First thing that happened is that my computer just randomly restarted while I was tweeting and reading some article on yahoo. After my pc restarted, I received the following error through ESET:
Eset Smart Security Found a threat:
Object: MBR sector of the 1.physical disk
Threat: Win32/Olmarik.AXY.Trojan
Next thing I did was run MBAM (Malware-bytes AntiMalware). It did not pick anything up so a google search brought me to this website. Somebody else had a similar issue: http://www.geekstogo...marikaxytrojan/
I did not want to try any of those steps since they may differ for me. I am also not the only user of this computer
Thanks buddy!
______________________________________________________________________________________________________________________________________________________________
OTL logfile created on: 1/25/2012 11:16:53 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = Z:\Users\Harsh\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 60.63% Memory free
8.00 Gb Paging File | 6.22 Gb Available in Paging File | 77.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = Z: | %SystemRoot% = Z:\Windows | %ProgramFiles% = Z:\Program Files (x86)
Drive C: | 76.69 Gb Total Space | 12.33 Gb Free Space | 16.07% Space Free | Partition Type: NTFS
Drive E: | 40.00 Gb Total Space | 39.91 Gb Free Space | 99.78% Space Free | Partition Type: NTFS
Drive F: | 74.53 Gb Total Space | 22.57 Gb Free Space | 30.29% Space Free | Partition Type: NTFS
Drive G: | 844.03 Gb Total Space | 398.04 Gb Free Space | 47.16% Space Free | Partition Type: NTFS
Drive Z: | 47.48 Gb Total Space | 2.39 Gb Free Space | 5.04% Space Free | Partition Type: NTFS
Computer Name: HARSH-PC | User Name: Harsh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/25 23:16:15 | 000,584,192 | ---- | M] (OldTimer Tools) -- Z:\Users\Harsh\Desktop\OTL.exe
PRC - [2012/01/15 14:04:20 | 000,924,632 | ---- | M] (Mozilla Corporation) -- Z:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/01/03 08:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- Z:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/12/17 16:05:00 | 002,348,864 | ---- | M] (NVIDIA Corporation) -- Z:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2011/10/04 22:50:37 | 000,075,136 | ---- | M] () -- Z:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010/11/20 07:17:56 | 000,164,864 | ---- | M] (Microsoft Corporation) -- Z:\Program Files (x86)\Windows Media Player\wmplayer.exe
PRC - [2010/08/03 09:43:02 | 000,522,824 | ---- | M] (Logitech Inc.) -- Z:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
PRC - [2010/05/05 15:56:06 | 000,251,392 | ---- | M] () -- Z:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
PRC - [2010/03/30 23:00:00 | 002,465,888 | ---- | M] (Lavalys, Inc.) -- Z:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\everest.exe
PRC - [2009/12/02 19:40:40 | 000,068,136 | ---- | M] () -- Z:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe
PRC - [2009/09/29 12:03:46 | 000,735,960 | ---- | M] (ESET) -- Z:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- Z:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2007/12/19 10:58:24 | 000,163,840 | ---- | M] (Razer Inc.) -- Z:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
========== Modules (No Company Name) ==========
MOD - [2012/01/15 14:04:20 | 001,911,768 | ---- | M] () -- Z:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/12/20 20:48:21 | 008,930,976 | ---- | M] () -- Z:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_160.dll
MOD - [2010/05/05 15:56:06 | 000,251,392 | ---- | M] () -- Z:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2012/01/02 17:30:20 | 000,515,104 | ---- | M] (Soluto) [Auto | Running] -- Z:\Program Files\Soluto\SolutoService.exe -- (SolutoService)
SRV:64bit: - [2011/08/11 18:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- Z:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2011/03/21 16:19:16 | 001,845,248 | ---- | M] (Locktime Software) [On_Demand | Stopped] -- Z:\Program Files\NetLimiter 3\nlsvc.exe -- (nlsvc)
SRV:64bit: - [2009/09/29 12:11:14 | 000,023,296 | ---- | M] (ESET) [On_Demand | Stopped] -- Z:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV:64bit: - [2009/09/29 12:03:46 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- Z:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- Z:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- Z:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/01/17 12:10:34 | 000,008,704 | ---- | M] (Hi-Rez Studios) [On_Demand | Running] -- G:\Games\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2012/01/03 08:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Running] -- Z:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/12/20 20:48:21 | 000,253,600 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- Z:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2011/12/17 16:05:00 | 002,348,864 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- Z:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2011/12/14 15:43:00 | 003,316,000 | ---- | M] () [On_Demand | Running] -- z:\program files (x86)\common files\akamai/netsession_win_b427739.dll -- (Akamai)
SRV - [2011/10/14 13:49:38 | 000,745,832 | ---- | M] (Tunngle.net GmbH) [On_Demand | Stopped] -- Z:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2011/10/04 22:50:37 | 000,075,136 | ---- | M] () [On_Demand | Running] -- Z:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011/04/21 16:36:28 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- Z:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/03/01 17:29:58 | 000,130,976 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- Z:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- Z:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/12/02 19:40:40 | 000,068,136 | ---- | M] () [Auto | Running] -- Z:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- Z:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [On_Demand | Running] -- Z:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/01/02 17:15:26 | 000,054,728 | ---- | M] (Soluto LTD.) [File_System | Boot | Running] -- Z:\Windows\SysNative\drivers\Soluto.sys -- (Soluto)
