I seem to acquired Virus.Ramnit, Zbot.g and some other malware.
I think I acquired it from browsing some free content sites. This morning I started getting User Account Control prompts to allow CMD access to an unknown application. (which i did not approve)
I then ran full system scans, first using Malwarebytes, which caught and removed many instances of Virus.Ramnit. Then i ran a full system scan using AVG, which caught and healed many instances of Zbot.g. However, it still keeps periodically showing even more instances of the same virus in other files.
Furthermore, i cannot access any antivirus site or microsoft website now. Gmail in standard view also runs very slowly (seems to be running fine in HTML mode). Google Chrome won't start (tried unstalling and reinstalling).
I have pasted the OTL log below. Please let me know if i need to post any other info and I will post immediately.
Many thanks in advance for your help. This seems to an amazing forum of dedicated people!
OTL logfile created on: 03/12/2011 21:31:12 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Rajat\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19154)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.99 Gb Total Physical Memory | 1.32 Gb Available Physical Memory | 44.02% Memory free
6.21 Gb Paging File | 4.41 Gb Available in Paging File | 71.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 282.97 Gb Total Space | 56.70 Gb Free Space | 20.04% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 10.14 Gb Free Space | 67.60% Space Free | Partition Type: NTFS
Computer Name: RAJAT-PC | User Name: Rajat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found --
PRC - [2011/12/03 21:04:57 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Rajat\Desktop\OTL.exe
PRC - [2011/11/13 10:37:46 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/10/27 08:57:46 | 002,078,048 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2011/10/27 08:54:37 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
PRC - [2011/10/20 11:58:40 | 002,497,352 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2011/10/07 17:47:13 | 001,883,328 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/11/25 22:39:54 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/09/24 07:08:19 | 000,621,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/07/17 14:26:11 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/07/17 14:26:08 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/07/17 14:25:12 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2009/04/11 06:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/03/20 08:26:18 | 000,483,428 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009/03/20 08:26:08 | 000,254,042 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe
PRC - [2009/03/20 08:25:42 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe
PRC - [2007/05/28 16:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
========== Modules (No Company Name) ==========
MOD - [2011/12/03 08:05:40 | 011,804,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\e00630ec1e225a2376fdd430645e20f7\System.Web.ni.dll
MOD - [2011/12/03 08:05:27 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll
MOD - [2011/12/03 07:45:50 | 007,950,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll
MOD - [2011/12/03 07:43:04 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
MOD - [2011/11/13 10:37:45 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/06/17 18:42:55 | 006,271,136 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2008/12/22 10:32:38 | 000,054,784 | ---- | M] () -- C:\Windows\System32\bcmwlrmt.dll
MOD - [2008/12/01 05:42:30 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/11/13 01:01:47 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/10/07 17:47:13 | 001,883,328 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/07/17 14:26:08 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/01/24 20:57:38 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/01/15 12:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/03/20 08:26:08 | 000,254,042 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe -- (STacSV)
SRV - [2009/03/20 08:25:42 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe -- (AESTFilters)
SRV - [2008/01/21 02:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/05/28 16:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2007/03/19 11:44:44 | 000,070,656 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2006/10/31 09:32:09 | 002,541,248 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate)
========== Driver Services (SafeList) ==========
DRV - [2011/10/07 17:47:45 | 000,082,400 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\inspect.sys -- (inspect)
