Alright, Now we in business!! I am so happy that we finally got a dang scan done!!! lol
Ok, I am sorry I had just mentioned it in PM to you raktor, but..I have VISTA…When I had made the post initially, my profile still showed XP. Sorry about that.
1. Showing hidden files and stuff done successfully.
2. I cannot find any folder/file with a name as a 8 digit number. I even searched for *.exe under c:\users and no luck.
I did look under documents and settings also, but none there either.
OTListIt.txt :
OTL logfile created on: 8/11/2009 10:11:53 AM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Users\Parth\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.31 Gb Total Space | 69.58 Gb Free Space | 31.59% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.88 Gb Free Space | 58.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PARTH-PC
Current User Name: Parth
Logged in as Administrator.
Current Boot Mode: SafeMode
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Users\Parth\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wbem\wmiprvse.exe (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AESTFilters [Auto | Stopped]) – C:\Windows\System32\aestsrv.exe (Andrea Electronics Corporation)
SRV - (AntipPro2009_12 [Auto | Stopped]) – C:\Windows\svchast.exe ()
SRV - (Apple Mobile Device [Auto | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Bonjour Service [Auto | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Creative ALchemy AL6 Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Creative Labs Licensing Service [Auto | Stopped]) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (Creative Media Toolbox 6 Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe (Creative Labs)
SRV - (CTAudSvcService [Auto | Stopped]) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (dlcd_device [Auto | Stopped]) – C:\Windows\System32\dlcdcoms.exe ( )
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (Eventlog [Auto | Running]) – C:\Windows\System32\wevtsvc.dll (Microsoft Corporation)
SRV - (EvtEng [Auto | Stopped]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoToAssist [On_Demand | Stopped]) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (IAANTMON [Auto | Stopped]) – C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LMIMaint [Auto | Stopped]) – File not found
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NMIndexingService [Disabled | Stopped]) – File not found
SRV - (nvsvc [Auto | Stopped]) – C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
SRV - (PnkBstrA [Auto | Stopped]) – C:\Windows\System32\PnkBstrA.exe ()
SRV - (RapiMgr [Auto | Stopped]) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (RegSrvc [Auto | Stopped]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (RoxMediaDB9 [On_Demand | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (RoxWatch9 [Auto | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
SRV - (rpcapd [On_Demand | Stopped]) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (STacSV [Auto | Stopped]) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe (IDT, Inc.)
SRV - (stllssvr [On_Demand | Stopped]) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Stopped]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WcesComm [Auto | Stopped]) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (WinDefend [Auto | Stopped]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\Windows\System32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (atksgt [Auto | Stopped]) – C:\Windows\System32\DRIVERS\atksgt.sys ()
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (btwaudio [On_Demand | Stopped]) – C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (btwavdt [On_Demand | Stopped]) – C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwrchid [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\btwrchid.sys (Broadcom Corporation.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Stopped]) – C:\Windows\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (e1express [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\e1e6032.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (iaNvStor [Disabled | Stopped]) – C:\Windows\system32\drivers\ianvstor.sys (Intel Corporation)
DRV - (iaStor [Boot | Running]) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (iaStorV [Boot | Running]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (ksaud [On_Demand | Stopped]) – C:\Windows\System32\drivers\ksaud.sys (Creative Technology Ltd.)
DRV - (lirsgt [Auto | Stopped]) – C:\Windows\System32\DRIVERS\lirsgt.sys ()
DRV - (lmimirr [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\lmimirr.sys (LogMeIn, Inc.)
