playlist-enqueue \"%1\" ()

Folder [open] -- %SystemRoot%\\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center]

\"FirstRunDisabled\" = 1

\"AntiVirusDisableNotify\" = 1

\"FirewallDisableNotify\" = 1

\"UpdatesDisableNotify\" = 1

\"AntiVirusOverride\" = 0

\"FirewallOverride\" = 0

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\KasperskyAntiVirus]

\"DisableMonitoring\" = 1

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring\\ZoneLabsFirewall]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore]

\"DisableSR\" = 1

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Sr]

\"Start\" = 4

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SrService]

\"Start\" = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\DomainProfile]

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\StandardProfile]

\"EnableFirewall\" = 1

\"DoNotAllowExceptions\" = 0

\"DisableNotifications\" = 0

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\StandardProfile\\GloballyOpenPorts\\List]

\"1900:UDP\" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

\"2869:TCP\" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\DomainProfile\\AuthorizedApplications\\List]

\"%windir%\\system32\\sessmgr.exe\" = %windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

\"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe\" = C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe:*:Enabled:McAfee Framework Service

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\StandardProfile\\AuthorizedApplications\\List]

\"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe\" = C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe:*:Enabled:McAfee Framework Service

\"C:\\Program Files\\Internet Download Manager\\IDMan.exe\" = C:\\Program Files\\Internet Download Manager\\IDMan.exe:*:Enabled:Internet Download Manager (IDM) -- (Tonec Inc.)

\"C:\\Documents and Settings\\Administrator\\Application Data\\uTorrent\\uTorrent.exe\" = C:\\Documents and Settings\\Administrator\\Application Data\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent Inc.)

\"C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe\" = C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe:*:Disabled:Facebook Video Calling Plugin -- (Skype Limited)

\"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE\" = C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Disabled:Microsoft Office Groove -- (Microsoft Corporation)

\"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE\" = C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Disabled:Microsoft Office OneNote -- (Microsoft Corporation)

\"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE\" = C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Disabled:Microsoft Office Outlook -- (Microsoft Corporation)

\"C:\\WINDOWS\\system32\\sessmgr.exe\" = C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall]

\"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}\" = Microsoft_VC90_ATL_x86

\"{08D2E121-7F6A-43EB-97FD-629B44903403}\" = Microsoft_VC90_CRT_x86

\"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}\" = Adobe Community Help

\"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}\" = Microsoft_VC80_ATL_x86

\"{15FEDA5F-141C-4127-8D7E-B962D1742728}\" = Adobe Photoshop CS5

\"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}\" = WebFldrs XP

\"{45A66726-69BC-466B-A7A4-12FCBA4883D7}\" = HiJackThis

\"{560985FB-4B76-4121-9189-7A2CDC7886D6}\" = Kaspersky Anti-Virus 2013

\"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}\" = Microsoft_VC90_MFC_x86

\"{8A708DD8-A5E6-11D4-A706-000629E95E20}\" = Intel(R) Graphics Media Accelerator Driver

\"{90120000-0010-0409-0000-0000000FF1CE}\" = Microsoft Software Update for Web Folders  (English) 12

\"{90120000-0015-0409-0000-0000000FF1CE}\" = Microsoft Office Access MUI (English) 2007

\"{90120000-0016-0409-0000-0000000FF1CE}\" = Microsoft Office Excel MUI (English) 2007

\"{90120000-0018-0409-0000-0000000FF1CE}\" = Microsoft Office PowerPoint MUI (English) 2007

\"{90120000-0019-0409-0000-0000000FF1CE}\" = Microsoft Office Publisher MUI (English) 2007

\"{90120000-001A-0409-0000-0000000FF1CE}\" = Microsoft Office Outlook MUI (English) 2007

\"{90120000-001B-0409-0000-0000000FF1CE}\" = Microsoft Office Word MUI (English) 2007

\"{90120000-001F-0409-0000-0000000FF1CE}\" = Microsoft Office Proof (English) 2007

\"{90120000-001F-040C-0000-0000000FF1CE}\" = Microsoft Office Proof (French) 2007

\"{90120000-001F-0C0A-0000-0000000FF1CE}\" = Microsoft Office Proof (Spanish) 2007

\"{90120000-002C-0409-0000-0000000FF1CE}\" = Microsoft Office Proofing (English) 2007

\"{90120000-0030-0000-0000-0000000FF1CE}\" = Microsoft Office Enterprise 2007

\"{90120000-0044-0409-0000-0000000FF1CE}\" = Microsoft Office InfoPath MUI (English) 2007

\"{90120000-006E-0409-0000-0000000FF1CE}\" = Microsoft Office Shared MUI (English) 2007

\"{90120000-00A1-0409-0000-0000000FF1CE}\" = Microsoft Office OneNote MUI (English) 2007

\"{90120000-00BA-0409-0000-0000000FF1CE}\" = Microsoft Office Groove MUI (English) 2007