DRV - [2011/10/07 17:47:43 | 000,038,616 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2011/10/07 17:47:42 | 000,488,208 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2011/09/12 20:24:03 | 000,029,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2011/09/04 10:22:47 | 000,081,936 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdLH3.sys -- (AtiHDAudioService)
DRV - [2011/08/31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/05/06 06:07:25 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/07/17 14:25:13 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/01/01 03:19:18 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2010/01/01 03:19:17 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2009/11/11 16:23:46 | 000,030,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\point32k.sys -- (Point32)
DRV - [2009/11/09 03:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2009/09/04 22:35:37 | 000,722,416 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/03/20 08:26:22 | 000,398,336 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2009/03/12 10:36:38 | 000,143,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2009/02/10 09:40:28 | 000,133,472 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OA008Ufd.sys -- (OA008Ufd)
DRV - [2009/02/10 09:40:26 | 000,271,616 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OA008Vid.sys -- (OA008Vid)
DRV - [2008/12/22 10:32:18 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY)
DRV - [2008/12/01 05:42:28 | 004,016,640 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2008/12/01 05:42:28 | 004,016,640 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008/10/20 15:15:22 | 000,034,592 | ---- | M] () [Kernel | System | Running] -- C:\Windows\system32\drivers\nipplpt.sys -- (nipplpt2)
DRV - [2008/10/08 09:37:36 | 000,212,992 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\k57nd60x.sys -- (k57nd60x) Broadcom NetLink
DRV - [2008/09/16 09:11:02 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2008/09/16 09:11:00 | 000,046,592 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2008/09/16 09:10:56 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2008/01/21 02:23:25 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel®
DRV - [2007/06/29 14:47:34 | 000,034,304 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmdLLD.sys -- (AmdLLD)
DRV - [2007/02/25 11:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.2.44172
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: [email protected]:2.8
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.3
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.36.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {66E978CD-981F-47DF-AC42-E3CF417C1467}:0.4.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: [email protected]:0.6
FF - prefs.js..extensions.enabledItems: {BE2100B3-1D80-48eb-ACCF-D26750644378}:0.4.23
FF - prefs.js..extensions.enabledItems: {9F929BB4-CD50-495C-909B-1DD1A6A989A6}:1.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0
FF - user.js..network.proxy.type: 0
FF - user.js..network.proxy.http: ""
FF - user.js..network.proxy.http_port:
FF - user.js..network.proxy.no_proxies_on: ""
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Rajat\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Rajat\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Rajat\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Rajat\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Rajat\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2011/09/12 20:25:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2010/03/06 01:37:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/13 10:37:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/08 20:53:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{9F929BB4-CD50-495C-909B-1DD1A6A989A6}: C:\Users\Rajat\AppData\Local\{9F929BB4-CD50-495C-909B-1DD1A6A989A6} [2010/10/18 22:29:01 | 000,000,000 | ---D | M]
[2009/09/05 08:17:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Extensions
[2011/11/13 10:38:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions
[2010/04/30 00:48:58 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/10 15:46:58 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2011/04/07 20:58:50 | 000,000,000 | ---D | M] (New Tab Homepage) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}
[2009/09/13 12:39:57 | 000,000,000 | ---D | M] (flashget3 Extension) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
[2011/05/08 20:54:42 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\[email protected]
[2010/04/30 00:48:50 | 000,000,000 | ---D | M] (Illimitux) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\[email protected]
[2011/04/07 20:58:54 | 000,000,000 | ---D | M] (Flash Video Resources Downloader) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\[email protected]