DRV - (LMIRfsClientNP [Disabled | Stopped]) – C:\Windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver [Auto | Stopped]) – C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NETw4v32 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\NETw4v32.sys (Intel Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (NPF [On_Demand | Stopped]) – C:\Windows\System32\drivers\npf.sys (CACE Technologies)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvlddmkm [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (OEM02Dev [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (OEM02Vfx [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (pcouffin [On_Demand | Stopped]) – C:\Windows\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (PxHelp20 [Boot | Running]) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (R300 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (rimmptsk [Auto | Running]) – C:\Windows\System32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [Auto | Running]) – C:\Windows\System32\DRIVERS\rimsptsk.sys (REDC)
DRV - (rismxdp [Auto | Running]) – C:\Windows\System32\DRIVERS\rixdptsk.sys (REDC)
DRV - (SASDIFSV [System | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (secdrv [Auto | Stopped]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (sptd [Boot | Running]) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (STHDA [On_Demand | Stopped]) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (TcUsb [On_Demand | Stopped]) – C:\Windows\System32\Drivers\tcusb.sys (UPEK Inc.)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\Windows\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\Windows\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (usb_rndisx [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\usb8023x.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (yukonwlh [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\yk60x86.sys (Marvell)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = http://www.iesearch.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.iesearch.com/
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\S-1-5-21-3256818742-1514715972-2829636577-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\S-1-5-21-3256818742-1514715972-2829636577-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "FireSearch"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: [removed]:5.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: [removed]:1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.4
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - prefs.js..keyword.URL: "
http://www.ffsearch.net/s/?ref=adr&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/05/26 19:01:00 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/25 09:38:29 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/04 16:01:07 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/04 16:01:07 | 00,000,000 | —D | M]
[2009/05/23 18:22:01 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Extensions
[2008/08/26 20:51:03 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/23 18:22:01 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Extensions\[removed]
[2009/08/10 15:47:55 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Firefox\Profiles\nz19xi5p.default\extensions
[2009/06/25 11:11:43 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Firefox\Profiles\nz19xi5p.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/05/04 10:16:15 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Firefox\Profiles\nz19xi5p.default\extensions\[removed]
[2008/07/03 13:35:59 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Firefox\Profiles\nz19xi5p.default\extensions\[removed]
[2008/02/07 11:45:21 | 00,002,920 | —- | M] () – C:\Users\Parth\AppData\Roaming\Mozilla\FireFox\Profiles\nz19xi5p.default\searchplugins\daemon-search.xml
[2008/03/10 19:05:30 | 00,000,996 | —- | M] () – C:\Users\Parth\AppData\Roaming\Mozilla\FireFox\Profiles\nz19xi5p.default\searchplugins\FireSearch.xml
[2009/08/10 15:47:55 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/04 16:01:07 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/12/30 21:04:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/05/02 15:24:13 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/08/26 20:51:00 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2009/08/04 16:01:06 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/04 16:01:06 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/04/17 01:10:32 | 00,539,136 | —- | M] (UPEK Inc.) – C:\Program Files\mozilla firefox\components\pbgk1_8.dll
[2007/04/10 18:21:08 | 00,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2008/08/06 17:22:02 | 00,114,688 | —- | M] (Adobe Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2008/10/17 14:29:52 | 01,332,224 | —- | M] (DivX,Inc.) – C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2008/01/07 19:14:26 | 00,098,304 | —- | M] (DivX, Inc) – C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2007/10/11 15:17:50 | 01,435,688 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/08/04 16:01:06 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/10/14 22:33:30 | 00,095,600 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008/05/26 19:00:54 | 00,144,984 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2009/04/04 13:38:37 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008/05/26 19:01:07 | 00,008,192 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2008/05/26 19:00:51 | 00,094,208 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2008/09/15 11:52:06 | 00,376,832 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2008/05/12 10:31:02 | 01,212,416 | —- | M] (cedelia) – C:\Program Files\mozilla firefox\plugins\NPStreamPlug.dll
[2008/11/04 21:50:22 | 00,221,184 | —- | M] (CNN) – C:\Program Files\mozilla firefox\plugins\NPTURNMED.dll
[2007/04/16 13:07:12 | 00,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2008/09/30 10:52:58 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/09/30 10:52:58 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/09/30 10:52:58 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/14 09:17:58 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/09/30 10:52:58 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/09/30 10:52:58 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/09/30 10:52:58 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (27 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\IDM.5.14.Build.3.Fixed-REA\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {46d2b8e4-b1a2-4e71-b177-0d681ad96db1} - C:\Windows\System32\himesuvo.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (ICQSys (IE PlugIn)) - {F54AF7DE-6038-4026-8433-CC30E3F17212} - C:\Windows\System32\dddesot.dll (ASC - AntiSpyware)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [CPM294f4f23] C:\Windows\System32\titewiko.DLL ()
O4 - HKLM..\Run: [Creative SB Monitoring Utility] C:\Windows\System32\sbavmon.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [jofefevemi] C:\Windows\System32\pipidesa.DLL ()
O4 - HKLM..\Run: [Module Loader] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Fingerprint Reader Suite\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi Notebook\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000..\Run: [IDMan] C:\IDM.5.14.Build.3.Fixed-REA\IDMan.exe (Tonec Inc.)