\"{90120000-0114-0409-0000-0000000FF1CE}\" = Microsoft Office Groove Setup Metadata MUI (English) 2007

\"{90120000-0115-0409-0000-0000000FF1CE}\" = Microsoft Office Shared Setup Metadata MUI (English) 2007

\"{90120000-0117-0409-0000-0000000FF1CE}\" = Microsoft Office Access Setup Metadata MUI (English) 2007

\"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}\" = Microsoft_VC80_CRT_x86

\"{A2BCA9F1-566C-4805-97D1-7FDC93386723}\" = Adobe AIR

\"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}\" = PDF Settings CS5

\"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}\" = Facebook Video Calling 1.2.0.287

\"{D1A19B02-817E-4296-A45B-07853FD74D57}\" = Microsoft_VC80_MFC_x86

\"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}\" = Microsoft_VC80_MFCLOC_x86

\"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}\" = Adobe Media Player

\"{F0C2AD51-9F09-4B75-82EE-74DA80F708D8}\" = Nitro PDF Professional

\"6AF27CD11B617BED2F81E26729D33AF8338D453C\" = Windows Driver Package - Hewlett-Packard hp scanjet 3600 series (04/26/2007 9.0.0.0)

\"Adobe AIR\" = Adobe AIR

\"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1\" = Adobe Community Help

\"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1\" = Adobe Media Player

\"ENTERPRISE\" = Microsoft Office Enterprise 2007

\"Foxit Reader\" = Foxit Reader

\"GOM Player\" = GOM Player

\"InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}\" = Kaspersky Anti-Virus 2013

\"Internet Download Manager\" = Internet Download Manager

\"KLiteCodecPack_is1\" = K-Lite Mega Codec Pack 1.53

\"USB Disk Security_is1\" = USB Disk Security

\"uTorrent\" = µTorrent

\"VLC media player\" = VLC media player 1.1.11

\"WinRAR archiver\" = WinRAR archiver

\"ZTEWireless-101_is1\" = EVDO BROADBAND PTCL

 

========== HKEY_CURRENT_USER Uninstall List ==========

 

[HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall]

\"Google Chrome\" = Google Chrome

 

========== Last 20 Event Log Errors ==========

 

[ Application Events ]

Error - 6/29/2013 3:04:08 AM | Computer Name = HP-AC60887941E4 | Source = Google Update | ID = 20

Description =

 

Error - 6/29/2013 3:08:01 AM | Computer Name = HP-AC60887941E4 | Source = LoadPerf | ID = 3011

Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)

 failed. The  Error code is the first DWORD in Data section.

 

Error - 6/29/2013 3:08:04 AM | Computer Name = HP-AC60887941E4 | Source = LoadPerf | ID = 3006

Description = Unable to read the performance counter strings of the 009 language

 ID.  The Win32 status returned by the call is the first DWORD in Data section.

 

Error - 6/29/2013 3:11:33 AM | Computer Name = HP-AC60887941E4 | Source = Google Update | ID = 20

Description =

 

Error - 6/29/2013 5:07:03 AM | Computer Name = HP-AC60887941E4 | Source = Google Update | ID = 20

Description =

 

Error - 6/29/2013 5:10:43 AM | Computer Name = HP-AC60887941E4 | Source = LoadPerf | ID = 3011

Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)

 failed. The  Error code is the first DWORD in Data section.

 

Error - 6/29/2013 5:10:46 AM | Computer Name = HP-AC60887941E4 | Source = LoadPerf | ID = 3006

Description = Unable to read the performance counter strings of the 009 language

 ID.  The Win32 status returned by the call is the first DWORD in Data section.

 

Error - 6/29/2013 5:11:04 AM | Computer Name = HP-AC60887941E4 | Source = LoadPerf | ID = 3011

Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)

 failed. The  Error code is the first DWORD in Data section.

 

Error - 6/29/2013 5:11:07 AM | Computer Name = HP-AC60887941E4 | Source = LoadPerf | ID = 3006

Description = Unable to read the performance counter strings of the 009 language

 ID.  The Win32 status returned by the call is the first DWORD in Data section.

 

Error - 6/29/2013 7:03:32 AM | Computer Name = HP-AC60887941E4 | Source = Google Update | ID = 20

Description =

 

[ System Events ]

Error - 7/1/2013 9:06:37 AM | Computer Name = HP-AC60887941E4 | Source = Service Control Manager | ID = 7034

Description = The McAfee Validation Trust Protection Service service terminated

unexpectedly.  It has done this 1 time(s).

 

Error - 7/1/2013 9:08:10 AM | Computer Name = HP-AC60887941E4 | Source = Service Control Manager | ID = 7031

Description = The McAfee McShield service terminated unexpectedly.  It has done

this 1 time(s).  The following corrective action will be taken in 5000 milliseconds:

 Restart the service.

