OTL logfile created on: 25/Jul/13 5:45:48 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\\Users\\Faraz\\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MMM/yy
3.91 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 67.97% Memory free
7.82 Gb Paging File | 6.41 Gb Available in Paging File | 81.99% Paging File free
Paging file location(s): ?:\\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)
Drive C: | 48.73 Gb Total Space | 5.85 Gb Free Space | 12.01% Space Free | Partition Type: NTFS
Drive D: | 48.83 Gb Total Space | 2.43 Gb Free Space | 4.97% Space Free | Partition Type: NTFS
Drive E: | 368.10 Gb Total Space | 33.39 Gb Free Space | 9.07% Space Free | Partition Type: NTFS
Computer Name: SLAIN | User Name: Faraz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days
========== Processes (SafeList) ==========
PRC - [2013/07/24 18:58:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe
PRC - [2013/04/13 12:07:26 | 000,802,136 | ---- | M] (BitTorrent Inc.) -- C:\\Program Files (x86)\\uTorrent\\uTorrent.exe
PRC - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE
PRC - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe
PRC - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe
PRC - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe
PRC - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe
PRC - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe
========== Modules (No Company Name) ==========
MOD - [2011/04/22 08:13:00 | 000,004,096 | ---- | M] () -- C:\\Program Files (x86)\\NVIDIA Corporation\\coprocmanager\\detoured.dll
========== Services (SafeList) ==========
SRV:64bit: - [2012/11/08 04:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe -- (cmdAgent)
SRV:64bit: - [2012/09/18 14:28:28 | 000,230,920 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\\Program Files\\Common Files\\Nitro\\Pro\\8.0\\NitroPDFDriverService8x64.exe -- (NitroDriverReadSpool8)
SRV:64bit: - [2011/11/23 15:27:10 | 001,267,000 | ---- | M] (COMODO) [Auto | Running] -- C:\\Program Files\\COMODO\\COMODO GeekBuddy\\CLPSLS.exe -- (CLPSLS)
SRV:64bit: - [2010/03/19 01:25:55 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\\Windows\\SysNative\\Crypserv.exe -- (CrypKey License)
SRV:64bit: - [2009/08/25 09:15:30 | 000,410,112 | ---- | M] () [Auto | Running] -- C:\\Program Files\\EVDO BROADBAND PTCL\\bin\\MonServiceUDisk64.exe -- (UDisk Monitor)
SRV:64bit: - [2009/07/14 06:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 06:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysNative\\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/07/14 06:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\CISVC.EXE -- (CISVC)
SRV - [2013/06/12 21:24:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/02/28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)
SRV - [2013/01/14 14:41:14 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe -- (AVP)
SRV - [2012/09/18 14:28:32 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\\Windows\\SysWOW64\\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2011/04/22 08:13:00 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe -- (nvUpdatusService)
SRV - [2011/04/21 19:32:26 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/03/14 20:27:34 | 000,346,976 | ---- | M] () [Disabled | Stopped] -- C:\\ProgramData\\DatacardService\\HWDeviceService64.exe -- (HWDeviceService64.exe)
SRV - [2010/12/17 14:46:48 | 000,053,920 | ---- | M] (Atheros Commnucations) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\AdminService.exe -- (AtherosSvc)
SRV - [2010/11/03 12:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2010/11/03 12:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2010/11/03 11:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\\Program Files (x86)\\Intel\\Bluetooth\\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010/10/05 21:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe -- (UNS)
SRV - [2010/10/05 21:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe -- (LMS)
SRV - [2010/10/01 11:49:08 | 000,151,552 | ---- | M] (Atheros) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell Wireless\\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (WAS)
SRV - [2009/07/14 06:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Windows\\SysWOW64\\inetsrv\\iisw3adm.dll -- (W3SVC)
SRV - [2009/07/14 06:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\SysWOW64\\inetsrv\\apphostsvc.dll -- (AppHostSvc)
SRV - [2009/06/11 02:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007/12/03 14:43:06 | 000,841,728 | ---- | M] () [Disabled | Stopped] -- C:\\Program Files (x86)\\Common Files\\Primavera Common\\BackgroundAgent\\PrmBackgroundAgent.exe -- (PrmBackAgent)
SRV - [2007/02/10 07:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe -- (MSSQL$PRIMAVERA)
SRV - [2006/08/28 04:53:48 | 000,092,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files (x86)\\MSSQL\\Primavera\\MSSQL.1\\MSSQL\\Binn\\msftesql.exe -- (msftesql$PRIMAVERA)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/07/14 22:10:42 | 000,178,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kneps.sys -- (kneps)