DRV:64bit: - [2011/11/20 19:28:39 | 000,530,488 | ---- | M] () [Kernel | Boot | Running] -- Z:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- Z:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- Z:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/03/30 06:05:55 | 000,035,112 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV:64bit: - [2011/03/21 16:44:30 | 000,033,416 | ---- | M] (Locktime Software) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\nlndis.sys -- (NLNdisPT)
DRV:64bit: - [2011/03/21 16:44:30 | 000,033,416 | ---- | M] (Locktime Software) [Kernel | On_Demand | Running] -- Z:\Windows\SysNative\drivers\nlndis.sys -- (NLNdisMP)
DRV:64bit: - [2011/03/21 16:44:28 | 000,088,200 | ---- | M] (Locktime Software) [Kernel | System | Running] -- Z:\Program Files\NetLimiter 3\nltdi.sys -- (nltdi)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- Z:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 06:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/06 22:24:34 | 000,024,176 | ---- | M] () [Kernel | On_Demand | Running] -- Z:\Program Files\PeerBlock\pbfilter.sys -- (pbfilter)
DRV:64bit: - [2010/04/19 16:04:44 | 000,012,032 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- Z:\Windows\SysNative\drivers\dadder.sys -- (DAdderFltr)
DRV:64bit: - [2010/04/09 12:17:24 | 000,019,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)
DRV:64bit: - [2010/04/09 12:17:20 | 000,013,280 | ---- | M] () [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\pwdspio.sys -- (pwdspio)
DRV:64bit: - [2009/12/21 20:50:00 | 000,007,552 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] -- Z:\Windows\SysNative\drivers\vHidDev.sys -- (vhidmini)
DRV:64bit: - [2009/11/23 16:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- Z:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009/11/23 16:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- Z:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009/09/29 12:06:16 | 000,123,200 | ---- | M] (ESET) [Kernel | Auto | Running] -- Z:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:64bit: - [2009/09/29 12:03:00 | 000,136,584 | ---- | M] (ESET) [Kernel | System | Running] -- Z:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2009/09/29 11:56:36 | 000,144,824 | ---- | M] (ESET) [File_System | Auto | Running] -- Z:\Windows\SysNative\drivers\eamon.sys -- (eamon)
DRV:64bit: - [2009/09/16 07:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- Z:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle)
DRV:64bit: - [2009/08/13 22:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- Z:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/03/01 22:05:32 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- Z:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2008/11/11 13:42:00 | 000,033,792 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\lgx64modem.sys -- (USBModem)
DRV:64bit: - [2008/11/11 13:42:00 | 000,027,136 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\lgx64diag.sys -- (UsbDiag)
DRV:64bit: - [2008/11/11 13:42:00 | 000,017,920 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\lgx64bus.sys -- (usbbus)
DRV:64bit: - [2006/11/10 08:08:58 | 000,030,720 | ---- | M] () [Kernel | On_Demand | Stopped] -- Z:\Windows\SysNative\drivers\ATITool64.sys -- (ATITool)
DRV - [2012/01/25 23:03:31 | 000,025,640 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- Z:\Windows\gdrv.sys -- (gdrv)
DRV - [2011/11/20 20:19:08 | 000,025,640 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- Z:\Windows\etdrv.sys -- (etdrv)
DRV - [2011/11/20 20:13:24 | 000,030,528 | ---- | M] () [Kernel | On_Demand | Stopped] -- Z:\Windows\GVTDrv64.sys -- (GVTDrv64)
DRV - [2011/10/26 17:13:42 | 000,021,712 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- Z:\Windows\SysWOW64\drivers\DrvAgent64.SYS -- (DrvAgent64)
DRV - [2010/11/27 18:01:37 | 000,019,952 | ---- | M] () [Kernel | On_Demand | Running] -- Z:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys -- (RivaTuner64)
DRV - [2010/03/30 23:00:00 | 000,026,752 | ---- | M] () [Kernel | On_Demand | Running] -- Z:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 -- (EverestDriver)
DRV - [2009/12/18 11:58:52 | 000,017,864 | ---- | M] () [Kernel | On_Demand | Stopped] -- Z:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys -- (cpudrv64)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- Z:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5A 1B F8 D2 D0 83 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {7aeb3efd-e564-43f1-b658-5058a7c5743b} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "www.gamespot.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.11
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: [email protected]:2.6.1
FF - prefs.js..keyword.URL: "http://www.google.co...ient&gfns=1&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: Z:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_160.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: Z:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: Z:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: Z:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_160.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: Z:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: Z:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: Z:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: Z:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: Z:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: Z:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: Z:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@onlive.com/OlGameDetect,version=1.1.0.67837: Z:\Program Files (x86)\OnLive\FirefoxPlugin\npolgdet.dll (OnLive)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: Z:\Program Files (x86)\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: Z:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: Z:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: Z:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: Z:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: Z:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: Z:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: Z:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/10/30 13:51:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: Z:\Program Files (x86)\Mozilla Firefox\components [2012/01/15 14:04:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: Z:\Program Files (x86)\Mozilla Firefox\plugins [2012/01/14 15:09:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0b12\extensions\\Components: Z:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\components [2011/11/06 18:54:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0b12\extensions\\Plugins: Z:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\plugins [2012/01/14 15:09:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: Z:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/03/26 01:56:49 | 000,000,000 | ---D | M]