 

Error - 7/1/2013 9:15:54 AM | Computer Name = HP-AC60887941E4 | Source = Service Control Manager | ID = 7032

Description = The Service Control Manager tried to take a corrective action (Restart

 the service) after the unexpected termination of the Windows Management Instrumentation

 service, but this action failed with the following error:   %%1056

 

Error - 7/1/2013 9:19:14 AM | Computer Name = HP-AC60887941E4 | Source = Dhcp | ID = 1002

Description = The IP address lease 192.168.100.114 for the Network Card with network

 address 0015604FC4CD has been  denied by the DHCP server 0.0.0.0 (The DHCP Server

 sent a DHCPNACK message).

 

Error - 7/1/2013 9:20:04 AM | Computer Name = HP-AC60887941E4 | Source = Service Control Manager | ID = 7034

Description = The McAfee Framework Service service terminated unexpectedly.  It

has done this 1 time(s).

 

Error - 7/1/2013 9:23:26 AM | Computer Name = HP-AC60887941E4 | Source = Service Control Manager | ID = 7031

Description = The McAfee McShield service terminated unexpectedly.  It has done

this 1 time(s).  The following corrective action will be taken in 5000 milliseconds:

 Restart the service.

 

Error - 7/1/2013 9:26:44 AM | Computer Name = HP-AC60887941E4 | Source = Service Control Manager | ID = 7034

Description = The StarWind iSCSI Service service terminated unexpectedly.  It has

 done this 1 time(s).

 

Error - 7/1/2013 9:32:56 AM | Computer Name = HP-AC60887941E4 | Source = Service Control Manager | ID = 7034

Description = The UDisk Monitor service terminated unexpectedly.  It has done this

 1 time(s).

 

Error - 7/1/2013 11:38:49 AM | Computer Name = HP-AC60887941E4 | Source = LDMS | ID = 16780239

Description = The Logical Disk Manager Service failed while registering for device

 handle notifications on device \\\\?\\usbstor#cdrom&ven_zte&prod_usb_storage_fff1&rev_2.31#000000000002&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}.

 Win32 Error: 2.

 

Error - 7/1/2013 2:02:50 PM | Computer Name = HP-AC60887941E4 | Source = PSched | ID = 14107

Description = QoS [Adapter NDISWANIP]:  The Packet Scheduler could not initialize

the virtual miniport with NDIS.

 

 

< End of report >

 


 


*******************************************************************************************************************************************************


OTL logfile created on: 7/2/2013 2:07:24 PM - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Documents and Settings\\Administrator\\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.2180)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

1015.35 Mb Total Physical Memory | 535.04 Mb Available Physical Memory | 52.70% Memory free

2.38 Gb Paging File | 1.97 Gb Available in Paging File | 82.79% Paging File free

Paging file location(s): C:\\pagefile.sys 1524 3048 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\WINDOWS | %ProgramFiles% = C:\\Program Files

Drive C: | 24.99 Gb Total Space | 14.65 Gb Free Space | 58.61% Space Free | Partition Type: FAT32

Drive D: | 25.00 Gb Total Space | 3.98 Gb Free Space | 15.93% Space Free | Partition Type: NTFS

Drive E: | 49.70 Gb Total Space | 2.90 Gb Free Space | 5.84% Space Free | Partition Type: NTFS

Drive F: | 49.34 Gb Total Space | 3.59 Gb Free Space | 7.27% Space Free | Partition Type: NTFS

 

Computer Name: HP-AC60887941E4 | User Name: Administrator | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2013/07/02 13:25:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Documents and Settings\\Administrator\\Desktop\\OTL.exe

PRC - [2013/06/17 09:41:20 | 001,045,072 | ---- | M] (BitTorrent Inc.) -- C:\\Documents and Settings\\Administrator\\Application Data\\uTorrent\\uTorrent.exe

PRC - [2013/05/10 07:53:34 | 003,487,128 | ---- | M] (Tonec Inc.) -- C:\\Program Files\\Internet Download Manager\\IDMan.exe

PRC - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) -- C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe

PRC - [2011/01/29 15:52:10 | 000,623,520 | ---- | M] (Zbshareware Lab) -- C:\\Program Files\\USB Disk Security\\USBGuard.exe

PRC - [2010/05/25 05:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\\Program Files\\Internet Download Manager\\IEMonitor.exe

PRC - [2009/08/25 09:15:12 | 000,262,144 | ---- | M] () -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk.exe

PRC - [2004/08/04 00:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\\WINDOWS\\explorer.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2013/01/14 14:41:16 | 001,310,136 | ---- | M] () -- C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\kpcengine.2.2.dll

MOD - [2012/08/17 21:38:56 | 000,479,160 | ---- | M] () -- C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\dblite.dll

MOD - [2009/08/25 09:15:12 | 000,262,144 | ---- | M] () -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk.exe