DRV:64bit: - [2013/07/14 22:10:38 | 000,054,368 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\kltdi.sys -- (kltdi)
DRV:64bit: - [2013/07/14 22:10:03 | 000,620,128 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\klif.sys -- (KLIF)
DRV:64bit: - [2013/06/21 06:07:16 | 000,046,792 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys -- (HssDRV6)
DRV:64bit: - [2013/04/25 00:28:08 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\taphss6.sys -- (taphss6)
DRV:64bit: - [2013/01/14 14:41:12 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klmouflt.sys -- (klmouflt)
DRV:64bit: - [2013/01/14 14:41:12 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\klkbdflt.sys -- (klkbdflt)
DRV:64bit: - [2012/11/08 04:37:57 | 000,022,736 | ---- | M] (COMODO) [File_System | System | Running] -- C:\\Windows\\SysNative\\drivers\\cmderd.sys -- (cmderd)
DRV:64bit: - [2012/08/02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\klim6.sys -- (KLIM6)
DRV:64bit: - [2012/06/21 00:15:53 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV:64bit: - [2012/06/21 00:15:52 | 000,422,400 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbwwan.sys -- (ewusbmbb)
DRV:64bit: - [2012/06/21 00:15:52 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2012/06/21 00:15:52 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV:64bit: - [2012/06/21 00:15:52 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV:64bit: - [2012/06/21 00:15:52 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\ew_jubusenum.sys -- (huawei_enumerator)
DRV:64bit: - [2012/06/21 00:15:52 | 000,072,192 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ew_jucdcecm.sys -- (huawei_cdcecm)
DRV:64bit: - [2012/06/19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\kl1.sys -- (kl1)
DRV:64bit: - [2012/04/23 16:26:26 | 000,154,272 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\idmwfp.sys -- (IDMWFP)
DRV:64bit: - [2012/03/01 11:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/05/25 04:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\taphss.sys -- (taphss)
DRV:64bit: - [2011/05/13 00:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2011/04/22 08:13:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2011/03/26 01:17:50 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/03/11 11:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 11:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/03/03 21:29:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2010/12/17 14:47:10 | 000,275,616 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btfilter.sys -- (BtFilter)
DRV:64bit: - [2010/12/17 14:47:08 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2010/12/17 14:47:08 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2010/12/17 14:47:08 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2010/12/17 14:47:08 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2010/12/17 14:47:08 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2010/12/17 14:47:06 | 000,298,144 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010/11/24 11:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\athrx.sys -- (athr)
DRV:64bit: - [2010/11/04 05:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\btmaux.sys -- (btmaux)
DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/05/27 06:30:00 | 001,121,632 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\netr28ux.sys -- (netr28ux)
DRV:64bit: - [2010/03/19 04:11:09 | 000,030,272 | ---- | M] () [Kernel | System | Running] -- C:\\Windows\\SysNative\\Ckldrv.sys -- (NetworkX)
DRV:64bit: - [2009/12/23 19:33:48 | 000,118,360 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\FVXSCSI.SYS -- (FVXSCSI)
DRV:64bit: - [2009/07/21 16:04:16 | 000,119,168 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)
DRV:64bit: - [2009/07/14 06:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 06:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 06:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 06:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 05:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser.sys -- (usbser)
DRV:64bit: - [2009/06/11 01:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/11 01:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/11 01:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/11 01:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/02/09 10:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64j.sys -- (UsbserFilt)
DRV:64bit: - [2009/02/09 10:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbx64.sys -- (nmwcdx64)
DRV:64bit: - [2009/02/09 10:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2009/02/09 10:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\ccdcmbox64.sys -- (nmwcdcx64)
DRV:64bit: - [2008/10/29 10:47:02 | 000,024,592 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\FCDABUS.SYS -- (fcdabus)
DRV:64bit: - [2008/05/06 18:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\wdcsam64.sys -- (WDC_SAM)
DRV - [2009/07/14 06:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank
IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope =
IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm
IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank
IE - HKLM\\..\\SearchScopes,DefaultScope =
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = about:blank
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page Redirect Cache_TIMESTAMP = ED 44 0A 8A 56 41 CC 01 [binary data]
IE - HKCU\\..\\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found
IE - HKCU\\..\\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\\..\\URLSearchHook: {c34bfb11-eff0-4123-a7a5-79051ef24cf5} - No CLSID value found
IE - HKCU\\..\\SearchScopes,DefaultScope =
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = local
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37
FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"
FF - prefs.js..browser.search.param.yahoo-fr: \"chrf-comodo\"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: \"chrf-comodo\"
FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"
FF - user.js - File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()
FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.21.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.21.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@nitropdf.com/NitroPDF: C:\\Program Files (x86)\\Nitro\\Pro 8\\npnitromozilla.dll (Nitro PDF)
FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVision: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@nvidia.com/3DVisionStreaming: C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Faraz\\AppData\\Local\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\
[email protected]: C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\bkmrksync\\ [2011/07/29 16:13:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\
[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\
[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\
[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\
[email protected] [2013/07/14 22:10:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\
[email protected]: C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\FFExt\\
[email protected] [2013/07/14 22:10:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2012/04/12 22:29:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 11.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins
FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\Extensions\\\\
[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\\software\\mozilla\\SeaMonkey\\Extensions\\\\
[email protected]: C:\\Users\\Faraz\\AppData\\Roaming\\IDM\\idmmzcc5 [2013/06/26 07:05:30 | 000,000,000 | ---D | M]
[2012/04/12 22:30:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Extensions
[2013/07/25 04:37:30 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions
[2013/05/07 12:34:31 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\\Users\\Faraz\\AppData\\Roaming\\mozilla\\Firefox\\Profiles\\3ajw8v5r.default\\extensions\\{C92DDD27-768C-4E40-B655-740B017E698D}
[2013/07/25 04:36:47 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions
[2012/08/03 02:47:40 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/03 20:41:54 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
File not found (No name found) -- C:\\PROGRAM FILES (X86)\\MOZILLA FIREFOX\\EXTENSIONS\\
[email protected][2012/03/13 09:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\\Program Files (x86)\\mozilla firefox\\components\\browsercomps.dll
[2012/03/13 09:38:32 | 000,002,252 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\bing.xml
[2012/03/13 09:38:32 | 000,002,040 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Disabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\PepperFlash\\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\Application\\28.0.1500.72\\pdf.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL
CHR - plugin: Java(TM) Platform SE 7 U13 (Enabled) = C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll
CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\\Program Files (x86)\\Nitro PDF\\Reader 2\\npnitromozilla.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\\Program Files (x86)\\Real Alternative\\browser\\plugins\\nprpjplug.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\\Users\\Faraz\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_6_602_180.dll
CHR - plugin: Java Deployment Toolkit 7.0.130.20 (Enabled) = C:\\Windows\\SysWOW64\\npDeployJava1.dll
CHR - Extension: TV = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\beobeededemalmllhkmnkinmfembdimh\\1.0.12_0\\
CHR - Extension: YouTube = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\
CHR - Extension: Google Search = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\
CHR - Extension: Kaspersky URL Advisor = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dchlnpcodkpfdpacogkljefecpegganj\\13.0.1.4190_0\\
CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlklinjgampohhihndkofhhaahoicoip\\1.0.0_0\\
CHR - Extension: Google+ = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlppkpafhbajpcmmoheippocdidnckmm\\1.2.0.418_0\\
CHR - Extension: ssafEE- saVae = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\epcacbllddpdcojcggmijaggcpambccj\\1\\
CHR - Extension: saafe saveo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hbhkimppigjgkknlpoohbcbfdhhbaeig\\1\\