O4 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download all links with IDM - C:\IDM.5.14.Build.3.Fixed-REA\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\IDM.5.14.Build.3.Fixed-REA\IEGetVL.htm File not found
O8 - Extra context menu item: Download with IDM - C:\IDM.5.14.Build.3.Fixed-REA\IEExt.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\..Trusted Domains: blank ([]about in Trusted sites)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
http://echat.bellsouth.net/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874}
http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} http://www.worldwinner.com/games/v50/pool/pool.cab (Pool Control)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0}
http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158}
http://www.worldwinner.com/games/v63/bjattack/bja.cab (BJA Control)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B}
http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab (WordMojo Control)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F}
http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0}
http://www.idesitv.com/livetv.ocx (KooPlayer Control)
O16 - DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7}
http://68.213.32.251/cab/OCXChecker_8198.cab (OCXDownloadChecker Control)
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC}
http://www.worldwinner.com/games/v45/royal/royal.cab (Royal Control)
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47}
http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab (DinerDash Control)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/famil…/familyfeud.cab (FamilyFeud Control)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://www.creative.com/softwareupdate/su2…15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F}
http://www.worldwinner.com/games/v53/h2hpool/h2hpool.cab (H2hPool Control)
O16 - DPF: {FEC048AB-277A-460C-BF50-1A4193AEF148}
http://68.213.32.251/cab/DownloadCenter_8200.cab (DownloadCenter Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\Windows\system32\jufuvowa.dll) - C:\Windows\System32\jufuvowa.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\sarotehi.dll) - C:\Windows\System32\sarotehi.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\titewiko.dll) - C:\Windows\System32\titewiko.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) - C:\Windows\System32\vrlogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll File not found
O20 - Winlogon\Notify\psfus: DllName - C:\Windows\system32\psqlpwd.dll - C:\Windows\System32\psqlpwd.dll File not found
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - C:\Windows\System32\titewiko.dll ()
O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - C:\Windows\System32\titewiko.dll ()
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/08/10 16:03:10 | 00,000,000 | —D | M] - C:\autorefresh – [ NTFS ]
O33 - MountPoints2\{01277b41-4f67-11dd-b96f-001dd9e85b36}\Shell\Auto\command - "" = wscript "esta ig.vbs"
O33 - MountPoints2\{47b55a55-53a2-11de-ab4b-001dd9e85b36}\Shell\Auto\command - "" = wscript "esta ig.vbs"
O33 - MountPoints2\{4d76c645-53cd-11de-a767-001dd9e85b36}\Shell\Auto\command - "" = wscript "esta ig.vbs"
O33 - MountPoints2\{85e62f6f-cd16-11dd-b9bb-001dd9e85b36}\Shell - "" = AutoRun
O33 - MountPoints2\{85e62f6f-cd16-11dd-b9bb-001dd9e85b36}\Shell\AutoRun\command - "" = G:\LapNetWizard.exe – File not found
O33 - MountPoints2\{d1f3d59c-bf6e-11dd-a748-001dd9e85b36}\Shell\Auto\command - "" = wscript "esta ig.vbs"
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/08/11 10:07:24 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Users\Parth\Desktop\OTL.exe
[2009/08/10 21:46:55 | 03,739,490 | -H– | C] () – C:\Users\Parth\AppData\Local\IconCache.db
[2009/08/10 11:55:43 | 03,550,592 | —- | C] (Sysinternals - www.sysinternals.com) – C:\Users\Parth\Desktop\procexp.exe