MOD - [2004/01/22 18:36:28 | 000,120,832 | ---- | M] () -- C:\\Program Files\\WinRAR\\RarExt.dll

 

 

========== Services (SafeList) ==========

 

SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)

SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe -- (SwitchBoard)

SRV - [2009/08/25 09:15:12 | 000,262,144 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk.exe -- (UDisk Monitor)

SRV - [2007/02/21 17:26:40 | 000,151,552 | ---- | M] () [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\BCL Technologies\\easyPDF 5\\bepldr.exe -- (bepldr)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)

DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)

DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)

DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)

DRV - File not found [Kernel | System | Stopped] --  -- (Changer)

DRV - [2013/02/13 14:26:02 | 000,033,512 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\taphss.sys -- (taphss)

DRV - [2013/01/14 14:41:12 | 000,586,584 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\\WINDOWS\\system32\\drivers\\klif.sys -- (KLIF)

DRV - [2013/01/14 14:41:12 | 000,043,608 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\\WINDOWS\\system32\\drivers\\kltdi.sys -- (kltdi)

DRV - [2013/01/14 14:41:12 | 000,024,920 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\klmouflt.sys -- (klmouflt)

DRV - [2013/01/14 14:41:12 | 000,024,408 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\klkbdflt.sys -- (klkbdflt)

DRV - [2012/08/13 16:49:44 | 000,144,344 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\\WINDOWS\\system32\\drivers\\kneps.sys -- (kneps)

DRV - [2012/06/27 14:09:08 | 000,035,672 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\klim5.sys -- (klim5)

DRV - [2012/06/19 17:28:12 | 000,136,024 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\WINDOWS\\system32\\drivers\\kl1.sys -- (kl1)

DRV - [2012/04/23 04:26:26 | 000,108,448 | ---- | M] (Tonec Inc.) [Kernel | System | Running] -- C:\\WINDOWS\\system32\\drivers\\idmtdi.sys -- (IDMTDI)

DRV - [2009/07/21 16:04:16 | 000,104,704 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)

DRV - [2008/12/09 21:56:18 | 000,187,392 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\b57xp32.sys -- (b57w2k)

DRV - [2005/01/07 17:07:16 | 000,145,920 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\Hdaudio.sys -- (HdAudAddService)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = %SystemRoot%\\system32\\blank.htm

IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

 

 

========== FireFox ==========

 

FF - HKLM\\Software\\MozillaPlugins\\@real.com/nppl3260;version=6.0.11.2321: C:\\Program Files\\K-Lite Codec Pack\\Real\\browser\\plugins\\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@real.com/nprpjplug;version=6.0.12.1483: C:\\Program Files\\K-Lite Codec Pack\\Real\\browser\\plugins\\nprpjplug.dll (RealNetworks, Inc.)

FF - HKLM\\Software\\MozillaPlugins\\@real.com/nsJSRealPlayerPlugin;version=:  File not found

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Update\\1.3.21.145\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Update\\1.3.21.145\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/01 23:02:14 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/01 23:02:14 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\[email protected] [2013/07/01 23:02:14 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\[email protected]: C:\\Documents and Settings\\Administrator\\Application Data\\IDM\\idmmzcc5 [2013/05/10 07:49:06 | 000,000,000 | ---D | M]

 

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://www.google.com/\'>http://www.google.com/

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\27.0.1453.116\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\27.0.1453.116\\pdf.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\27.0.1453.116\\gcswf32.dll

CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\\Program Files\\Windows Media Player\\npdsplay.dll

CHR - plugin: Microsoft\\u00AE DRM (Enabled) = C:\\Program Files\\Windows Media Player\\npwmsdrm.dll

CHR - plugin: Microsoft\\u00AE DRM (Enabled) = C:\\Program Files\\Windows Media Player\\npdrmv2.dll

CHR - Extension: Kaspersky URL Advisor = C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\

CHR - Extension: Content Blocker = C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\

CHR - Extension: Virtual Keyboard = C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4190_0\\

CHR - Extension: Gmail = C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\

 

O1 HOSTS File: ([2001/08/23 14:00:00 | 000,000,734 | ---- | M]) - C:\\WINDOWS\\system32\\drivers\\etc\\hosts

O1 - Hosts: 127.0.0.1       localhost

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Program Files\\Internet Download Manager\\IDMIECC.dll (Internet Download Manager, Tonec Inc.)

O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O4 - HKLM..\\Run: [AVP] C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)

O4 - HKLM..\\Run: [USB Security] C:\\Program Files\\USB Disk Security\\USBGuard.exe (Zbshareware Lab)

O4 - HKCU..\\Run: [IDMan] C:\\Program Files\\Internet Download Manager\\IDMan.exe (Tonec Inc.)