CHR - Extension: Content Blocker = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\hghkgaeecgjhjkannahfamoehjmkjail\\13.0.1.4190_0\\
CHR - Extension: ESPN Cricinfo = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ijhlikjoigjegofbedmfmlcfkmhabldh\\1.8.4.1_0\\
CHR - Extension: Quran = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iklmggidaneooheckcalppihpgfidbpe\\2_0\\
CHR - Extension: Virtual Keyboard = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\jagncdcchgajhfhijbbhecadmaiegcmh\\13.0.1.4292_0\\
CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\
CHR - Extension: Web Navigation = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lkemddiljapcmhicklfpcbpfffahfbja\\1.0_0\\.bak
CHR - Extension: Gmail = C:\\Users\\Faraz\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_1\\
O1 HOSTS File: ([2013/07/03 16:10:09 | 000,000,707 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC64.dll File not found
O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\\Users\\Faraz\\AppData\\Local\\Temp\\IDMIECC.dll File not found
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\ContentBlocker\\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)
O2 - BHO: (SelectionLinks) - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\\Program Files (x86)\\OApps\\SelectionLinks.dll File not found
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (ssafEE- saVae) - {98ED5451-2AA6-96DB-7012-46C7C9673C57} - C:\\ProgramData\\ssafEE- saVae\\51d19df9cfdfa.dll File not found
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\\PROGRA~2\\TEXTware\\QUICKF~1\\PlugIns\\IEHelp.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {C34BFB11-EFF0-4123-A7A5-79051EF24CF5} - No CLSID value found.
O4:64bit: - HKLM..\\Run: [COMODO Internet Security] C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe (COMODO)
O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\\Run: [NVHotkey] C:\\Windows\\SysNative\\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)
O4 - HKLM..\\Run: [AVP] C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\avp.exe (Kaspersky Lab ZAO)
O4 - HKCU..\\Run: [IDMan] C:\\Program Files (x86)\\Internet Download Manager\\IDMan.exe /onboot File not found
O4 - HKCU..\\Run: [uTorrent] C:\\Program Files (x86)\\uTorrent\\uTorrent.exe (BitTorrent Inc.)
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found
O8:64bit: - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found
O8:64bit: - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEGetAll.htm File not found
O8 - Extra context menu item: Download with IDM - C:\\Users\\Faraz\\AppData\\Local\\Temp\\Rar$EX37.136\\Internet Download Manager v6.05.10\\crack\\IEExt.htm File not found
O8 - Extra context menu item: QuickDefine - C:\\Program Files (x86)\\Common Files\\microsoft shared\\Reference Titles\\eddefine.htm ()
O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\x64\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2iexp.dll ()
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\VirtualKeyboard\\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra \'Tools\' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\\Program Files (x86)\\Dell Wireless\\Bluetooth Suite\\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Anti-Virus 2013\\IEExt\\UrlAdvisor\\klwtbbho.dll (Kaspersky Lab ZAO)
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{50E85FEB-E007-45E8-A588-742A30D19941}: NameServer = 46.184.252.171 46.184.252.82
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{60D8391B-FB23-4063-83BA-281FECD708AE}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{8C0BDDB9-9EE1-42AC-8A70-23BE28B8C50A}: DhcpNameServer = 192.168.100.254
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A267094A-40C3-47D3-8DAE-302A089FA963}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B4E1DD84-082B-4E48-95F7-B9F21F406F24}: NameServer = 8.8.8.8
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{DD41DE21-F7EB-4434-9DAB-E5924B4B42FB}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found
O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found
O18:64bit: - Protocol\\Handler\\skype-ie-addon-data - No CLSID value found
O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)
O18 - Protocol\\Handler\\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll File not found
O20:64bit: - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)
O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\nvinitx.dll) - C:\\Windows\\SysNative\\nvinitx.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\\Windows\\system32\\guard64.dll) - C:\\Windows\\SysNative\\guard64.dll (COMODO)