[2010/09/09 21:23:13 | 000,000,000 | ---D | M] (No name found) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Extensions
[2010/09/09 21:23:13 | 000,000,000 | ---D | M] (No name found) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Extensions\[email protected]
[2012/01/22 20:14:12 | 000,000,000 | ---D | M] (No name found) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Firefox\Profiles\vk995pnm.default\extensions
[2012/01/03 20:13:10 | 000,000,000 | ---D | M] (vshare.tv Bar Community Toolbar) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Firefox\Profiles\vk995pnm.default\extensions\{7aeb3efd-e564-43f1-b658-5058a7c5743b}
[2011/11/03 17:12:54 | 000,000,000 | ---D | M] (WebSlingPlayer) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Firefox\Profiles\vk995pnm.default\extensions\{9EB34849-81D3-4841-939D-666D522B889A}
[2012/01/21 14:22:50 | 000,000,000 | ---D | M] (Greasemonkey) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Firefox\Profiles\vk995pnm.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/10/26 20:00:57 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Firefox\Profiles\vk995pnm.default\extensions\[email protected]
[2011/10/01 14:04:28 | 000,000,000 | ---D | M] (CheckPlaces) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Firefox\Profiles\vk995pnm.default\extensions\[email protected]
[2010/11/28 15:18:15 | 000,000,000 | ---D | M] (vShare) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Firefox\Profiles\vk995pnm.default\extensions\vshare@toolbar
[2012/01/22 20:14:12 | 000,000,000 | ---D | M] (We-Care Reminder) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Firefox\Profiles\vk995pnm.default\extensions\wecarereminder@bryan
[2012/01/12 17:42:37 | 000,000,000 | ---D | M] (Widevine Media Transformer Plugin) -- Z:\Users\Harsh\AppData\Roaming\Mozilla\Firefox\Profiles\vk995pnm.default\extensions\widevinemediatransformer@widevine
[2011/10/31 15:44:40 | 000,000,000 | ---D | M] (No name found) -- Z:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/15 14:04:21 | 000,000,000 | ---D | M] (No name found) -- Z:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2012/01/15 14:04:21 | 000,134,104 | ---- | M] (Mozilla Foundation) -- Z:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/07/17 04:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- Z:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/08/31 05:38:58 | 000,082,944 | ---- | M] (vShare.tv ) -- Z:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll
[2011/10/26 13:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- Z:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012/01/15 14:04:17 | 000,002,252 | ---- | M] () -- Z:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/01/15 14:04:17 | 000,002,040 | ---- | M] () -- Z:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = Z:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = Z:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_18.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = Z:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = Z:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = Z:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = Z:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = Z:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = Z:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = Z:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = Z:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U24 (Enabled) = Z:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = Z:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = Z:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = Z:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = Z:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = Z:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = Z:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = Z:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: vShare.tv plug-in (Enabled) = Z:\Users\Harsh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll
CHR - plugin: vShare.tv plug-in (Enabled) = Z:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Widevine Media Transformer (Enabled) = Z:\Program Files (x86)\Google\Chrome\Application\plugins\npwidevinemediatransformer.dll
CHR - plugin: downloadUpdater (Enabled) = Z:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = Z:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: Winamp Application Detector (Enabled) = Z:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = Z:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = Z:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = Z:\Program Files (x86)\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = Z:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = Z:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = Z:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: OnLive Games Service Detector for Firefox (Enabled) = Z:\Program Files (x86)\OnLive\FirefoxPlugin\npolgdet.dll
CHR - plugin: Veetle TV Player (Enabled) = Z:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle Broadcaster Plugin (Enabled) = Z:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll
CHR - plugin: Veetle TV Core (Enabled) = Z:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: iTunes Application Detector (Enabled) = Z:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2012/01/22 14:33:28 | 000,440,287 | R--- | M]) - Z:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15136 more lines...