O4 - HKCU..\\Run: [uTorrent] C:\\Documents and Settings\\Administrator\\Application Data\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60

O7 - HKCU\\Software\\Policies\\Microsoft\\Internet Explorer\\Control Panel present

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 36

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveAutoRun = FF FF FF FF  [binary data]

O8 - Extra context menu item: Download all links with IDM - C:\\Program Files\\Internet Download Manager\\IEGetAll.htm ()

O8 - Extra context menu item: Download with IDM - C:\\Program Files\\Internet Download Manager\\IEExt.htm ()

O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{03E48A69-FD25-4691-9BDC-99CDA7FFF656}: DhcpNameServer = 192.168.100.254

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\\WINDOWS\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\\WINDOWS\\system32\\userinit.exe) - C:\\WINDOWS\\system32\\userinit.exe (Microsoft Corporation)

O20 - Winlogon\\Notify\\klogon: DllName - (C:\\WINDOWS\\system32\\klogon.dll) - C:\\WINDOWS\\system32\\klogon.dll (Kaspersky Lab ZAO)

O24 - Desktop WallPaper: C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Microsoft\\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Microsoft\\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 0

O32 - AutoRun File - [2013/03/18 07:27:18 | 000,000,000 | ---- | M] () - C:\\AUTOEXEC.BAT -- [ FAT32 ]

O32 - AutoRun File - [2013/07/01 16:18:14 | 000,000,000 | ---D | M] - C:\\autorun.inf -- [ FAT32 ]

O32 - AutoRun File - [2013/07/01 16:18:13 | 000,000,000 | ---D | M] - D:\\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2013/07/01 16:18:13 | 000,000,000 | ---D | M] - E:\\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2013/07/01 16:18:14 | 000,000,000 | ---D | M] - F:\\autorun.inf -- [ NTFS ]

O33 - MountPoints2\\{05c568a4-8f9b-11e2-9fba-806d6172696f}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{05c568a4-8f9b-11e2-9fba-806d6172696f}\\Shell\\AutoRun - \"\" = Auto&Play

O33 - MountPoints2\\{05c568a4-8f9b-11e2-9fba-806d6172696f}\\Shell\\AutoRun\\command - \"\" = G:\\setup.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2095/07/22 18:41:56 | 000,000,000 | -HSD | C] -- C:\\FOUND.014

[2033/09/30 21:36:46 | 000,000,000 | -HSD | C] -- C:\\FOUND.018

[2013/07/02 14:07:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Documents and Settings\\Administrator\\Desktop\\OTL.exe

[2013/07/02 12:16:27 | 000,000,000 | RH-D | C] -- C:\\Documents and Settings\\Administrator\\Recent

[2013/07/02 12:05:06 | 000,000,000 | -HSD | C] -- C:\\FOUND.028

[2013/07/01 23:03:12 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013

[2013/07/01 23:02:12 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab

[2013/07/01 23:02:00 | 000,586,584 | ---- | C] (Kaspersky Lab) -- C:\\WINDOWS\\System32\\drivers\\klif.sys

[2013/07/01 23:02:00 | 000,074,072 | ---- | C] (Kaspersky Lab) -- C:\\WINDOWS\\System32\\drivers\\klflt.sys

[2013/07/01 22:56:14 | 000,000,000 | -HSD | C] -- C:\\FOUND.027

[2013/07/01 20:47:00 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\StarApp

[2013/07/01 20:46:42 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\InstallMate

[2013/07/01 20:18:36 | 000,000,000 | ---D | C] -- C:\\Program Files\\Trend Micro

[2013/07/01 20:18:36 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\HiJackThis

[2013/07/01 18:53:20 | 000,000,000 | -HSD | C] -- C:\\FOUND.026

[2013/07/01 18:28:57 | 000,000,000 | ---D | C] -- C:\\Avenger

[2013/07/01 18:20:49 | 000,000,000 | ---D | C] -- C:\\WINDOWS\\pss

[2013/07/01 16:43:01 | 000,000,000 | ---D | C] -- C:\\Program Files\\Kaspersky Lab

[2013/07/01 16:42:16 | 000,000,000 | ---D | C] -- C:\\KAV

[2013/07/01 16:41:08 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\Windows Genuine Advantage

[2013/07/01 16:18:13 | 000,000,000 | ---D | C] -- C:\\autorun.inf

[2013/07/01 16:06:14 | 000,000,000 | -HSD | C] -- C:\\FOUND.025

[2013/06/30 11:09:54 | 000,000,000 | -HSD | C] -- C:\\FOUND.024

[2013/06/29 14:06:18 | 000,000,000 | -HSD | C] -- C:\\FOUND.023

[2013/06/28 20:46:53 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Administrator\\Application Data\\Adobe Mini Bridge CS5

[2013/06/28 20:46:52 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Administrator\\Application Data\\StageManager.BD092818F67280F4B42B04877600987F0111B594.1

[2013/06/28 06:49:28 | 000,000,000 | -HSD | C] -- C:\\FOUND.022

[2013/06/27 18:50:37 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\regid.1986-12.com.adobe