[2009/08/10 11:55:43 | 00,072,138 | —- | C] () – C:\Users\Parth\Desktop\procexp.chm
[2009/08/10 11:49:41 | 01,615,732 | —- | C] () – C:\Users\Parth\Desktop\PE.zip
[2009/08/09 15:39:04 | 00,034,816 | —- | C] () – C:\Windows\System32\drivers\rr.sys
[2009/08/09 15:38:52 | 00,470,528 | —- | C] () – C:\Users\Parth\Desktop\RootRepeal.exe
[2009/08/09 15:38:30 | 00,462,996 | —- | C] () – C:\Users\Parth\Desktop\rr.zip
[2009/08/09 15:30:22 | 00,359,932 | R— | C] () – C:\Users\Parth\Desktop\dd.com
[2009/08/09 15:07:58 | 00,359,932 | —- | C] () – C:\Users\Parth\Desktop\dd.scr
[2009/08/09 15:05:57 | 00,000,000 | —D | C] – C:\Users\Parth\Desktop\gmer
[2009/08/09 10:25:57 | 00,000,000 | —D | C] – C:\Users\Parth\Desktop\rootrepeal
[2009/08/09 10:04:09 | 00,287,744 | —- | C] () – C:\Users\Parth\Desktop\remg.exe
[2009/08/08 18:10:21 | 00,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2009/08/08 18:10:21 | 00,000,000 | RHS- | C] () – C:\IO.SYS
[2009/08/08 11:24:38 | 00,000,030 | —- | C] () – C:\Windows\System32\sonhelp.htm
[2009/08/08 10:34:39 | 00,001,382 | —- | C] () – C:\Windows\System32\onhelp.htm
[2009/08/08 10:18:53 | 00,000,004 | —- | C] () – C:\Windows\System32\bincd32.dat
[2009/08/08 10:18:15 | 00,000,036 | —- | C] () – C:\Windows\System32\sysnet.dat
[2009/08/08 10:18:08 | 00,827,392 | —- | C] (ASC - AntiSpyware) – C:\Windows\System32\dddesot.dll
[2009/08/08 10:18:08 | 00,176,128 | —- | C] () – C:\Windows\svchast.exe
[2009/08/08 10:18:08 | 00,016,384 | —- | C] () – C:\Windows\System32\desot.exe
[2009/08/08 10:18:08 | 00,000,064 | —- | C] () – C:\Windows\ppp4.dat
[2009/08/08 10:18:08 | 00,000,009 | —- | C] () – C:\Windows\System32\bennuar.old
[2009/08/08 10:18:08 | 00,000,003 | —- | C] () – C:\Windows\ppp3.dat
[2009/08/08 10:17:59 | 00,000,000 | —D | C] – C:\Program Files\Windows Antivirus Pro
[2009/08/07 19:57:20 | 00,001,744 | —- | C] () – C:\Users\Parth\Desktop\Mozilla Firefox.lnk
[2009/08/07 19:41:55 | 00,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/07 19:41:53 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/08/07 19:41:52 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/08/07 19:41:52 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/07 19:29:34 | 00,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2009/08/07 19:27:52 | 00,000,904 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/08/07 19:27:51 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Roaming\SUPERAntiSpyware.com
[2009/08/07 19:27:51 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/08/07 19:13:57 | 01,343,651 | —- | C] () – C:\MGtools.exe
[2009/08/07 16:43:23 | 00,000,000 | —D | C] – C:\sdfix
[2009/08/07 15:54:15 | 00,000,000 | —D | C] – C:\Spybot
[2009/08/07 15:42:25 | 00,000,000 | -H-D | C] – C:\Windows\PIF
[2009/08/07 15:22:43 | 00,000,000 | —D | C] – C:\ht
[2009/08/07 15:02:41 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Local\Adobe
[2009/08/07 14:44:03 | 00,000,000 | —D | C] – C:\Program Files\ht
[2009/08/07 14:43:39 | 00,488,144 | —- | C] (Soeperman Enterprises Ltd ) – C:\Users\Parth\Desktop\HJTsetup.exe
[2009/08/07 14:37:41 | 00,050,688 | —- | C] (Atribune.org) – C:\Users\Parth\Desktop\ATF-Cleaner.exe
[2009/08/07 11:15:49 | 00,000,282 | -H– | C] () – C:\Windows\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[2009/08/07 11:15:49 | 00,000,240 | -H– | C] () – C:\Windows\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/08/01 11:36:22 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Local\Smilebox
[2009/08/01 11:36:20 | 00,000,000 | —D | C] – C:\Users\Parth\Documents\My Smilebox Creations
[2009/08/01 11:36:00 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Roaming\Smilebox