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - Z:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - Z:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - Z:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - Z:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - Z:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O4:64bit: - HKLM..\Run: [egui] Z:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [RtHDVCpl] Z:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [DeathAdder] Z:\Program Files (x86)\Razer\DeathAdder\razerhid.exe ()
O4 - HKCU..\Run: [PeerBlock] Z:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC)
O4 - Startup: Z:\Users\Harsh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk.disabled ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Download with pod-works-platinum - Z:\Program Files (x86)\ImTOO\PodWorks Platinum\upod_link.HTM File not found
O8 - Extra context menu item: Download with pod-works-platinum - Z:\Program Files (x86)\ImTOO\PodWorks Platinum\upod_link.HTM File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - Z:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - Z:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} http://download.micr...44/igdtoolx.cab (IGDTester Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0CF0BB43-C8A6-418D-AC51-B3170BB82810}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Z:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - Z:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (Z:\Windows\system32\userinit.exe) - Z:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (Z:\Program Files\Soluto\soluto.exe /userinit) - Z:\Program Files\Soluto\soluto.exe (Soluto)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - Z:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -Z:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -Z:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/25 15:39:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{82104484-b22e-11df-a5ce-001fd05d3274}\Shell - "" = AutoRun
O33 - MountPoints2\{82104484-b22e-11df-a5ce-001fd05d3274}\Shell\AutoRun\command - "" = J:\INSTALL.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/25 23:16:00 | 000,584,192 | ---- | C] (OldTimer Tools) -- Z:\Users\Harsh\Desktop\OTL.exe
[2012/01/25 21:03:07 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{85F9E3A7-C1DC-44E4-9C91-70C148BACEBB}
[2012/01/25 21:02:55 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{BF41D7B9-3B56-49CF-8645-9EB3A0424D88}
[2012/01/23 21:50:20 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{377EDB52-E98B-400C-B00D-3BFB5CB34E23}
[2012/01/23 21:50:09 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{55C25430-C5C1-4723-8D4F-58FA64F066C9}
[2012/01/23 18:34:11 | 000,000,000 | ---D | C] -- Z:\ProgramData\Microsoft\Windows\Start Menu\Programs\mIRC
[2012/01/22 23:29:12 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\Desktop\JTypes3.asp_files
[2012/01/21 16:27:31 | 000,054,728 | ---- | C] (Soluto LTD.) -- Z:\Windows\SysNative\drivers\Soluto.sys
[2012/01/21 16:27:28 | 000,000,000 | ---D | C] -- Z:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soluto
[2012/01/21 16:27:28 | 000,000,000 | ---D | C] -- Z:\Program Files\Soluto
[2012/01/21 16:26:39 | 000,000,000 | ---D | C] -- Z:\ProgramData\WeCareReminder
[2012/01/21 16:26:39 | 000,000,000 | ---D | C] -- Z:\ProgramData\Soluto
[2012/01/21 14:55:41 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\Desktop\computer concepts
[2012/01/21 14:52:42 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\Desktop\Internet and Info environment
[2012/01/18 01:04:46 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\Desktop\Mass Media
[2012/01/18 01:01:10 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\Desktop\Medical Anthropology
[2012/01/17 20:25:24 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{9D3B5D16-257E-4A83-A435-621D69D2F09E}
[2012/01/17 20:25:13 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{1DAA29AC-2076-49D3-82AA-3249994F8D7F}
[2012/01/17 14:52:42 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Bootvis
[2012/01/17 14:52:42 | 000,000,000 | ---D | C] -- Z:\Program Files (x86)\Microsoft Bootvis