[2013/06/27 18:45:29 | 000,000,000 | ---D | C] -- C:\\Program Files\\Adobe Media Player

[2013/06/27 18:45:29 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Adobe

[2013/06/27 18:43:30 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Adobe AIR

[2013/06/27 18:39:35 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\Adobe

[2013/06/27 18:39:28 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Adobe

[2013/06/27 18:39:01 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Adobe

[2013/06/27 10:44:39 | 000,286,720 | ---- | C] (Indigo Rose Corporation) -- C:\\WINDOWS\\iun503.exe

[2013/06/27 10:40:35 | 000,000,000 | ---D | C] -- C:\\Program Files\\Alcohol Soft

[2013/06/27 10:07:04 | 000,000,000 | -HSD | C] -- C:\\FOUND.021

[2013/06/24 23:00:58 | 000,000,000 | -HSD | C] -- C:\\FOUND.020

[2013/06/23 18:52:32 | 000,000,000 | -HSD | C] -- C:\\FOUND.019

[2013/06/22 11:14:10 | 000,000,000 | -HSD | C] -- C:\\FOUND.017

[2013/06/22 06:27:38 | 000,000,000 | -HSD | C] -- C:\\FOUND.016

[2013/06/17 10:33:46 | 000,000,000 | ---D | C] -- C:\\WINDOWS\\System32\\appmgmt

[2013/06/17 10:09:48 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\LocalService\\Application Data\\Hotspot Shield

[2013/06/17 09:24:39 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Administrator\\Application Data\\uTorrent

[2013/06/17 08:28:24 | 000,000,000 | -HSD | C] -- C:\\FOUND.015

[2013/06/16 12:40:09 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Administrator\\Application Data\\Nitro PDF

[2013/06/16 11:41:48 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\BCL Technologies

[2013/06/16 11:41:34 | 000,000,000 | ---D | C] -- C:\\Program Files\\Nitro PDF

[2013/06/16 11:41:34 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Application Data\\Nitro PDF

[2013/06/16 11:40:46 | 000,000,000 | ---D | C] -- C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Downloaded Installations

[2013/06/13 09:11:55 | 000,000,000 | ---D | C] -- C:\\Program Files\\DIFX

[2013/06/09 04:03:26 | 000,000,000 | -HSD | C] -- C:\\FOUND.013

[2013/06/08 06:19:14 | 000,000,000 | -HSD | C] -- C:\\FOUND.012

[3 C:\\WINDOWS\\*.tmp files -> C:\\WINDOWS\\*.tmp -> ]

[2 C:\\WINDOWS\\System32\\*.tmp files -> C:\\WINDOWS\\System32\\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2013/07/02 14:04:02 | 000,002,048 | --S- | M] () -- C:\\WINDOWS\\bootstat.dat

[2013/07/02 14:04:00 | 1064,747,008 | -HS- | M] () -- C:\\hiberfil.sys

[2013/07/02 13:25:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Documents and Settings\\Administrator\\Desktop\\OTL.exe

[2013/07/02 00:21:08 | 000,000,542 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Desktop\\Four Star.lnk

[2013/07/02 00:17:12 | 000,000,211 | -HS- | M] () -- C:\\boot.ini

[2013/07/01 23:42:00 | 000,002,463 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\HiJackThis.lnk

[2013/07/01 23:02:58 | 000,000,755 | ---- | M] () -- C:\\Documents and Settings\\All Users\\Desktop\\Kaspersky Anti-Virus 2013.lnk

[2013/07/01 23:01:26 | 000,002,251 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\Google Chrome.lnk

[2013/07/01 20:51:48 | 000,001,008 | ---- | M] () -- C:\\WINDOWS\\tasks\\FacebookUpdateTaskUserS-1-5-21-776561741-725345543-708340629-500Core.job

[2013/07/01 18:14:18 | 000,017,408 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2013/07/01 16:41:10 | 000,002,206 | ---- | M] () -- C:\\WINDOWS\\System32\\wpa.dbl

[2013/07/01 00:02:06 | 000,389,376 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\My Documents\\managers-officers-coordinators-accountants-healthcare-staff-admin-staff-engineers-and-lot-of-other-important-staff-jobs-in-public-sector-organization-6-207042.jpg

[2013/06/30 09:17:34 | 000,093,367 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\d.jpg

[2013/06/30 02:00:04 | 000,000,358 | ---- | M] () -- C:\\WINDOWS\\tasks\\AdobeAAMUpdater-1.0-HP-AC60887941E4-Administrator.job

[2013/06/29 05:14:20 | 000,286,720 | ---- | M] (Indigo Rose Corporation) -- C:\\WINDOWS\\iun503.exe

[2013/06/28 07:23:30 | 000,017,769 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\c.jpg