[2009/07/29 10:51:37 | 11,067,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/07/29 10:51:37 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/07/29 10:51:36 | 01,985,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/07/29 10:51:36 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/07/29 10:51:36 | 01,208,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/07/29 10:51:36 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/07/29 10:51:36 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/07/29 10:51:36 | 00,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/07/29 10:51:36 | 00,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/07/29 10:51:35 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/07/29 10:51:35 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/07/29 10:51:35 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/07/29 10:51:35 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/07/29 10:51:35 | 00,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/07/29 10:51:35 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/07/29 10:51:35 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/07/29 10:51:35 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/07/29 10:51:35 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/07/29 10:51:35 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/07/29 10:51:35 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/07/29 10:51:35 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/07/28 12:26:14 | 03,844,129 | —- | C] () – C:\Users\Parth\Desktop\clan eat.rar
[2009/07/21 16:21:46 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Roaming\IrfanView
[2009/07/21 16:21:46 | 00,000,000 | —D | C] – C:\Program Files\IrfanView
[2009/07/15 14:02:01 | 00,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2009/07/15 14:02:01 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2009/07/15 14:02:01 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2009/07/15 14:02:00 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dciman32.dll
[2009/07/13 14:41:45 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Local\RapidShare
[2009/07/13 14:41:15 | 00,002,633 | —- | C] () – C:\Users\Parth\Desktop\RapidShare Manager.lnk
[2009/05/11 09:21:48 | 00,084,480 | -HS- | C] () – C:\Windows\System32\titewiko.dll
[2009/05/11 09:21:48 | 00,037,376 | -HS- | C] () – C:\Windows\System32\hajigira.dll
[2009/05/10 21:10:52 | 00,083,968 | -HS- | C] () – C:\Windows\System32\sarotehi.dll
[2009/05/10 21:10:52 | 00,037,376 | -HS- | C] () – C:\Windows\System32\losesafa.dll
[2009/05/10 09:11:23 | 00,050,176 | -HS- | C] () – C:\Windows\System32\pipidesa.dll
[2009/05/10 09:11:23 | 00,050,176 | -HS- | C] () – C:\Windows\System32\jufuvowa.dll
[2009/05/10 09:11:23 | 00,050,176 | -HS- | C] () – C:\Windows\System32\himesuvo.dll
[2009/05/10 09:10:51 | 00,084,480 | -HS- | C] () – C:\Windows\System32\sinehotu.dll
[2009/05/10 09:10:51 | 00,050,176 | -HS- | C] () – C:\Windows\System32\kizomelo.dll
[2009/05/10 09:10:51 | 00,037,888 | -HS- | C] () – C:\Windows\System32\gokisoso.dll
[2009/05/09 15:38:59 | 00,084,992 | -HS- | C] () – C:\Windows\System32\kegezadu.dll
[2009/05/09 15:38:59 | 00,037,888 | -HS- | C] () – C:\Windows\System32\kewevuro.dll
[2009/05/08 22:38:28 | 00,085,504 | -HS- | C] () – C:\Windows\System32\buhivayi.dll
[2009/05/08 22:38:28 | 00,049,664 | -HS- | C] () – C:\Windows\System32\zoyiboha.dll
[2009/05/08 22:38:28 | 00,038,400 | -HS- | C] () – C:\Windows\System32\gugasara.dll
[2009/05/08 10:38:02 | 00,084,992 | -HS- | C] () – C:\Windows\System32\siruguhu.dll
[2009/05/08 10:38:02 | 00,038,400 | -HS- | C] () – C:\Windows\System32\pufajahe.dll
[2008/11/14 13:40:44 | 00,022,350 | R— | C] () – C:\Windows\System32\kschimp.ini
[2008/11/14 13:40:31 | 00,028,234 | —- | C] () – C:\Windows\System32\ksaud.ini
[2008/11/14 13:40:31 | 00,000,029 | —- | C] () – C:\Windows\System32\ctzapxx.ini