[2011/04/07 20:58:53 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\[email protected]
[2011/11/13 10:38:15 | 000,000,000 | ---D | M] (Cooliris) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\[email protected]
[2010/12/18 22:56:20 | 000,000,000 | ---D | M] (Tab Kit) -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\extensions\[email protected]
[2011/07/12 13:40:46 | 000,001,947 | ---- | M] () -- C:\Users\Rajat\AppData\Roaming\Mozilla\Firefox\Profiles\jescpk74.default\searchplugins\a-wiki-of-ice-and-fire-en.xml
[2011/12/03 20:23:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/08/28 21:35:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/12/03 20:23:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2009/11/16 23:59:44 | 000,000,000 | ---D | M] (Hide My IP) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
() (No name found) -- C:\USERS\RAJAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JESCPK74.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\RAJAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JESCPK74.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
[2011/11/13 10:37:46 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008/10/28 09:15:22 | 000,255,248 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npnipp.dll
[2008/10/28 09:15:24 | 000,107,792 | ---- | M] (Novell Inc.) -- C:\Program Files\mozilla firefox\plugins\npnisp.dll
[2011/10/23 06:28:49 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/13 10:37:47 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.120\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.120\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.120\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: Novell iPrint Plug-in (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npnipp.dll
CHR - plugin: Novell iPrint Scriptable Plug-in 1.0 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npnisp.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Rajat\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Rajat\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Rajat\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Rajat\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: AdBlock = C:\Users\Rajat\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.4.29_0\
O1 HOSTS File: ([2011/03/20 09:58:46 | 000,001,066 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 static3.cdn.ubi.com
O1 - Hosts: 127.0.0.1 ubisoft-orbit.s3.amazonaws.com
O1 - Hosts: 127.0.0.1 onlineconfigservice.ubi.com
O1 - Hosts: 127.0.0.1 orbitservice.ubi.com
O1 - Hosts: 127.0.0.1 ubisoft-orbit-savegames.s3.amazonaws.com
O1 - Hosts: 173.212.255.178 embedded.garena.com
O1 - Hosts: 173.212.255.178 embedded.garenanow.com
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [TncRufnu] C:\Users\Rajat\AppData\Local\lhkfkfee\tncrufnu.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Download All By FlashGet3 - C:\Users\Rajat\AppData\Roaming\FlashGetBHO\GetAllUrl.htm File not found
O8 - Extra context menu item: Download By FlashGet3 - C:\Users\Rajat\AppData\Roaming\FlashGetBHO\GetUrl.htm File not found
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O15 - HKCU\..Trusted Domains: diamondconsultants.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: diamondconsultants.com ([apply] https in Trusted sites)
O15 - HKCU\..Trusted Domains: london.edu ([portal] https in Trusted sites)
O15 - HKCU\..Trusted Domains: symplicity.com ([london-csm] https in Trusted sites)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.syste...yri_4.3.1.0.cab (SysInfo Class)
O16 - DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} http://dl.pplive.com/PluginSetup.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{660D73FB-58BD-4691-918E-C8DC2E83A96C}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9040D51A-5D38-49AD-8022-28A72F5BEDDB}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll ()
O20 - AppInit_DLLs: (C:\Windows\System32\acaptuser32.dll) -C:\Windows\System32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - AppInit_DLLs: (C:\Windows\System32\avgrsstx.dll) -C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (avgrsstx.dll C:\Windows\system32\guard32.dll) -C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{445f24fe-c5cb-11de-bb35-002219f65d4c}\Shell\AutoRun\command - "" = F:\installer.exe
O33 - MountPoints2\{d3a55dde-07ef-11df-b81f-002219f65d4c}\Shell\AutoRun\command - "" = F:\installer.exe
O33 - MountPoints2\{ed716939-b571-11df-9464-002219f65d4c}\Shell - "" = Autorun
O33 - MountPoints2\{ed716939-b571-11df-9464-002219f65d4c}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\unlock.exe
O33 - MountPoints2\{ed716939-b571-11df-9464-002219f65d4c}\Shell\open\command - "" = F:\unlock.exe
O33 - MountPoints2\{ff7125b9-bad9-11de-91e2-002219f65d4c}\Shell\1\Command - "" = F:\Recycled.exe