[2013/06/27 21:19:08 | 003,568,328 | ---- | M] () -- C:\\WINDOWS\\System32\\FNTCACHE.DAT

[2013/06/22 19:36:52 | 000,002,269 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\Google Chrome.lnk

[2013/06/21 09:21:50 | 000,049,652 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\Brasil.jpg

[2013/06/16 01:25:02 | 000,035,833 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\b.jpg

[2013/06/15 23:34:16 | 003,933,337 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\[SongsPK.info] Table No 21 - 05 - Man Mera (Remix).mp3

[2013/06/15 23:27:34 | 005,286,589 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\[SongsPK.info] Aashiqui 2 - 01 - Tum Hi Ho_2.mp3

[2013/06/15 05:20:00 | 004,847,451 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\[Songs.PK] 02 - Rani Tu Mein Raja.mp3

[2013/06/15 04:38:30 | 014,930,814 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\Desktop\\Balma Full Song (Khiladi 786) ,Akshay Kumar _ Tune.pk.flv

[2013/06/13 09:03:20 | 000,007,287 | ---- | M] () -- C:\\Documents and Settings\\Administrator\\My Documents\\shez.JPG

[3 C:\\WINDOWS\\*.tmp files -> C:\\WINDOWS\\*.tmp -> ]

[2 C:\\WINDOWS\\System32\\*.tmp files -> C:\\WINDOWS\\System32\\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2013/07/02 00:57:34 | 1064,747,008 | -HS- | C] () -- C:\\hiberfil.sys

[2013/07/02 00:21:06 | 000,000,542 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Desktop\\Four Star.lnk

[2013/07/01 23:03:12 | 000,000,755 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Desktop\\Kaspersky Anti-Virus 2013.lnk

[2013/07/01 20:18:36 | 000,002,463 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Desktop\\HiJackThis.lnk

[2013/07/01 16:13:23 | 000,033,585 | -HS- | C] () -- C:\\Documents and Settings\\Administrator\\Application Data\\ofbdgevejc..vbs

[2013/07/01 00:02:07 | 000,389,376 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\My Documents\\managers-officers-coordinators-accountants-healthcare-staff-admin-staff-engineers-and-lot-of-other-important-staff-jobs-in-public-sector-organization-6-207042.jpg

[2013/06/30 09:17:40 | 000,093,367 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Desktop\\d.jpg

[2013/06/28 20:14:30 | 000,000,358 | ---- | C] () -- C:\\WINDOWS\\tasks\\AdobeAAMUpdater-1.0-HP-AC60887941E4-Administrator.job

[2013/06/28 07:23:36 | 000,017,769 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Desktop\\c.jpg

[2013/06/27 18:48:32 | 000,000,761 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Adobe Photoshop CS5.lnk

[2013/06/27 18:47:36 | 000,000,723 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Adobe Bridge CS5.lnk

[2013/06/27 18:47:08 | 000,000,816 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Adobe Device Central CS5.lnk

[2013/06/27 18:44:49 | 000,000,907 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Adobe Extension Manager CS5.lnk

[2013/06/27 18:44:37 | 000,001,051 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Adobe ExtendScript Toolkit CS5.lnk

[2013/06/27 18:43:33 | 000,000,635 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Adobe Help.lnk

[2013/06/21 09:22:03 | 000,049,652 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Desktop\\Brasil.jpg

[2013/06/16 11:41:36 | 000,001,671 | ---- | C] () -- C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Nitro PDF Professional.lnk

[2013/06/16 01:25:06 | 000,035,833 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Desktop\\b.jpg

[2013/06/15 23:33:12 | 003,933,337 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Desktop\\[SongsPK.info] Table No 21 - 05 - Man Mera (Remix).mp3

[2013/06/15 23:26:12 | 005,286,589 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Desktop\\[SongsPK.info] Aashiqui 2 - 01 - Tum Hi Ho_2.mp3

[2013/06/15 05:11:43 | 004,847,451 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Desktop\\[Songs.PK] 02 - Rani Tu Mein Raja.mp3

[2013/06/15 04:18:49 | 014,930,814 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Desktop\\Balma Full Song (Khiladi 786) ,Akshay Kumar _ Tune.pk.flv

[2013/06/13 09:03:18 | 000,007,287 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\My Documents\\shez.JPG

[2013/05/17 12:50:53 | 000,157,696 | ---- | C] () -- C:\\WINDOWS\\System32\\unrar.dll

[2013/05/17 12:50:49 | 000,568,850 | ---- | C] () -- C:\\WINDOWS\\System32\\x264vfw.dll

[2013/05/17 12:50:48 | 000,856,064 | ---- | C] () -- C:\\WINDOWS\\System32\\xvidcore.dll

[2013/05/17 12:50:48 | 000,217,088 | ---- | C] () -- C:\\WINDOWS\\System32\\xvidvfw.dll