[2008/10/25 20:24:00 | 00,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2008/10/25 20:24:00 | 00,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2008/10/25 20:23:59 | 00,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/10/25 20:23:59 | 00,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/10/25 20:23:57 | 00,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/10/25 20:23:57 | 00,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[2008/09/23 09:47:45 | 00,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2008/09/21 16:16:49 | 00,000,119 | —- | C] () – C:\Windows\GeoLan.ini
[2008/09/20 15:13:06 | 00,000,128 | —- | C] () – C:\Windows\multiview.ini
[2008/09/20 15:12:51 | 00,000,082 | —- | C] () – C:\Windows\GeoPAL.ini
[2008/09/20 15:06:44 | 00,200,704 | —- | C] () – C:\Windows\JxIni.dll
[2008/09/20 15:06:44 | 00,139,264 | —- | C] () – C:\Windows\GV_GeoPTZini.dll
[2008/09/20 15:06:44 | 00,139,264 | —- | C] () – C:\Windows\GeoEditAVIDll.dll
[2008/09/20 15:06:44 | 00,024,576 | —- | C] ( ) – C:\Windows\GV_AccessIni_Memory.dll
[2008/05/29 10:16:31 | 00,060,928 | —- | C] () – C:\Windows\System32\scecli.dll
[2008/05/26 19:01:30 | 00,000,025 | —- | C] () – C:\Windows\cdplayer.ini
[2008/03/04 19:52:34 | 00,286,720 | —- | C] () – C:\Windows\System32\libcurl.dll
[2008/02/07 14:08:12 | 00,022,328 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2008/02/07 11:39:48 | 00,716,272 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008/01/04 17:58:50 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/01/04 17:57:22 | 00,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/01/04 17:57:22 | 00,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/01/03 15:23:54 | 00,278,984 | —- | C] () – C:\Windows\System32\drivers\atksgt.sys
[2008/01/03 15:23:54 | 00,025,416 | —- | C] () – C:\Windows\System32\drivers\lirsgt.sys
[2007/12/21 09:43:28 | 00,167,936 | —- | C] () – C:\Windows\System32\nvccoin.dll
[2007/12/21 09:43:27 | 00,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/12/21 02:04:38 | 00,127,488 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2007/12/21 02:04:38 | 00,069,120 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2007/12/21 02:04:38 | 00,000,628 | —- | C] () – C:\Windows\System32\PCI_VEN_1102&DEV_FF05&SUBSYS_00001102.ini
[2007/11/06 16:19:28 | 00,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2007/10/31 09:39:54 | 00,059,904 | —- | C] () – C:\Windows\System32\zlib1.dll
[2007/07/25 18:40:02 | 00,999,424 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2007/05/17 14:58:10 | 00,143,360 | —- | C] () – C:\Windows\System32\libexpatw.dll
[2007/01/03 17:58:58 | 00,344,064 | —- | C] () – C:\Windows\System32\dlcdcoin.dll
[2006/12/20 21:12:18 | 00,069,632 | —- | C] () – C:\Windows\System32\dlcdcfg.dll
[2006/12/20 17:08:24 | 00,643,072 | —- | C] ( ) – C:\Windows\System32\dlcdpmui.dll
[2006/12/20 17:06:58 | 01,224,704 | —- | C] ( ) – C:\Windows\System32\dlcdserv.dll
[2006/12/20 17:01:04 | 00,421,888 | —- | C] ( ) – C:\Windows\System32\dlcdcomm.dll
[2006/12/20 16:59:24 | 00,585,728 | —- | C] ( ) – C:\Windows\System32\dlcdlmpm.dll
[2006/12/20 16:58:02 | 00,397,312 | —- | C] ( ) – C:\Windows\System32\dlcdiesc.dll
[2006/12/20 16:55:40 | 00,094,208 | —- | C] ( ) – C:\Windows\System32\dlcdpplc.dll
[2006/12/20 16:54:54 | 00,684,032 | —- | C] ( ) – C:\Windows\System32\dlcdcomc.dll
[2006/12/20 16:54:20 | 00,163,840 | —- | C] ( ) – C:\Windows\System32\dlcdprox.dll
[2006/12/20 16:47:32 | 00,413,696 | —- | C] ( ) – C:\Windows\System32\dlcdinpa.dll
[2006/12/20 16:46:50 | 00,991,232 | —- | C] ( ) – C:\Windows\System32\dlcdusb1.dll
[2006/12/20 16:42:36 | 00,696,320 | —- | C] ( ) – C:\Windows\System32\dlcdhbn3.dll
[2006/12/06 23:56:58 | 00,106,496 | —- | C] () – C:\Windows\System32\dlcdinsr.dll
[2006/12/06 23:56:50 | 00,036,864 | —- | C] () – C:\Windows\System32\dlcdcur.dll
[2006/12/06 23:56:16 | 00,135,168 | —- | C] () – C:\Windows\System32\dlcdjswr.dll
[2006/12/06 23:52:36 | 00,176,128 | —- | C] () – C:\Windows\System32\dlcdinsb.dll
[2006/12/06 23:52:30 | 00,086,016 | —- | C] () – C:\Windows\System32\dlcdcub.dll
[2006/12/06 23:52:18 | 00,073,728 | —- | C] () – C:\Windows\System32\dlcdcu.dll