[2012/01/16 15:27:19 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{B5D19BC4-5239-4C59-BFCB-3D5CCC3D78F4}
[2012/01/16 15:27:08 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{3A27EA5B-7A90-4517-8012-561EC20C0A4F}
[2012/01/15 17:45:15 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\Documents\ImTOO
[2012/01/15 17:45:15 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Roaming\ImTOO
[2012/01/15 17:45:06 | 000,000,000 | ---D | C] -- Z:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImTOO
[2012/01/15 17:44:38 | 000,000,000 | ---D | C] -- Z:\ProgramData\ImTOO
[2012/01/15 17:44:38 | 000,000,000 | ---D | C] -- Z:\Program Files (x86)\ImTOO
[2012/01/14 14:24:26 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{C15DF179-7DC3-4444-84AE-53ABBAA81041}
[2012/01/14 14:24:12 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{6BAF296E-3C63-4E99-87F3-5F769C5FA335}
[2012/01/14 01:38:44 | 000,000,000 | ---D | C] -- Z:\Windows\symbols
[2012/01/14 01:37:11 | 000,000,000 | ---D | C] -- Z:\ProgramData\VS
[2012/01/13 18:37:45 | 000,000,000 | ---D | C] -- Z:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2012/01/13 18:37:45 | 000,000,000 | ---D | C] -- Z:\ProgramData\Hi-Rez Studios
[2012/01/13 18:35:57 | 013,209,696 | ---- | C] (Hi-Rez Studios) -- Z:\Users\Harsh\Desktop\InstallHiRezGamesEnglish.exe
[2012/01/13 15:14:42 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{7C3FD1F0-F7CA-4331-AC2C-DA17B325BBCF}
[2012/01/13 15:14:27 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{386A2AB0-5528-44BA-88FA-7343D5C34264}
[2012/01/13 14:12:48 | 000,000,000 | ---D | C] -- Z:\ProgramData\NVIDIA Corporation
[2012/01/13 14:10:54 | 000,068,928 | ---- | C] (Khronos Group) -- Z:\Windows\SysNative\OpenCL.dll
[2012/01/13 14:10:54 | 000,061,248 | ---- | C] (Khronos Group) -- Z:\Windows\SysWow64\OpenCL.dll
[2012/01/12 23:29:29 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{C0F04E07-8C8C-4017-A2F1-72D92139B51C}
[2012/01/12 23:29:18 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{2CDA6267-F057-4F3F-BB75-9F3105E55451}
[2012/01/10 13:39:00 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{1E494B82-5050-4805-A274-F3EB9EFD5A61}
[2012/01/10 13:38:47 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{F7799EA8-A853-4E25-9E4D-D7E9CD795F19}
[2012/01/08 13:58:24 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{10AE13CC-F126-450C-82CD-B6E3D3442950}
[2012/01/08 13:58:10 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{73BA81F5-BD0F-4C7F-BB76-24EEA9DDB68E}
[2012/01/07 14:47:44 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{8C64AE3E-DE54-49E5-8ECE-651056054647}
[2012/01/07 14:47:33 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{51D4F647-E8FC-49F0-BB75-63828F595ED2}
[2012/01/06 13:07:10 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{A689B594-F58C-4931-B55F-B55A4D27DE9D}
[2012/01/06 13:06:58 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{78DD7EF0-8386-4BB8-976E-6F722A4C9AF5}
[2012/01/05 13:20:55 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{96EBEEAD-643F-47C8-9CDE-8F41B46E4CB5}
[2012/01/05 13:20:43 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{41E838D1-19A9-4190-A296-3110EDC76E42}
[2012/01/04 13:59:56 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{6E8E6857-01BD-4C85-B3FD-B5864F7383C5}
[2012/01/04 13:59:44 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{716E208A-81D5-4DF7-83A9-C1C8971F3A04}
[2012/01/03 13:26:26 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{5F86E5CD-9AF5-4026-B641-8BAFA7893310}
[2012/01/03 13:26:13 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{CFBBF942-3132-4513-B840-B06998B8170B}
[2012/01/03 01:23:53 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{D5EBBEE8-DC4B-4EEB-AC77-275767B074ED}
[2012/01/03 01:23:41 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{EA0D5F06-AC6F-4C9F-8C35-2F425EAE3D5A}
[2012/01/02 18:17:56 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\Desktop\walgreens rebate finalConfirm.action_files
[2012/01/02 13:23:22 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{ACB13723-967E-4350-9D7C-26C01FD025BD}