[2013/05/17 12:50:46 | 003,596,288 | ---- | C] () -- C:\\WINDOWS\\System32\\qt-dx331.dll

[2013/05/17 12:50:44 | 000,005,120 | ---- | C] () -- C:\\WINDOWS\\System32\\ff_vfw.dll

[2013/05/10 05:33:25 | 000,017,408 | ---- | C] () -- C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2013/03/18 08:30:39 | 000,000,376 | ---- | C] () -- C:\\WINDOWS\\ODBC.INI

[2013/03/18 07:38:59 | 000,147,456 | ---- | C] () -- C:\\WINDOWS\\System32\\igfxCoIn_v4926.dll

[2013/03/18 07:30:57 | 000,002,048 | --S- | C] () -- C:\\WINDOWS\\bootstat.dat

[2013/03/18 07:24:15 | 000,021,640 | ---- | C] () -- C:\\WINDOWS\\System32\\emptyregdb.dat

[2013/03/18 07:18:34 | 000,004,161 | ---- | C] () -- C:\\WINDOWS\\ODBCINST.INI

[2013/03/18 07:17:23 | 003,568,328 | ---- | C] () -- C:\\WINDOWS\\System32\\FNTCACHE.DAT

 

========== ZeroAccess Check ==========

 

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32]

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

\"\" = %SystemRoot%\\system32\\shdocvw.dll -- [2004/08/04 00:56:46 | 001,483,264 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Apartment

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32]

\"\" = C:\\WINDOWS\\system32\\wbem\\fastprox.dll -- [2004/08/03 16:56:44 | 000,472,064 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Free

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32]

\"\" = C:\\WINDOWS\\system32\\wbem\\wbemess.dll -- [2004/08/03 16:56:48 | 000,273,920 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Both


< End of report >



20
Tech Clinic / System is running too slow ... viruses are not detected
« on: July 01, 2013, 10:21:09 AM »
here is log file of Hijack this

 

****************************************************************************************************************************

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 8:18:47 PM, on 7/1/2013

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\\WINDOWS\\System32\\smss.exe

C:\\WINDOWS\\system32\\winlogon.exe

C:\\WINDOWS\\system32\\services.exe

C:\\WINDOWS\\system32\\lsass.exe

C:\\WINDOWS\\system32\\svchost.exe

C:\\WINDOWS\\System32\\svchost.exe

C:\\WINDOWS\\system32\\spoolsv.exe

C:\\WINDOWS\\system32\\svchost.exe

C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk.exe

C:\\WINDOWS\\Explorer.EXE

C:\\Program Files\\USB Disk Security\\USBGuard.exe

C:\\Program Files\\Internet Download Manager\\IDMan.exe

C:\\Documents and Settings\\Administrator\\Application Data\\uTorrent\\uTorrent.exe

C:\\Program Files\\Internet Download Manager\\IEMonitor.exe

C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\App.exe

C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe

C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe

C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe

C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe

C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe

C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe

C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe

C:\\WINDOWS\\system32\\msiexec.exe

C:\\Program Files\\Trend Micro\\HiJackThis\\HiJackThis.exe

 

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Program Files\\Internet Download Manager\\IDMIECC.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\\PROGRA~1\\MICROS~2\\Office12\\GRA8E1~1.DLL

O4 - HKLM\\..\\Run: [USB Security] C:\\Program Files\\USB Disk Security\\USBGuard.exe

O4 - HKLM\\..\\Run: [MSConfig] C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto

O4 - HKCU\\..\\Run: [IDMan] C:\\Program Files\\Internet Download Manager\\IDMan.exe /onboot

O4 - HKCU\\..\\Run: [uTorrent] \"C:\\Documents and Settings\\Administrator\\Application Data\\uTorrent\\uTorrent.exe\"  /MINIMIZED

O8 - Extra context menu item: Download all links with IDM - C:\\Program Files\\Internet Download Manager\\IEGetAll.htm

O8 - Extra context menu item: Download with IDM - C:\\Program Files\\Internet Download Manager\\IEExt.htm


O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~2\\Office12\\ONBttnIE.dll

O9 - Extra \'Tools\' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~2\\Office12\\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~1\\MICROS~2\\Office12\\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe

O9 - Extra \'Tools\' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{B12C7F3A-70CB-48D6-939A-FA365C28C208}: NameServer = 119.159.255.36 182.176.32.29

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\\PROGRA~1\\MICROS~2\\Office12\\GR99D3~1.DLL

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\\WINDOWS\\system32\\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\\WINDOWS\\system32\\browseui.dll

O23 - Service: BCL easyPDF SDK 5 Loader (bepldr) - Unknown owner - C:\\Program Files\\Common Files\\BCL Technologies\\easyPDF 5\\bepldr.exe

O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\\Program Files\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe

O23 - Service: UDisk Monitor - Unknown owner - C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk.exe

 

--

End of file - 4261 bytes

 


Pages: [1] 2 3 4