O33 - MountPoints2\{ff7125b9-bad9-11de-91e2-002219f65d4c}\Shell\2\Command - "" = F:\Recycled.exe
O33 - MountPoints2\{ff7125b9-bad9-11de-91e2-002219f65d4c}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Recycled.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\OblivionLauncher.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\OblivionLauncher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/03 21:08:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WB Games
[2011/12/03 21:05:02 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Rajat\Desktop\OTL.exe
[2011/12/03 20:27:56 | 000,000,000 | ---D | C] -- C:\Program Files\AMD APP
[2011/12/03 20:11:55 | 000,000,000 | ---D | C] -- C:\Users\Rajat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/12/02 22:01:53 | 000,000,000 | ---D | C] -- C:\Users\Rajat\AppData\Local\lhkfkfee
[2011/11/27 06:34:35 | 000,000,000 | ---D | C] -- C:\Users\Rajat\Documents\WB Games
[2011/11/27 06:23:36 | 000,034,304 | ---- | C] (AMD, Inc.) -- C:\Windows\System32\drivers\AmdLLD.sys
[2011/11/27 06:23:35 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2011/11/27 06:22:40 | 000,000,000 | ---D | C] -- C:\Users\Rajat\AppData\Local\Downloaded Installations
[2011/11/26 22:08:39 | 000,000,000 | ---D | C] -- C:\Users\Rajat\AppData\Roaming\Origin
[2011/11/26 22:08:38 | 000,000,000 | ---D | C] -- C:\Users\Rajat\AppData\Local\Origin
[2011/11/26 22:08:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Origin
[2011/11/26 22:08:27 | 000,000,000 | ---D | C] -- C:\Program Files\Origin Games
[2011/11/26 22:08:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2011/11/26 22:08:17 | 000,000,000 | ---D | C] -- C:\Program Files\Origin
[2011/11/26 07:57:21 | 000,000,000 | ---D | C] -- C:\Users\Rajat\Documents\Assassin's Creed Revelations
[2011/11/25 23:47:14 | 000,000,000 | ---D | C] -- C:\Program Files\Ubisoft
[2011/11/25 23:13:58 | 000,000,000 | ---D | C] -- C:\Ubisoft
[2011/11/25 19:45:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/11/25 19:45:50 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/11/23 18:27:12 | 000,033,984 | ---- | C] (COMODO) -- C:\Windows\System32\cmdcsr.dll
[2011/11/13 15:54:36 | 000,000,000 | ---D | C] -- C:\Program Files\Rockstar Games
[2011/11/13 12:20:10 | 000,000,000 | ---D | C] -- C:\lanoire
[2011/11/13 06:22:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Rockstar Games
[2011/11/11 17:17:23 | 000,000,000 | ---D | C] -- C:\Users\Rajat\AppData\Local\Skyrim
[2011/11/11 05:27:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/11/05 12:36:04 | 000,000,000 | ---D | C] -- C:\Users\Rajat\Documents\Ubisoft
[2011/11/05 11:13:21 | 000,000,000 | ---D | C] -- C:\Users\Rajat\AppData\Local\Ubisoft Game Launcher
[2011/11/05 09:26:56 | 000,000,000 | -H-D | C] -- C:\Users\Rajat\InstallAnywhere
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Rajat\Desktop\*.tmp files -> C:\Users\Rajat\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/03 21:29:11 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/03 21:29:10 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/03 21:20:51 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{6B69AA6F-3ADA-462C-B7EA-DCF258490292}.job
[2011/12/03 21:08:03 | 000,001,246 | ---- | M] () -- C:\Users\Public\Desktop\Batman - Arkham City.lnk
[2011/12/03 21:04:57 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Rajat\Desktop\OTL.exe
[2011/12/03 21:01:19 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/03 20:51:12 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2622647993-3817205681-1033453672-1000UA.job
[2011/12/03 20:51:03 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2622647993-3817205681-1033453672-1000Core.job
[2011/12/03 17:30:13 | 000,000,000 | ---- | M] () -- C:\Users\Rajat\AppData\Local\prvlcl.dat
[2011/12/03 17:14:59 | 089,895,423 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2011/12/03 11:35:42 | 000,643,598 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/03 11:35:42 | 000,121,764 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/03 11:29:09 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/03 11:28:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/03 11:28:41 | 3215,835,136 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/03 07:40:40 | 000,382,504 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/03 07:03:32 | 000,000,118 | ---- | M] () -- C:\Windows\System32\MRT.INI
[2011/12/01 19:41:51 | 000,000,252 | ---- | M] () -- C:\Windows\tasks\TClock4.job
[2011/11/30 05:45:00 | 000,000,252 | ---- | M] () -- C:\Windows\tasks\TClock3.job
[2011/11/29 06:45:37 | 000,000,252 | ---- | M] () -- C:\Windows\tasks\TClock2.job
[2011/11/28 06:45:35 | 000,000,252 | ---- | M] () -- C:\Windows\tasks\TClock1.job