[2012/01/02 13:23:08 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{5968A38C-B227-4BA7-8501-EC7CCF0AE3E7}
[2012/01/01 13:48:20 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{30C51424-2098-4A13-ABCE-6494136CDBE5}
[2012/01/01 13:48:09 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{494BEB85-81D8-4F22-8A13-9A90C88A7395}
[2011/12/31 13:20:07 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{50F41D85-046F-4BE7-A5C9-CB0074D3DA8E}
[2011/12/31 13:19:51 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{6539B963-6C07-4177-A328-3FD86FA20FA0}
[2011/12/30 15:00:06 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{6078DD19-B816-4E4B-BFCE-EF0DC27BD0E2}
[2011/12/30 14:59:54 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{B495EBCE-98BC-4B8E-A5E0-6C1E65F57D8F}
[2011/12/29 15:21:15 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{E8D2470C-9C1B-451B-BB12-2A6586FB2BB6}
[2011/12/29 15:21:03 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{DE6B66B7-B379-41C8-AAB7-6E7CACD54DDB}
[2011/12/28 13:31:58 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{6C2324F2-9609-401F-AECF-98C9FF530556}
[2011/12/28 13:31:46 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{BE2DB8DA-9C8B-4743-96ED-A74D8134241F}
[2011/12/27 22:10:33 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{B8BBC3C5-F879-478A-AD65-14463FCFC939}
[2011/12/27 22:10:22 | 000,000,000 | ---D | C] -- Z:\Users\Harsh\AppData\Local\{8700ACCA-3EE7-42D5-BB99-2A12DB37B0B1}
[3 Z:\Windows\SysWow64\*.tmp files -> Z:\Windows\SysWow64\*.tmp -> ]
[3 Z:\Users\Harsh\Desktop\*.tmp files -> Z:\Users\Harsh\Desktop\*.tmp -> ]
[1 Z:\Windows\SysNative\*.tmp files -> Z:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/25 23:16:15 | 000,584,192 | ---- | M] (OldTimer Tools) -- Z:\Users\Harsh\Desktop\OTL.exe
[2012/01/25 23:12:15 | 000,014,224 | -H-- | M] () -- Z:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/25 23:12:15 | 000,014,224 | -H-- | M] () -- Z:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/25 23:03:28 | 000,000,830 | ---- | M] () -- Z:\Windows\tasks\Adobe Flash Player Updater.job
[2012/01/25 23:03:24 | 000,067,584 | --S- | M] () -- Z:\Windows\bootstat.dat
[2012/01/25 23:03:21 | 3220,037,632 | -HS- | M] () -- Z:\hiberfil.sys
[2012/01/25 22:56:00 | 000,000,896 | ---- | M] () -- Z:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/23 20:44:36 | 000,685,810 | ---- | M] () -- Z:\Users\Harsh\Desktop\Introduction.BeginSets.Spring2011.v2.pdf
[2012/01/23 20:43:39 | 000,010,783 | ---- | M] () -- Z:\Users\Harsh\Desktop\ia-scoringKey-611.pdf
[2012/01/23 20:43:35 | 000,797,448 | ---- | M] () -- Z:\Users\Harsh\Desktop\20110126-ia-examRegents.pdf
[2012/01/23 18:18:38 | 000,000,892 | ---- | M] () -- Z:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/23 01:15:08 | 000,000,000 | ---- | M] () -- Z:\Windows\SysWow64\Access.dat
[2012/01/22 23:29:12 | 000,017,096 | ---- | M] () -- Z:\Users\Harsh\Desktop\JTypes3.asp.htm
[2012/01/22 23:14:59 | 000,368,209 | ---- | M] () -- Z:\Users\Harsh\Desktop\humanmetrics.jpg
[2012/01/22 14:33:28 | 000,440,287 | R--- | M] () -- Z:\Windows\SysNative\drivers\etc\hosts
[2012/01/21 16:29:41 | 000,000,098 | ---- | M] () -- Z:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2012/01/19 21:39:51 | 000,030,457 | ---- | M] () -- Z:\Users\Harsh\Desktop\BuybackLabel_660890.PDF
[2012/01/17 14:47:57 | 000,000,003 | ---- | M] () -- Z:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/01/15 17:40:27 | 000,014,208 | ---- | M] () -- Z:\Users\Harsh\Desktop\-_Demonoid.me_-ImTOO_PodWorks_Platinum_5_0_1_1205_673633.7822.torrent
[2012/01/14 00:23:44 | 000,440,137 | R--- | M] () -- Z:\Windows\SysNative\drivers\etc\hosts.20120122-143328.backup
[2012/01/13 18:36:03 | 013,209,696 | ---- | M] (Hi-Rez Studios) -- Z:\Users\Harsh\Desktop\InstallHiRezGamesEnglish.exe
[2012/01/13 18:31:00 | 000,000,880 | ---- | M] () -- Z:\Windows\tasks\Google Software Updater.job
[2012/01/13 14:10:16 | 000,783,374 | ---- | M] () -- Z:\Windows\SysNative\PerfStringBackup.INI
[2012/01/13 14:10:16 | 000,663,200 | ---- | M] () -- Z:\Windows\SysNative\perfh009.dat
[2012/01/13 14:10:16 | 000,122,068 | ---- | M] () -- Z:\Windows\SysNative\perfc009.dat