[2006/12/06 23:52:14 | 00,159,744 | —- | C] () – C:\Windows\System32\dlcdins.dll
[2006/12/06 23:51:00 | 00,434,176 | —- | C] () – C:\Windows\System32\dlcdutil.dll
[2006/11/07 15:25:58 | 00,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/03 19:25:56 | 00,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006/11/02 08:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:25:44 | 00,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:31 | 00,000,215 | —- | C] () – C:\Windows\system.ini
[2006/11/02 06:23:31 | 00,000,144 | —- | C] () – C:\Windows\win.ini
[2006/11/02 03:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/17 01:36:50 | 00,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/17 01:36:50 | 00,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/08/18 06:26:46 | 00,040,960 | —- | C] () – C:\Windows\System32\dlcdvs.dll
[2005/05/17 18:17:52 | 00,061,440 | —- | C] () – C:\Windows\System32\dlcdcnv4.dll
[2001/11/14 14:56:00 | 01,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll
========== Files - Modified Within 30 Days ==========
[5 C:\Windows\System32\*.tmp files]
[2009/08/11 10:10:04 | 00,011,168 | -H– | M] () – C:\Windows\System32\mupepidu
[2009/08/11 10:09:32 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/08/11 10:08:07 | 00,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/08/11 10:08:07 | 00,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/08/11 10:08:07 | 00,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2009/08/11 10:08:07 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/08/11 10:08:01 | 03,739,490 | -H– | M] () – C:\Users\Parth\AppData\Local\IconCache.db
[2009/08/11 10:07:18 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Users\Parth\Desktop\OTL.exe
[2009/08/11 10:06:45 | 00,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2009/08/11 10:00:02 | 00,000,240 | -H– | M] () – C:\Windows\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/08/11 10:00:01 | 00,000,282 | -H– | M] () – C:\Windows\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[2009/08/11 09:46:28 | 00,000,004 | —- | M] () – C:\Windows\System32\bincd32.dat
[2009/08/11 09:25:57 | 00,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/08/11 09:25:57 | 00,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/08/11 09:25:57 | 00,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/08/11 09:22:24 | 00,027,839 | —- | M] () – C:\ProgramData\nvModes.dat
[2009/08/11 09:22:24 | 00,027,839 | —- | M] () – C:\ProgramData\nvModes.001
[2009/08/11 09:21:49 | 00,084,480 | -HS- | M] () – C:\Windows\System32\titewiko.dll
[2009/08/11 09:21:48 | 00,037,376 | -HS- | M] () – C:\Windows\System32\hajigira.dll
[2009/08/10 21:10:53 | 00,083,968 | -HS- | M] () – C:\Windows\System32\sarotehi.dll
[2009/08/10 21:10:52 | 00,037,376 | -HS- | M] () – C:\Windows\System32\losesafa.dll
[2009/08/10 14:28:58 | 29,626,7221 | —- | M] () – C:\Windows\MEMORY.DMP
[2009/08/10 11:49:33 | 01,615,732 | —- | M] () – C:\Users\Parth\Desktop\PE.zip
[2009/08/10 09:11:22 | 00,050,176 | -HS- | M] () – C:\Windows\System32\kizomelo.dll
[2009/08/10 09:10:52 | 00,084,480 | -HS- | M] () – C:\Windows\System32\sinehotu.dll
[2009/08/10 09:10:52 | 00,037,888 | -HS- | M] () – C:\Windows\System32\gokisoso.dll
[2009/08/09 16:03:05 | 00,015,872 | —- | M] () – C:\Users\Parth\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/09 15:40:25 | 00,001,356 | —- | M] () – C:\Users\Parth\AppData\Local\d3d9caps.dat
[2009/08/09 15:39:16 | 00,034,816 | —- | M] () – C:\Windows\System32\drivers\rr.sys
[2009/08/09 15:39:00 | 00,084,992 | -HS- | M] () – C:\Windows\System32\kegezadu.dll
[2009/08/09 15:39:00 | 00,037,888 | -HS- | M] () – C:\Windows\System32\kewevuro.dll
[2009/08/09 15:38:25 | 00,462,996 | —- | M] () – C:\Users\Parth\Desktop\rr.zip
[2009/08/09 15:30:22 | 00,359,932 | R— | M] () – C:\Users\Parth\Desktop\dd.com
[2009/08/09 15:07:58 | 00,359,932 | —- | M] () – C:\Users\Parth\Desktop\dd.scr