[2011/11/26 22:47:43 | 000,025,088 | ---- | M] () -- C:\Users\Rajat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/26 22:07:16 | 000,000,680 | ---- | M] () -- C:\Users\Rajat\AppData\Local\d3d9caps.dat
[2011/11/26 07:53:25 | 000,000,882 | ---- | M] () -- C:\Users\Rajat\Desktop\AssassinsCreedRevelations.exe - Shortcut.lnk
[2011/11/25 19:45:52 | 000,000,806 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/17 14:30:53 | 000,000,544 | ---- | M] () -- C:\Users\Rajat\Desktop\LANoire.lnk
[2011/11/05 08:45:40 | 000,002,595 | ---- | M] () -- C:\Users\Rajat\Desktop\Mobipocket Reader.lnk
[2011/11/04 22:54:01 | 000,051,186 | ---- | M] () -- C:\Users\Rajat\AppData\Roaming\room_v3.dat
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Rajat\Desktop\*.tmp files -> C:\Users\Rajat\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/03 21:08:03 | 000,001,246 | ---- | C] () -- C:\Users\Public\Desktop\Batman - Arkham City.lnk
[2011/12/03 07:03:32 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2011/11/26 07:53:25 | 000,000,882 | ---- | C] () -- C:\Users\Rajat\Desktop\AssassinsCreedRevelations.exe - Shortcut.lnk
[2011/11/25 19:45:52 | 000,000,806 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/17 14:30:53 | 000,000,544 | ---- | C] () -- C:\Users\Rajat\Desktop\LANoire.lnk
[2011/10/25 21:21:48 | 000,056,832 | ---- | C] () -- C:\Windows\System32\OpenVideo.dll
[2011/10/25 21:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\System32\OVDecoder.dll
[2011/07/28 16:49:12 | 000,053,760 | ---- | C] () -- C:\Windows\System32\OVDecode.dll
[2011/05/26 14:22:56 | 000,051,186 | ---- | C] () -- C:\Users\Rajat\AppData\Roaming\room_v3.dat
[2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/03/24 18:30:45 | 000,046,658 | ---- | C] () -- C:\Users\Rajat\AppData\Roaming\room.dat
[2011/03/06 13:21:56 | 000,000,321 | ---- | C] () -- C:\Windows\SoftWriting.ini
[2010/11/14 03:08:44 | 000,081,920 | ---- | C] () -- C:\Windows\System32\emfxp.dll
[2010/11/14 03:08:44 | 000,059,904 | ---- | C] () -- C:\Windows\System32\unpdf.exe
[2010/10/18 22:29:05 | 000,000,120 | ---- | C] () -- C:\Users\Rajat\AppData\Local\Owujijolozikeq.dat
[2010/10/18 22:29:05 | 000,000,000 | ---- | C] () -- C:\Users\Rajat\AppData\Local\Cneruvurovilox.bin
[2010/08/26 18:47:09 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/05/15 16:10:49 | 000,001,024 | ---- | C] () -- C:\Windows\System32\grcauth2.dll
[2010/05/15 16:10:49 | 000,001,024 | ---- | C] () -- C:\Windows\System32\grcauth1.dll
[2010/05/15 16:10:49 | 000,000,100 | ---- | C] () -- C:\Windows\System32\prsgrc.dll
[2010/03/14 02:19:10 | 000,000,088 | RHS- | C] () -- C:\ProgramData\4EAAC0B088.sys
[2010/03/14 02:19:07 | 000,005,642 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010/03/13 02:46:31 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2010/02/11 07:07:04 | 000,000,535 | ---- | C] () -- C:\Windows\eReg.dat
[2010/01/31 02:03:44 | 000,000,000 | ---- | C] () -- C:\Users\Rajat\AppData\Local\prvlcl.dat
[2010/01/01 03:19:18 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2010/01/01 03:19:17 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2009/12/14 06:57:39 | 000,094,208 | ---- | C] () -- C:\Windows\System32\zmbv.dll
[2009/10/12 21:44:45 | 000,236,544 | ---- | C] () -- C:\Windows\PEV.exe
[2009/10/12 21:44:45 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2009/10/12 21:44:45 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2009/10/12 21:44:45 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2009/10/04 14:47:21 | 000,000,680 | ---- | C] () -- C:\Users\Rajat\AppData\Local\d3d9caps.dat
[2009/09/24 13:47:29 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/24 13:47:29 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/24 13:46:50 | 000,217,088 | ---- | C] () -- C:\Windows\System32\WerFault.exe
[2009/09/24 09:55:35 | 000,073,728 | ---- | C] () -- C:\Windows\System32\nipplpte.exe
[2009/09/24 09:55:35 | 000,065,536 | ---- | C] () -- C:\Windows\System32\icapture.exe
[2009/09/24 09:55:35 | 000,034,592 | ---- | C] () -- C:\Windows\System32\drivers\nipplpt.sys
[2009/09/23 14:10:47 | 000,819,200 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/09/23 14:10:47 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/09/13 19:39:35 | 000,025,088 | ---- | C] () -- C:\Users\Rajat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/13 12:39:46 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI
[2009/09/07 11:51:08 | 000,162,304 | ---- | C] () -- C:\Windows\System32\Unwise32.exe
[2009/09/07 11:50:57 | 000,000,572 | ---- | C] () -- C:\Windows\DTOOLS.INI
[2009/09/07 11:50:42 | 000,338,944 | ---- | C] () -- C:\Windows\System32\LFFPX7.DLL
[2009/09/07 11:50:42 | 000,118,784 | ---- | C] () -- C:\Windows\System32\LFKODAK.DLL
[2009/09/07 11:50:41 | 001,683,456 | ---- | C] () -- C:\Windows\System32\LTCLR13n.dll
[2009/09/06 12:18:51 | 000,000,256 | ---- | C] () -- C:\Users\Rajat\AppData\Roaming\wklnhst.dat