[2012/01/13 00:50:12 | 000,990,720 | ---- | M] () -- Z:\Users\Harsh\Desktop\bootvis.msi
[2012/01/06 23:57:11 | 000,002,349 | ---- | M] () -- Z:\Users\Public\Desktop\Google Chrome.lnk
[2012/01/06 13:03:54 | 000,440,010 | R--- | M] () -- Z:\Windows\SysNative\drivers\etc\hosts.20120114-002344.backup
[2012/01/03 00:52:19 | 000,032,385 | ---- | M] () -- Z:\Users\Harsh\Desktop\error.jpg
[2012/01/02 18:17:58 | 000,009,336 | ---- | M] () -- Z:\Users\Harsh\Desktop\walgreens rebate finalConfirm.action.htm
[2012/01/02 17:15:26 | 000,054,728 | ---- | M] (Soluto LTD.) -- Z:\Windows\SysNative\drivers\Soluto.sys
[2011/12/29 13:43:30 | 000,777,098 | ---- | M] () -- Z:\Windows\SysWow64\PerfStringBackup.INI
[2011/12/27 21:10:28 | 000,254,934 | ---- | M] () -- Z:\Users\Harsh\Desktop\Oximeter10December.pdf
[2011/12/27 16:41:28 | 000,254,556 | ---- | M] () -- Z:\Users\Harsh\Desktop\201011PSI_report_Quit.pdf
[2011/12/27 00:39:50 | 000,296,123 | ---- | M] () -- Z:\Users\Harsh\Desktop\http___www.providencecare.ca_objects_content_revision_download.cfm_revision_id.219362_workspace_id.-4_Breath Stacking handbook.pdf
[3 Z:\Windows\SysWow64\*.tmp files -> Z:\Windows\SysWow64\*.tmp -> ]
[3 Z:\Users\Harsh\Desktop\*.tmp files -> Z:\Users\Harsh\Desktop\*.tmp -> ]
[1 Z:\Windows\SysNative\*.tmp files -> Z:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/23 20:44:35 | 000,685,810 | ---- | C] () -- Z:\Users\Harsh\Desktop\Introduction.BeginSets.Spring2011.v2.pdf
[2012/01/23 20:43:38 | 000,010,783 | ---- | C] () -- Z:\Users\Harsh\Desktop\ia-scoringKey-611.pdf
[2012/01/23 20:43:35 | 000,797,448 | ---- | C] () -- Z:\Users\Harsh\Desktop\20110126-ia-examRegents.pdf
[2012/01/22 23:29:11 | 000,017,096 | ---- | C] () -- Z:\Users\Harsh\Desktop\JTypes3.asp.htm
[2012/01/22 23:14:59 | 000,368,209 | ---- | C] () -- Z:\Users\Harsh\Desktop\humanmetrics.jpg
[2012/01/21 16:29:41 | 000,000,098 | ---- | C] () -- Z:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2012/01/19 21:39:47 | 000,030,457 | ---- | C] () -- Z:\Users\Harsh\Desktop\BuybackLabel_660890.PDF
[2012/01/17 14:47:57 | 000,000,003 | ---- | C] () -- Z:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/01/15 17:40:25 | 000,014,208 | ---- | C] () -- Z:\Users\Harsh\Desktop\-_Demonoid.me_-ImTOO_PodWorks_Platinum_5_0_1_1205_673633.7822.torrent
[2012/01/13 14:10:54 | 000,007,653 | ---- | C] () -- Z:\Windows\SysNative\nvinfo.pb
[2012/01/13 00:50:08 | 000,990,720 | ---- | C] () -- Z:\Users\Harsh\Desktop\bootvis.msi
[2012/01/03 00:51:39 | 000,032,385 | ---- | C] () -- Z:\Users\Harsh\Desktop\error.jpg
[2012/01/02 18:17:55 | 000,009,336 | ---- | C] () -- Z:\Users\Harsh\Desktop\walgreens rebate finalConfirm.action.htm
[2011/12/27 21:10:28 | 000,254,934 | ---- | C] () -- Z:\Users\Harsh\Desktop\Oximeter10December.pdf
[2011/12/27 16:41:28 | 000,254,556 | ---- | C] () -- Z:\Users\Harsh\Desktop\201011PSI_report_Quit.pdf
[2011/12/27 00:39:50 | 000,296,123 | ---- | C] () -- Z:\Users\Harsh\Desktop\http___www.providencecare.ca_objects_content_revision_download.cfm_revision_id.219362_workspace_id.-4_Breath Stacking handbook.pdf
[2011/12/14 23:39:42 | 000,042,392 | ---- | C] () -- Z:\Windows\SysWow64\xfcodec.dll
[2011/10/24 21:19:47 | 000,000,000 | ---- | C] () -- Z:\Windows\SysWow64\Access.dat
[2011/10/15 00:54:52 | 000,321,856 | ---- | C] () -- Z:\Windows\SysWow64\nvStreaming.exe
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- Z:\Windows\SysWow64\xlive.dll.cat
[2011/02/26 22:04:36 | 000,000,120 | ---- | C] () -- Z:\Users\Harsh\AppData\Roaming\FixVTS.ini
[2011/02/05 18:40:01 | 000,119,296 | ---- | C] () -- Z:\Windows\SysWow64\zlib.dll
[2011/02/05 18:40:01 | 000,057,344 | ---- | C] () -- Z:\Windows\SysWow64\ADsSecurity.dll
[2011/02/05 18:40:01 | 000,036,864 | ---- | C] () -- Z:\Windows\SysWow64\dxinputdll.dll
[2010/12/05 20:28:39 | 000,777,098 | ---- | C] () -- Z:\Windows\SysWow64\PerfStringBackup.INI
[2010/11/27 15:52:16 | 000,030,528 | ---- | C] () -- Z:\Windows\GVTDrv64.sys
[2010/10/16 23:11:03 | 000,000,369 | ---- | C] () -- Z:\Windows\IfoEdit.INI
[2010/09/15 17:37:31 | 000,007,645 | ---- | C] () -- Z:\Users\Harsh\AppData\Local\Resmon.ResmonCfg