O20 - AppInit_DLLs: (c:\\windows\\syswow64\\nvinit.dll) - c:\\Windows\\SysWOW64\\nvinit.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\\Windows\\SysWOW64\\guard32.dll) - C:\\Windows\\SysWOW64\\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{02c8fcea-4ca3-11e1-bef9-b0f753bc31d4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{33399f99-67c2-11e1-8d4c-a98bf1d84fd7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41a4-2031-11e1-b52f-ee78cfe267cc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41cd-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{3c7c41fc-2031-11e1-b52f-cfa96447c4ac}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{4af26f6f-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{4af26f77-30a6-11e1-9b94-910f30baeed7}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e4585-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e459a-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e45b1-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{6e1e45c3-2fd1-11e2-a558-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f29098-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f290a8-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{73f290b2-acba-11e1-b04f-bb72616340ba}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe
O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{792b117a-79e6-11e2-8803-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{7b2ec2e4-ccc5-11e0-a18e-001e101f50a4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{85dd8db7-99f3-11e2-9cf8-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\Setup.exe /Auto
O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{86568119-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{86568127-c4b4-11e0-b905-001e101f24f1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b37abe37-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b37abe3e-0cab-11e1-8e39-f1be9be713a1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b3999c83-9c5f-11e1-b456-e3fa1a8666c4}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e385c-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e3869-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{b78e3877-0a03-11e1-916b-95476b19059a}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{c60b1d03-948a-11e1-b452-a9fb93de33a9}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e453e644-42ec-11e1-ba57-dbe944af10d1}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543a2-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = H:\\AutoRun.exe
O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543b7-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e5e543d4-b458-11e0-8134-c0f8da9ce4fc}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e98d437d-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = G:\\AutoRun.exe
O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell - \"\" = AutoRun
O33 - MountPoints2\\{e98d47ad-d555-11e0-8ea9-001e101f8ed0}\\Shell\\AutoRun\\command - \"\" = I:\\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*
O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*
O35 - HKLM\\..comfile [open] -- \"%1\" %*
O35 - HKLM\\..exefile [open] -- \"%1\" %*
O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*
O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*
O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*
O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 90 Days ==========
[2013/07/25 04:49:51 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT
[2013/07/25 04:33:26 | 000,560,934 | ---- | C] (Oleg N. Scherbakov) -- C:\\Users\\Faraz\\Desktop\\JRT.exe
[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro
[2013/07/24 19:03:10 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis
[2013/07/24 18:58:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Faraz\\Desktop\\OTL.exe
[2013/07/21 00:18:49 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EVDO BROADBAND PTCL
[2013/07/21 00:18:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\EVDO BROADBAND PTCL
[2013/07/03 16:19:01 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Comodo
[2013/07/02 19:53:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\CPA_VA
[2013/07/02 19:52:50 | 000,000,000 | ---D | C] -- C:\\Users\\Public\\Documents\\COMODO
[2013/07/02 16:13:11 | 000,000,000 | -H-D | C] -- C:\\VritualRoot
[2013/07/02 16:03:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Comodo
[2013/07/02 16:02:58 | 000,000,000 | ---D | C] -- C:\\Program Files\\COMODO
[2013/07/02 16:02:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Comodo
[2013/07/02 16:02:53 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Comodo
[2013/07/02 16:02:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gdiplus.dll
[2013/07/01 23:35:48 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Kaspersky Anti-Virus 2013
[2013/07/01 23:35:29 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\\Windows\\SysNative\\klfphc.dll
[2013/07/01 23:34:26 | 000,000,000 | ---D | C] -- C:\\Windows\\ELAMBKUP
[2013/07/01 23:34:13 | 000,620,128 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klif.sys
[2013/07/01 23:34:13 | 000,090,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\\Windows\\SysNative\\drivers\\klflt.sys
[2013/07/01 22:46:25 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Zbshareware Lab
[2013/07/01 22:46:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\USB Disk Security
[2013/07/01 22:46:12 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\USB Disk Security
[2013/06/29 11:41:48 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\Desktop\\Docs
[2013/06/27 12:19:08 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nero
[2013/06/27 12:18:06 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Nero
[2013/06/27 12:18:03 | 003,036,456 | ---- | C] (BCGSoft Ltd) -- C:\\Windows\\SysWow64\\BCGCBPRO860u80.dll