[2009/08/08 22:38:59 | 00,049,664 | -HS- | M] () – C:\Windows\System32\zoyiboha.dll
[2009/08/08 22:38:29 | 00,085,504 | -HS- | M] () – C:\Windows\System32\buhivayi.dll
[2009/08/08 22:38:29 | 00,038,400 | -HS- | M] () – C:\Windows\System32\gugasara.dll
[2009/08/08 18:10:21 | 00,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/08/08 18:10:21 | 00,000,000 | RHS- | M] () – C:\IO.SYS
[2009/08/08 18:00:02 | 00,016,384 | —- | M] () – C:\Windows\System32\desot.exe
[2009/08/08 18:00:02 | 00,000,064 | —- | M] () – C:\Windows\ppp4.dat
[2009/08/08 18:00:02 | 00,000,003 | —- | M] () – C:\Windows\ppp3.dat
[2009/08/08 17:57:37 | 00,001,382 | —- | M] () – C:\Windows\System32\onhelp.htm
[2009/08/08 17:36:24 | 00,827,392 | —- | M] (ASC - AntiSpyware) – C:\Windows\System32\dddesot.dll
[2009/08/08 11:24:38 | 00,000,030 | —- | M] () – C:\Windows\System32\sonhelp.htm
[2009/08/08 10:38:02 | 00,084,992 | -HS- | M] () – C:\Windows\System32\siruguhu.dll
[2009/08/08 10:38:02 | 00,038,400 | -HS- | M] () – C:\Windows\System32\pufajahe.dll
[2009/08/08 10:18:15 | 00,000,036 | —- | M] () – C:\Windows\System32\sysnet.dat
[2009/08/08 10:18:08 | 00,176,128 | —- | M] () – C:\Windows\svchast.exe
[2009/08/08 10:18:08 | 00,000,009 | —- | M] () – C:\Windows\System32\bennuar.old
[2009/08/07 19:41:55 | 00,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/07 19:27:52 | 00,000,904 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/08/07 19:13:58 | 01,343,651 | —- | M] () – C:\MGtools.exe
[2009/08/07 14:43:44 | 00,488,144 | —- | M] (Soeperman Enterprises Ltd ) – C:\Users\Parth\Desktop\HJTsetup.exe
[2009/08/07 14:37:42 | 00,050,688 | —- | M] (Atribune.org) – C:\Users\Parth\Desktop\ATF-Cleaner.exe
[2009/08/07 09:39:38 | 00,287,744 | —- | M] () – C:\Users\Parth\Desktop\remg.exe
[2009/08/05 15:43:44 | 00,000,038 | —- | M] () – C:\Windows\avisplitter.ini
[2009/08/04 21:30:28 | 00,056,440 | —- | M] () – C:\Windows\War3Unin.dat
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/07/30 15:45:38 | 00,470,528 | —- | M] () – C:\Users\Parth\Desktop\RootRepeal.exe
[2009/07/28 12:26:21 | 03,844,129 | —- | M] () – C:\Users\Parth\Desktop\clan eat.rar
[2009/07/21 17:52:28 | 00,915,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/07/21 17:52:13 | 01,208,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/07/21 17:50:46 | 00,206,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/07/21 17:48:31 | 05,937,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/07/21 17:48:27 | 00,594,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/07/21 17:48:27 | 00,055,296 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/07/21 17:47:47 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/07/21 17:47:41 | 01,469,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/07/21 17:47:28 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/07/21 17:47:28 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/07/21 17:47:27 | 01,985,536 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/07/21 17:47:27 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/07/21 17:47:26 | 11,067,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/07/21 17:47:26 | 00,184,320 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/07/21 17:47:26 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/07/21 17:47:21 | 00,386,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/07/21 16:13:58 | 00,133,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/07/21 16:13:51 | 00,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/07/21 16:13:15 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/07/21 16:12:49 | 01,638,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/07/21 14:31:43 | 00,057,667 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2009/07/16 10:13:28 | 00,277,864 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 14:41:15 | 00,002,633 | —- | M] () – C:\Users\Parth\Desktop\RapidShare Manager.lnk
< End of report >