[2009/09/01 00:01:56 | 000,022,723 | ---- | C] () -- C:\Windows\System32\ssp2ml3.dll
[2009/08/19 23:48:19 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2009/08/19 23:48:19 | 000,176,214 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2009/08/19 23:48:19 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009/08/19 23:48:19 | 000,081,920 | ---- | C] () -- C:\Windows\System32\ATIODE.exe
[2009/08/19 23:48:19 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ATIODCLI.exe
[2009/08/19 15:56:01 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/08/19 15:16:22 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2009/08/19 15:16:21 | 000,054,784 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2009/08/19 15:16:20 | 000,026,112 | ---- | C] () -- C:\Windows\System32\WLTRYSVC.EXE
[2009/04/11 18:02:01 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2006/12/27 11:34:00 | 000,462,848 | ---- | C] () -- C:\Windows\System32\softcoin.dll
[2006/12/27 11:34:00 | 000,344,064 | ---- | C] () -- C:\Windows\System32\gencoin.dll
[2006/11/02 12:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 12:47:37 | 000,382,504 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 12:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 10:33:01 | 000,643,598 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 10:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 10:33:01 | 000,121,764 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 10:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 10:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 08:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 08:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 07:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 07:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2003/04/09 09:28:44 | 000,233,472 | R--- | C] () -- C:\Windows\System32\MafiaSetup.exe
========== LOP Check ==========
[2009/11/26 01:34:38 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\AlarmClock
[2009/11/07 00:48:40 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Bump Technologies, Inc
[2009/09/04 22:35:21 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\DAEMON Tools Pro
[2011/07/23 09:50:06 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Downloaded Installations
[2009/09/13 12:39:38 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\FlashGet
[2010/01/10 08:19:44 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\FOG Downloader
[2011/08/21 18:49:30 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\GarenaMessenger
[2010/12/20 21:00:38 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Hive Cluster
[2010/11/14 14:04:26 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Hothead Games
[2011/02/26 17:10:29 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Kalypso Media
[2011/07/28 07:50:20 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Lionhead Studios
[2011/04/09 15:05:55 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\LolClient
[2011/09/18 17:41:30 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Mobipocket
[2011/03/30 22:13:43 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Octoshape
[2011/11/26 22:09:00 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Origin
[2011/02/26 19:05:36 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\PPlive
[2011/03/17 04:46:39 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\PunkBuster
[2010/12/24 15:13:50 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\runic games
[2010/10/17 12:30:37 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\ScripterRon
[2009/11/27 14:29:49 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\SecondLife
[2011/11/28 23:10:29 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Spotify
[2011/12/03 12:07:45 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\SystemRequirementsLab
[2009/09/06 12:18:53 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Template
[2011/03/19 10:03:04 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\The Creative Assembly
[2010/04/17 09:26:28 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\Ubisoft
[2011/11/27 16:18:57 | 000,000,000 | ---D | M] -- C:\Users\Rajat\AppData\Roaming\uTorrent
[2011/12/03 11:27:30 | 000,032,604 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/11/28 06:45:35 | 000,000,252 | ---- | M] () -- C:\Windows\Tasks\TClock1.job
[2011/11/29 06:45:37 | 000,000,252 | ---- | M] () -- C:\Windows\Tasks\TClock2.job
[2011/11/30 05:45:00 | 000,000,252 | ---- | M] () -- C:\Windows\Tasks\TClock3.job
[2011/12/01 19:41:51 | 000,000,252 | ---- | M] () -- C:\Windows\Tasks\TClock4.job
[2011/12/03 21:20:51 | 000,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{6B69AA6F-3ADA-462C-B7EA-DCF258490292}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:6D88F1EE
< End of report >