[2013/06/27 12:18:03 | 000,802,816 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXRA7.dll
[2013/06/27 12:18:03 | 000,368,640 | ---- | C] (Pegasus Imaging Corporation) -- C:\\Windows\\SysWow64\\TwnLib4.dll
[2013/06/27 12:18:03 | 000,258,048 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXR7.dll
[2013/06/27 12:18:02 | 000,497,296 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagXpr7.dll
[2013/06/27 12:18:01 | 001,757,184 | ---- | C] (Pegasus Imaging Corp.) -- C:\\Windows\\SysWow64\\imagX7.dll
[2013/06/27 12:17:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Ahead
[2013/06/27 12:17:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nero
[2013/06/26 06:59:33 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\CrashDumps
[2013/06/26 06:31:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Apps
[2013/06/21 06:07:16 | 000,046,792 | ---- | C] (AnchorFree Inc.) -- C:\\Windows\\SysNative\\drivers\\hssdrv6.sys
[2013/06/19 12:46:55 | 000,000,000 | R--D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\BT Devices
[2013/06/19 12:46:55 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\BMExplorer
[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager
[2013/06/17 14:37:57 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Download Manager
[2013/06/17 14:20:05 | 000,000,000 | ---D | C] -- C:\\ProgramData\\IDM
[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\Nitro
[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\FileOpen
[2013/06/17 03:07:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\FileOpen
[2013/06/17 03:06:05 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalmon2.dll
[2013/06/17 03:06:05 | 000,017,928 | ---- | C] (Nitro PDF Software) -- C:\\Windows\\SysNative\\nitrolocalui2.dll
[2013/06/17 03:05:24 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\Nitro
[2013/06/17 03:05:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Nitro
[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Nitro
[2013/06/17 03:05:19 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Nitro
[2013/06/17 00:09:23 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Roaming\\PDF
[2013/05/29 16:09:40 | 000,000,000 | ---D | C] -- C:\\Users\\Faraz\\AppData\\Local\\Macromedia
[2013/05/18 14:52:04 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java
[2013/05/18 14:51:39 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe
[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe
[2013/05/18 14:51:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe
[2013/05/18 14:51:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll
[2013/05/06 02:21:12 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\WdfLdr.sys
[2013/05/06 02:21:12 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wdfres.dll
[2013/05/06 02:09:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll
[2013/05/06 02:09:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll
[2013/05/06 02:09:24 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll
[2013/05/06 02:09:24 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll
[2013/05/06 02:07:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFPlatform.dll
[2013/05/06 02:07:57 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFCoinstaller.dll
[2013/05/06 02:07:56 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFx.dll
[2013/05/06 02:07:56 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WUDFHost.exe
[2013/05/06 01:59:05 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll
[2013/05/06 01:59:00 | 002,691,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll
[2013/05/06 01:58:58 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll
[2013/05/06 01:58:58 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll
[2013/05/06 01:58:57 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll
[2013/05/06 01:58:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll
[2013/05/06 01:53:28 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll
[2013/05/06 01:53:28 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll
[2013/05/06 01:53:27 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll
[2013/05/06 01:53:27 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll
[2013/05/06 01:53:26 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe
[2013/05/06 01:53:25 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll
[2013/05/06 01:53:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe
[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/05/06 01:53:24 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/05/06 01:53:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll
[2013/05/06 01:53:23 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll
[2013/05/06 01:53:23 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe
[2013/05/06 01:53:23 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wow32.dll
[2013/05/06 01:53:20 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll
[2013/05/06 01:53:19 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll
[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll
[2013/05/06 01:53:19 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll
[2013/05/06 01:53:19 | 000,