[2010/09/08 22:26:45 | 000,189,736 | -H-- | C] () -- Z:\Windows\SysWow64\mlfcache.dat
[2010/08/27 22:03:05 | 000,271,200 | ---- | C] () -- Z:\Windows\SysWow64\PnkBstrB.exe
[2010/08/27 22:02:10 | 000,075,136 | ---- | C] () -- Z:\Windows\SysWow64\PnkBstrA.exe
[2010/08/27 16:45:32 | 000,000,262 | ---- | C] () -- Z:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/08/27 16:11:58 | 000,819,200 | ---- | C] () -- Z:\Windows\SysWow64\xvidcore.dll
[2010/08/27 16:11:58 | 000,180,224 | ---- | C] () -- Z:\Windows\SysWow64\xvidvfw.dll
[2010/08/27 16:11:46 | 000,085,504 | ---- | C] () -- Z:\Windows\SysWow64\ff_vfw.dll
[2010/08/27 16:11:12 | 000,033,019 | ---- | C] () -- Z:\Windows\SysWow64\CoreAAC-uninstall.exe
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- Z:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- Z:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- Z:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- Z:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- Z:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- Z:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- Z:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2010/08/30 00:10:19 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\acccore
[2010/12/11 21:03:54 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Azureus
[2011/11/27 00:28:48 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\ChaosPro
[2011/12/12 00:49:29 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\ChaosPro 4.0
[2011/12/12 19:59:37 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\DAEMON Tools Lite
[2010/11/03 20:38:50 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Digiarty
[2012/01/06 12:59:29 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Dropbox
[2011/02/03 20:26:53 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Elluminate
[2011/10/31 17:41:22 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\IDM
[2012/01/15 17:45:15 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\ImTOO
[2010/11/26 15:58:12 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\IObit
[2011/10/06 16:28:43 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\LolClient
[2010/11/27 00:25:58 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\OfficeRecovery
[2010/11/18 22:39:40 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\OnLive App
[2011/10/04 18:42:59 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Origin
[2011/02/05 18:42:37 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\PowerUp Software
[2011/11/26 21:01:45 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\PyScripter
[2010/08/27 19:57:36 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Razer
[2011/05/09 00:45:23 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Sinvise Systems
[2011/11/03 17:13:00 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Sling Media
[2011/10/30 12:40:55 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\StreamTorrent
[2011/10/23 18:27:42 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\SystemRequirementsLab
[2011/11/20 16:01:04 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\TeamViewer
[2012/01/02 17:24:29 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\TS3Client
[2011/10/31 21:31:27 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\TuneUpMedia
[2011/10/25 01:13:02 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Tunngle
[2012/01/17 00:19:35 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\uTorrent
[2010/10/16 14:42:00 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\WinAVI
[2010/10/16 14:47:52 | 000,000,000 | ---D | M] -- Z:\Users\Harsh\AppData\Roaming\Xilisoft
[2011/12/10 13:15:28 | 000,032,556 | ---- | M] () -- Z:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> Z:\ProgramData\TEMP:EF6E4E62
@Alternate Data Stream - 128 bytes -> Z:\Windows\SysWow64\zlib.dll:SummaryInformation
@Alternate Data Stream - 128 bytes -> Z:\Windows\SysWow64\zlib.dll:DocumentSummaryInformation
@Alternate Data Stream - 121 bytes -> Z:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> Z:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> Z:\ProgramData\TEMP:76650B61
< End of report >